Skip to content

Comments

test(deps): update qs to 6.14.2#1654

Merged
jennifer-shehane merged 1 commit intocypress-io:masterfrom
MikeMcC399:update/qs
Feb 16, 2026
Merged

test(deps): update qs to 6.14.2#1654
jennifer-shehane merged 1 commit intocypress-io:masterfrom
MikeMcC399:update/qs

Conversation

@MikeMcC399
Copy link
Collaborator

@MikeMcC399 MikeMcC399 commented Feb 15, 2026

Situation

npm audit and Dependabot report a low severity vulnerability CVE-2026-2391 (GHSA-w7fw-mjwx-w883) in [email protected] which is a transient dependency of cypress. PR cypress-io/cypress#33373 will not fix the issue for external usage of cypress.

Change

Package manager Pre-fix Fix
npm npm ci npm audit fix
pnpm pnpm update -r
Yarn Classic yarn upgrade
Yarn Modern yarn remove cypress yarn add cypress -D -E

Note: this also resolves other low severity vulnerabilities in examples/webpack.

Verification

Package manager Command
npm npm audit
pnpm pnpm audit
Yarn Classic yarn audit
Yarn Modern yarn why qs

Updates also other transient dependencies in lockfiles
@MikeMcC399 MikeMcC399 added bug Something isn't working type: dependencies labels Feb 15, 2026
@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 self-assigned this Feb 15, 2026
@MikeMcC399 MikeMcC399 marked this pull request as ready for review February 15, 2026 16:17
@jennifer-shehane jennifer-shehane merged commit 8d8b64a into cypress-io:master Feb 16, 2026
86 checks passed
@MikeMcC399 MikeMcC399 deleted the update/qs branch February 16, 2026 15:02
@github-actions
Copy link

🎉 This PR is included in version 7.1.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants