Skip to content

Update dependency jspdf to v4 - autoclosed#677

Closed
mend-for-gitlite.zycloud.tk[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/jspdf-4.x
Closed

Update dependency jspdf to v4 - autoclosed#677
mend-for-gitlite.zycloud.tk[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/jspdf-4.x

Conversation

@mend-for-gitlite.zycloud.tk
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
jspdf dependencies major ^3.0.4 -> ^4.0.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
High High 8.6 CVE-2025-68428

Release Notes

parallax/jsPDF (jspdf)

v4.0.0

Compare Source

This release fixes a critical path traversal/local file inclusion security vulnerability in the jsPDF Node.js build. File system access is now restricted by default and can be enabled by either using node's --permission flag or the new jsPDF.allowFsRead property.

There are no other breaking changes.


  • If you want to rebase/retry this PR, check this box

@cwperks
Copy link
Copy Markdown
Member

cwperks commented Jan 23, 2026

Started throwing Claude at the problem here while waiting for some other builds to finish: cwperks#1

@mend-for-gitlite.zycloud.tk mend-for-gitlite.zycloud.tk bot changed the title Update dependency jspdf to v4 Update dependency jspdf to v4 - autoclosed Jan 23, 2026
@mend-for-gitlite.zycloud.tk mend-for-gitlite.zycloud.tk bot deleted the whitesource-remediate/jspdf-4.x branch January 23, 2026 23:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant