You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Insecure Randomness [High Severity][https://security.snyk.io/vuln/SNYK-JS-UNDICI-8641354] in undici@5.28.4
introduced by @badeball/cypress-cucumber-preprocessor@21.0.0 > find-cypress-specs@1.45.2 > @actions/core@1.10.1 > @actions/http-client@2.2.3 > undici@5.28.4
This issue was fixed in versions: 5.28.5, 6.21.1, 7.2.3
When github actions/http-client is updated with undici@5.28.5, and then find-cypress-specs is updated, then cypress-cucumber-preprocessor can be updated.
Current behavior
Snyk is reporting:
When github actions/http-client is updated with undici@5.28.5, and then find-cypress-specs is updated, then cypress-cucumber-preprocessor can be updated.
See:
actions/toolkit#1939
Desired behavior
Update find-cypress-specs version when child dependency undici@5.28.4 is updated.
Cypress version
14
Preprocessor version
22.0.0
Node version
22.14.0
Operating system
Mac Sonoma 14.7.1
Checklist
cypress-cucumber-preprocessor@4.3.1
(package name has changed and it is no longer the most recent version, see #689).The text was updated successfully, but these errors were encountered: