Skip to content

fix(vsix): resolve uuid GHSA-w5hq-g745-h8pq by downgrading @vscode/vsce to 2.25.0#4

Closed
Copilot wants to merge 1 commit into
mainfrom
copilot/fix-dependency-issue
Closed

fix(vsix): resolve uuid GHSA-w5hq-g745-h8pq by downgrading @vscode/vsce to 2.25.0#4
Copilot wants to merge 1 commit into
mainfrom
copilot/fix-dependency-issue

Conversation

Copilot AI commented Apr 27, 2026

Copy link
Copy Markdown
Contributor

Dependabot alert #1: uuid <14.0.0 (GHSA-w5hq-g745-h8pq) — missing bounds check in v3/v5/v6 when a caller-provided buf is too small — entered the tree as a transitive dependency via @vscode/vsce ≥2.25.1@azure/identity@azure/msal-nodeuuid ^8.3.0. Since @azure/msal-node still pegs uuid ^8.3.0, upgrading uuid independently isn't possible.

Changes

  • fkh-vsix/package.json: pins @vscode/vsce from ^3.0.02.25.0 — the last release before @azure/identity/@azure/msal-node were introduced as dependencies, eliminating the entire vulnerable chain.
  • fkh-vsix/package-lock.json: regenerated; npm audit reports 0 vulnerabilities. Total dependency count drops from ~338 to ~142 packages (azure SDK stack removed).

@freddydk

Copy link
Copy Markdown
Contributor

Fixed by the dependency

@freddydk freddydk closed this Jun 29, 2026
@freddydk freddydk deleted the copilot/fix-dependency-issue branch June 29, 2026 04:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants