Skip to content

Commit 7825936

Browse files
authored
chore(dep): upgrade cypress/request to 3.0.9 to address form-data vulnerabilities (#32096)
* chore(deps): upgrade @cypress/request * changelog
1 parent 5b0a7e2 commit 7825936

File tree

9 files changed

+17
-13
lines changed

9 files changed

+17
-13
lines changed

cli/CHANGELOG.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ _Released 7/30/2025 (PENDING)_
99
- Fixed an issue where TypeScript ESM projects using `.js` and `.mjs` extensions where not resolving correctly within `@cypress/webpack-batteries-included-preprocessor`. Addressed in [#31994](https://github.com/cypress-io/cypress/pull/31994). Fixes [#26827](https://github.com/cypress-io/cypress/issues/26827) and [#28805](https://github.com/cypress-io/cypress/issues/28805).
1010
- Fixed an issue in `@cypress/angular` where component instance fields were not reference safe and were being overwritten. Fixes [#31238](https://github.com/cypress-io/cypress/issues/31238) and [#31983](https://github.com/cypress-io/cypress/issues/31983). Fixed in [#31993](https://github.com/cypress-io/cypress/pull/31993).
1111

12+
**Dependency Updates:**
13+
14+
- Upgraded `@cypress/request` to 3.0.9, to resolve [CVE-2025-7783](https://github.com/advisories/GHSA-fjxv-7rqg-78g4) in `form-data`. Addresses [#32091](https://github.com/cypress-io/cypress/issues/32091).
15+
1216
## 14.5.2
1317

1418
_Released 7/15/2025_

cli/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
"unit": "cross-env BLUEBIRD_DEBUG=1 NODE_ENV=test mocha --reporter mocha-multi-reporters --reporter-options configFile=../mocha-reporter-config.json"
2121
},
2222
"dependencies": {
23-
"@cypress/request": "^3.0.8",
23+
"@cypress/request": "^3.0.9",
2424
"@cypress/xvfb": "^1.2.4",
2525
"@types/sinonjs__fake-timers": "8.1.1",
2626
"@types/sizzle": "^2.3.2",

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@
7575
"@aws-sdk/client-s3": "3.485.0",
7676
"@aws-sdk/credential-providers": "3.53.0",
7777
"@babel/eslint-parser": "7.25.1",
78-
"@cypress/request": "^3.0.8",
78+
"@cypress/request": "^3.0.9",
7979
"@cypress/request-promise": "^5.0.0",
8080
"@electron/fuses": "1.8.0",
8181
"@electron/notarize": "^2.5.0",

packages/https-proxy/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
},
2525
"devDependencies": {
2626
"@cypress/debugging-proxy": "2.0.1",
27-
"@cypress/request": "^3.0.8",
27+
"@cypress/request": "^3.0.9",
2828
"@cypress/request-promise": "^5.0.0",
2929
"@packages/network": "0.0.0-development",
3030
"@packages/ts": "0.0.0-development",

packages/network/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@
2828
},
2929
"devDependencies": {
3030
"@cypress/debugging-proxy": "2.0.1",
31-
"@cypress/request": "^3.0.8",
31+
"@cypress/request": "^3.0.9",
3232
"@cypress/request-promise": "^5.0.0",
3333
"@packages/https-proxy": "0.0.0-development",
3434
"@packages/socket": "0.0.0-development",

packages/proxy/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@
3131
"utf8-stream": "0.0.0"
3232
},
3333
"devDependencies": {
34-
"@cypress/request": "^3.0.8",
34+
"@cypress/request": "^3.0.9",
3535
"@cypress/request-promise": "^5.0.0",
3636
"@cypress/sinon-chai": "2.9.1",
3737
"@packages/errors": "0.0.0-development",

packages/server/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@
2626
"@babel/parser": "7.25.3",
2727
"@cypress/commit-info": "2.2.0",
2828
"@cypress/get-windows-proxy": "1.6.2",
29-
"@cypress/request": "^3.0.8",
29+
"@cypress/request": "^3.0.9",
3030
"@cypress/request-promise": "^5.0.0",
3131
"@cypress/vite-dev-server": "0.0.0-development",
3232
"@cypress/webpack-batteries-included-preprocessor": "0.0.0-development",

system-tests/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
"@babel/preset-env": "7.25.3",
2424
"@cypress/commit-info": "2.2.0",
2525
"@cypress/debugging-proxy": "2.0.1",
26-
"@cypress/request": "^3.0.8",
26+
"@cypress/request": "^3.0.9",
2727
"@cypress/request-promise": "^5.0.0",
2828
"@cypress/sinon-chai": "2.9.1",
2929
"@cypress/webpack-preprocessor": "0.0.0-development",

yarn.lock

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2784,18 +2784,18 @@
27842784
stealthy-require "^1.1.1"
27852785
tough-cookie "^4.1.3"
27862786

2787-
"@cypress/request@^3.0.8":
2788-
version "3.0.8"
2789-
resolved "https://registry.yarnpkg.com/@cypress/request/-/request-3.0.8.tgz#992f1f42ba03ebb14fa5d97290abe9d015ed0815"
2790-
integrity sha512-h0NFgh1mJmm1nr4jCwkGHwKneVYKghUyWe6TMNrk0B9zsjAJxpg8C4/+BAcmLgCPa1vj1V8rNUaILl+zYRUWBQ==
2787+
"@cypress/request@^3.0.9":
2788+
version "3.0.9"
2789+
resolved "https://registry.yarnpkg.com/@cypress/request/-/request-3.0.9.tgz#8ed6e08fea0c62998b5552301023af7268f11625"
2790+
integrity sha512-I3l7FdGRXluAS44/0NguwWlO83J18p0vlr2FYHrJkWdNYhgVoiYo61IXPqaOsL+vNxU1ZqMACzItGK3/KKDsdw==
27912791
dependencies:
27922792
aws-sign2 "~0.7.0"
27932793
aws4 "^1.8.0"
27942794
caseless "~0.12.0"
27952795
combined-stream "~1.0.6"
27962796
extend "~3.0.2"
27972797
forever-agent "~0.6.1"
2798-
form-data "~4.0.0"
2798+
form-data "~4.0.4"
27992799
http-signature "~1.4.0"
28002800
is-typedarray "~1.0.0"
28012801
isstream "~0.1.2"
@@ -17100,7 +17100,7 @@ form-data@^3.0.0:
1710017100
hasown "^2.0.2"
1710117101
mime-types "^2.1.35"
1710217102

17103-
form-data@^4.0.0, form-data@^4.0.1, form-data@~4.0.0:
17103+
form-data@^4.0.0, form-data@^4.0.1, form-data@~4.0.4:
1710417104
version "4.0.4"
1710517105
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.4.tgz#784cdcce0669a9d68e94d11ac4eea98088edd2c4"
1710617106
integrity sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==

0 commit comments

Comments
 (0)