Skip to content

Conversation

@toufali
Copy link
Member

@toufali toufali commented Jun 3, 2025

Because

  • the current version of multer includes multiple vulnerability alerts

This pull request

  • bumps nestjs/platform-express, which depends on multer
  • bumps multer to 2.0 which is the latest/resolved version

Issue that this pull request solves

Closes: FXA-11800

Other information (Optional)

Running yarn why multer after upgrading nestjs/platform-express confirms nest is using the latest patched 2.0 version of multer.

@toufali toufali requested a review from a team as a code owner June 3, 2025 16:29
@toufali toufali merged commit 9b25ba1 into main Jun 3, 2025
19 checks passed
@toufali toufali deleted the vuln-multer branch June 3, 2025 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants