patches v1.6.5 #58

Merged
jkeffects merged 14 commits from develop into main 2026-08-08 11:21:26 +00:00
Owner

update packages and cve close
Merge pull request 'feature/#56-icon-picker' (#57) from feature/#56-icon-picker into develop
fix: loading of notifications after delete
fix: create folder if not exists for client info
enhance: configurable z-index for BaseSearchSelect
enhance: FileViewer Image cover or contain
enhance: push sw - none overriding push notifications

update packages and cve close Merge pull request 'feature/#56-icon-picker' (#57) from feature/#56-icon-picker into develop fix: loading of notifications after delete fix: create folder if not exists for client info enhance: configurable z-index for BaseSearchSelect enhance: FileViewer Image cover or contain enhance: push sw - none overriding push notifications
brace-expansion  2.0.0 - 2.1.3 || 3.0.0 - 5.0.8
Severity: high
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups - https://github.com/advisories/GHSA-3jxr-9vmj-r5cp
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups - https://github.com/advisories/GHSA-3jxr-9vmj-r5cp
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash - https://github.com/advisories/GHSA-mh99-v99m-4gvg
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash - https://github.com/advisories/GHSA-mh99-v99m-4gvg
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation - https://github.com/advisories/GHSA-rgw5-rvv9-x895
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation - https://github.com/advisories/GHSA-rgw5-rvv9-x895

fast-uri  3.0.0 - 3.1.4
Severity: high
fast-uri vulnerable to host confusion via literal backslash authority delimiter - https://github.com/advisories/GHSA-v2hh-gcrm-f6hx
fast-uri vulnerable to host confusion via backslash authority introducer - https://github.com/advisories/GHSA-7p8r-x3mc-p8w7
fast-uri vulnerable to host confusion via failed IDN canonicalization - https://github.com/advisories/GHSA-4c8g-83qw-93j6

shell-quote  <=1.8.4
Severity: high
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) - https://github.com/advisories/GHSA-395f-4hp3-45gv

socket.io-parser  4.0.0 - 4.2.6
Severity: high
Socket.IO: Zero-attachment Memory Exhaustion - https://github.com/advisories/GHSA-2m8v-j782-fhvr
# Conflicts:
#	package-lock.json
#	package.json
Reviewed-on: #57
Sign in to join this conversation.
No reviewers
No labels
bug
feature
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
FF-Admin/ff-admin-core!58
No description provided.