build: bump body-parser dependency to resolve qs security issue #2752
+91
−51
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
This PR addresses a reported security issue related to the qs dependency used by
cli-server-api.The CLI currently pulls in
[email protected]via[email protected]. Versions ofqs≤6.14.0are affected by a known DoS vulnerability related to arrayLimit handling in bracket notation.Following the maintainer’s guidance in #2750, this change bumps body-parser to a version that depends on a patched
qsrelease, resolving the vulnerability without introducing functional changes to the CLI itself.Closes #2750.
Test Plan
No runtime behavior changes are expected, as this is a dependency-only update.
Checklist
react-nativecheckout (instructions).