Skip to content

Using an outdated version of inquirer/prompts which relies on outdated version of other inquirer packages with vulnerabilities #4054

@rachaelsmith-ecl

Description

@rachaelsmith-ecl

Pre-flight checklist

  • I have read the contribution documentation for this project.
  • I agree to follow the code of conduct that this project uses.
  • I have searched the issue tracker for a bug that matches the one I want to file, without success.

Forge version

7.10.2

Electron version

33.3.1

Operating system

macOS Tahoe 26.1

Last known working Forge version

7.10.2

Expected behavior

shouldn't have any security vulnerabilities

Actual behavior

the version of inquirer/prompts that is being used uses an old version inquirer/editor which is using an old version of external-editor that is now deprecated and using a vulnerable version of tmp - if you update the inquirer/prompts package to the most recent there will be no more vulnerabilities

Steps to reproduce

run an audit

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions