chore(deps): bump qs to ^6.14.2#5707
Conversation
Adds a yarn resolution to force qs to >=6.14.2, patching two DoS vulnerabilities: arrayLimit bypass via bracket notation (>= 4.0.0, <= 6.14.1) and arrayLimit bypass via comma parsing (<= 6.14.1). Consolidates 6.11.0 and 6.13.0 consumers onto 6.15.0. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Semver Impact of This PR⚪ None (no version bump detected) 📋 Changelog PreviewThis is how your changes will appear in the changelog.
🤖 This preview updates automatically when you update the PR. |
iOS (legacy) Performance metrics 🚀
|
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 90e7cb3+dirty | 1206.61 ms | 1209.46 ms | 2.84 ms |
| 60cd796+dirty | 1204.87 ms | 1202.71 ms | -2.17 ms |
| 8e653ac+dirty | 1218.63 ms | 1223.88 ms | 5.24 ms |
| f70acbf+dirty | 1235.71 ms | 1243.14 ms | 7.43 ms |
| ad27f6e+dirty | 1223.41 ms | 1246.29 ms | 22.88 ms |
| 6c11c6a+dirty | 1202.43 ms | 1212.70 ms | 10.27 ms |
| 664c66f+dirty | 1215.37 ms | 1221.30 ms | 5.92 ms |
| d916aa3+dirty | 1221.02 ms | 1228.98 ms | 7.96 ms |
| 36841a6+dirty | 1221.32 ms | 1222.17 ms | 0.85 ms |
| bca62c0+dirty | 1183.61 ms | 1183.76 ms | 0.14 ms |
App size
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 90e7cb3+dirty | 3.41 MiB | 4.58 MiB | 1.17 MiB |
| 60cd796+dirty | 3.44 MiB | 4.67 MiB | 1.23 MiB |
| 8e653ac+dirty | 2.63 MiB | 4.01 MiB | 1.38 MiB |
| f70acbf+dirty | 2.63 MiB | 3.98 MiB | 1.34 MiB |
| ad27f6e+dirty | 3.41 MiB | 4.67 MiB | 1.25 MiB |
| 6c11c6a+dirty | 3.44 MiB | 4.60 MiB | 1.16 MiB |
| 664c66f+dirty | 3.38 MiB | 4.60 MiB | 1.22 MiB |
| d916aa3+dirty | 2.63 MiB | 3.81 MiB | 1.18 MiB |
| 36841a6+dirty | 3.41 MiB | 4.67 MiB | 1.25 MiB |
| bca62c0+dirty | 3.38 MiB | 4.60 MiB | 1.22 MiB |
Android (legacy) Performance metrics 🚀
|
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| eeebd10+dirty | 493.12 ms | 545.91 ms | 52.79 ms |
| 664c66f+dirty | 434.82 ms | 471.38 ms | 36.56 ms |
| d73150f+dirty | 411.21 ms | 465.86 ms | 54.65 ms |
| 4a17c8f+dirty | 406.62 ms | 400.58 ms | -6.04 ms |
| 2adbd1e+dirty | 433.98 ms | 427.96 ms | -6.02 ms |
| 98f632c | 424.25 ms | 435.48 ms | 11.23 ms |
| 9ced351+dirty | 405.40 ms | 419.39 ms | 13.98 ms |
| 64cd15c | 439.02 ms | 427.63 ms | -11.39 ms |
| 8490686+dirty | 365.59 ms | 400.24 ms | 34.65 ms |
| 1853710 | 555.47 ms | 556.59 ms | 1.12 ms |
App size
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| eeebd10+dirty | 43.75 MiB | 48.41 MiB | 4.66 MiB |
| 664c66f+dirty | 43.75 MiB | 48.55 MiB | 4.80 MiB |
| d73150f+dirty | 43.75 MiB | 48.55 MiB | 4.80 MiB |
| 4a17c8f+dirty | 43.75 MiB | 47.99 MiB | 4.24 MiB |
| 2adbd1e+dirty | 17.75 MiB | 19.70 MiB | 1.96 MiB |
| 98f632c | 17.75 MiB | 20.15 MiB | 2.41 MiB |
| 9ced351+dirty | 43.75 MiB | 48.41 MiB | 4.66 MiB |
| 64cd15c | 17.75 MiB | 20.15 MiB | 2.41 MiB |
| 8490686+dirty | 17.75 MiB | 19.70 MiB | 1.96 MiB |
| 1853710 | 17.75 MiB | 19.68 MiB | 1.94 MiB |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.
| "resolutions": { | ||
| "appium-chromedriver@npm:5.6.73/@xmldom/xmldom": "0.8.10", | ||
| "form-data": "4.0.4", | ||
| "qs": "^6.14.2", |
There was a problem hiding this comment.
Non-deterministic qs version resolution
Medium Severity
Using a range in resolutions ("qs": "^6.14.2") allows future installs to pick up newer qs releases without an intentional lockfile change, which can make dependency resolution less reproducible and introduce unexpected behavior changes across environments.
Additional Locations (1)
iOS (new) Performance metrics 🚀
|
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 90e7cb3+dirty | 1212.61 ms | 1213.80 ms | 1.19 ms |
| 60cd796+dirty | 1206.08 ms | 1213.36 ms | 7.28 ms |
| 8e653ac+dirty | 1215.46 ms | 1220.20 ms | 4.75 ms |
| f70acbf+dirty | 1239.00 ms | 1242.53 ms | 3.53 ms |
| ad27f6e+dirty | 1214.28 ms | 1203.67 ms | -10.62 ms |
| 6c11c6a+dirty | 1217.55 ms | 1221.49 ms | 3.94 ms |
| 664c66f+dirty | 1195.94 ms | 1194.80 ms | -1.14 ms |
| d916aa3+dirty | 1211.02 ms | 1221.33 ms | 10.31 ms |
| 36841a6+dirty | 1215.87 ms | 1217.27 ms | 1.40 ms |
| bca62c0+dirty | 1219.65 ms | 1226.14 ms | 6.50 ms |
App size
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 90e7cb3+dirty | 3.41 MiB | 4.58 MiB | 1.17 MiB |
| 60cd796+dirty | 3.44 MiB | 4.67 MiB | 1.23 MiB |
| 8e653ac+dirty | 3.19 MiB | 4.58 MiB | 1.39 MiB |
| f70acbf+dirty | 3.19 MiB | 4.54 MiB | 1.36 MiB |
| ad27f6e+dirty | 3.41 MiB | 4.67 MiB | 1.25 MiB |
| 6c11c6a+dirty | 3.44 MiB | 4.60 MiB | 1.16 MiB |
| 664c66f+dirty | 3.38 MiB | 4.60 MiB | 1.22 MiB |
| d916aa3+dirty | 3.19 MiB | 4.38 MiB | 1.19 MiB |
| 36841a6+dirty | 3.41 MiB | 4.67 MiB | 1.25 MiB |
| bca62c0+dirty | 3.38 MiB | 4.60 MiB | 1.22 MiB |
Android (new) Performance metrics 🚀
|
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| df1f7df+dirty | 374.68 ms | 384.96 ms | 10.28 ms |
| a483f9f+dirty | 428.57 ms | 475.98 ms | 47.41 ms |
| 7091004+dirty | 377.76 ms | 402.11 ms | 24.35 ms |
| 5526494+dirty | 380.79 ms | 432.70 ms | 51.91 ms |
| 98f632c+dirty | 323.98 ms | 375.39 ms | 51.41 ms |
| 5c16cdc+dirty | 375.45 ms | 426.62 ms | 51.17 ms |
| 8ece263+dirty | 369.44 ms | 414.65 ms | 45.21 ms |
| a2bb688+dirty | 371.19 ms | 389.18 ms | 17.99 ms |
| 526494a+dirty | 361.10 ms | 410.84 ms | 49.74 ms |
| 60cd796+dirty | 410.56 ms | 439.00 ms | 28.44 ms |
App size
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| df1f7df+dirty | 43.94 MiB | 48.91 MiB | 4.97 MiB |
| a483f9f+dirty | 43.94 MiB | 49.27 MiB | 5.33 MiB |
| 7091004+dirty | 43.94 MiB | 48.81 MiB | 4.88 MiB |
| 5526494+dirty | 7.15 MiB | 8.41 MiB | 1.26 MiB |
| 98f632c+dirty | 7.15 MiB | 8.42 MiB | 1.27 MiB |
| 5c16cdc+dirty | 7.15 MiB | 8.41 MiB | 1.26 MiB |
| 8ece263+dirty | 7.15 MiB | 8.41 MiB | 1.26 MiB |
| a2bb688+dirty | 7.15 MiB | 8.43 MiB | 1.28 MiB |
| 526494a+dirty | 43.94 MiB | 48.82 MiB | 4.88 MiB |
| 60cd796+dirty | 43.94 MiB | 48.90 MiB | 4.96 MiB |
This reverts commit 19a0088.


Summary
resolutionsentry to forceqsto>=6.14.2, resolves to6.15.06.11.0and6.13.0consumers onto6.15.0Dependabot alerts
Test plan
yarn installresolves allqsconsumers to6.15.0yarn buildpassesyarn testpasses🤖 Generated with Claude Code