Skip to content

fix(deps): Bump node-forge to 1.3.2 #19183

Merged
chargome merged 1 commit intodevelopfrom
cg/sec-node-forge
Feb 5, 2026
Merged

fix(deps): Bump node-forge to 1.3.2 #19183
chargome merged 1 commit intodevelopfrom
cg/sec-node-forge

Conversation

@chargome
Copy link
Member

@chargome chargome commented Feb 5, 2026

Bump transitive dependency node-forge from 1.3.1 to 1.3.2 to address CVE-2025-12816

node-forge is a transitive dependency pulled in by:

  • @vinxi/listhen (via @sentry/solidstart)
  • listhen (via vinxi → nitropack)
  • selfsigned (via @angular-devkit/build-angular → webpack-dev-server)
  • google-p12-pem (via @google-cloud/common → google-auth-library)

All parent packages specify ^1.3.1 or ^1, so updating the lockfile to 1.3.2 is a safe patch bump with no breaking changes.

@github-actions
Copy link
Contributor

github-actions bot commented Feb 5, 2026

Codecov Results 📊


Generated by Codecov Action

@github-actions
Copy link
Contributor

github-actions bot commented Feb 5, 2026

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 9,061 - 9,479 -4%
GET With Sentry 1,652 18% 1,670 -1%
GET With Sentry (error only) 5,925 65% 6,073 -2%
POST Baseline 1,179 - 1,189 -1%
POST With Sentry 566 48% 586 -3%
POST With Sentry (error only) 1,053 89% 1,057 -0%
MYSQL Baseline 3,314 - 3,234 +2%
MYSQL With Sentry 442 13% 435 +2%
MYSQL With Sentry (error only) 2,625 79% 2,641 -1%

View base workflow run

@chargome chargome self-assigned this Feb 5, 2026
@chargome chargome requested review from a team, JPeer264 and logaretm and removed request for a team February 5, 2026 15:10
Copy link
Member

@logaretm logaretm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice one

@chargome chargome merged commit a8acff4 into develop Feb 5, 2026
214 checks passed
@chargome chargome deleted the cg/sec-node-forge branch February 5, 2026 16:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants