Skip to content

AppCenterTestV1: Fix CG alert 342212 — update jws to 3.2.3#22036

Open
v-vikjadhav wants to merge 7 commits intomasterfrom
users/v-vikjadhav/AppCenterTestV1
Open

AppCenterTestV1: Fix CG alert 342212 — update jws to 3.2.3#22036
v-vikjadhav wants to merge 7 commits intomasterfrom
users/v-vikjadhav/AppCenterTestV1

Conversation

@v-vikjadhav
Copy link
Copy Markdown

@v-vikjadhav v-vikjadhav commented Apr 22, 2026

Description:

Summary

Fixes Component Governance alert 342212 by updating the transitive dependency jws to 3.2.3, resolving CVE-2016-1000223 (Forgeable Public/Private Tokens — High severity).

Dependency chain

appcenter-cli@3.0.3 → jsonwebtoken@9.0.0 → jws@3.2.3 (fixed)

Changes

File Change
package-lock.json npm update jws — resolves jws to 3.2.3
task.json Version bump 1.269.01.274.0
task.loc.json Version bump 1.269.01.274.0

Testing

  • L0 tests: All 7 passing
  • Common tests: All 8 passing
  • npm ls jws confirms single resolved instance at 3.2.3

Updated transitive dependency jws from vulnerable version to 3.2.3
via npm update, resolving CVE-2016-1000223 (Forgeable Public/Private
Tokens — High severity).

Dependency chain: appcenter-cli@3.0.3 → jsonwebtoken@9.0.0 → jws@3.2.3

- package-lock.json: npm update jws resolves to 3.2.3
- task.json, task.loc.json: version bump 1.269.0 → 1.274.0
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-vikjadhav
Copy link
Copy Markdown
Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera
Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera v-abhishera marked this pull request as ready for review April 23, 2026 05:08
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera
Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants