Skip to content

Jws CG fix - AzureSpringCloudV0#21977

Open
v-gayatrij wants to merge 1 commit intomasterfrom
users/v-gayjaiswal/jws-cg-fix-springcloud
Open

Jws CG fix - AzureSpringCloudV0#21977
v-gayatrij wants to merge 1 commit intomasterfrom
users/v-gayjaiswal/jws-cg-fix-springcloud

Conversation

@v-gayatrij
Copy link
Copy Markdown
Contributor

Context

AB#2339822
CG Alert 342212

Vulnerability reported in jws 3.2.2 (CVE-2025-65945, High severity).
jws 3.2.2 is pulled in transitively via azure-arm-rest -> jsonwebtoken -> jws.
Safe version: jws 4.0.1


Task Name

AzureSpringCloudV0


Description

Regenerate package-lock.json to resolve jws to 4.0.1 (safe version) for CVE-2025-65945. Updated transitive dependencies including azure-arm-rest to latest version.


Risk Assessment (Low / Medium / High)

Low


Change Behind Feature Flag (Yes / No)

No - dependency version update only


Tech Design / Approach

  • Deleted package-lock.json and ran npm install to regenerate with safe jws version.

Documentation Changes Required (Yes/No)

No


Unit Tests Added or Updated (Yes / No)

No - dependency update only, no code changes


Additional Testing Performed

Verified jws resolves to 4.0.1 in regenerated lock file.


Logging Added/Updated (Yes/No)

No


Telemetry Added/Updated (Yes/No)

No


Rollback Scenario and Process (Yes/No)

Revert the package-lock.json changes.


Dependency Impact Assessed and Regression Tested (Yes/No)

Yes - only transitive dependency versions changed.


Checklist

  • Related issue linked (if applicable)
  • Task version was bumped
  • Verified the task behaves as expected

Regenerate package-lock.json to resolve jws to safe version
for CVE-2025-65945. Bump task patch version.

AB#2339822
@v-gayatrij v-gayatrij requested a review from a team as a code owner April 9, 2026 06:22
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant