Skip to content

Jws CG fix - AzureTestPlanV0, ContainerStructureTestV0#21979

Open
v-gayatrij wants to merge 1 commit intomasterfrom
users/v-gayjaiswal/jws-cg-fix-testplan-cst
Open

Jws CG fix - AzureTestPlanV0, ContainerStructureTestV0#21979
v-gayatrij wants to merge 1 commit intomasterfrom
users/v-gayjaiswal/jws-cg-fix-testplan-cst

Conversation

@v-gayatrij
Copy link
Copy Markdown
Contributor

Context

AB#2339822
CG Alert 342212

Vulnerability reported in jws 3.2.2 (CVE-2025-65945, High severity).
jws 3.2.2 is pulled in transitively via docker-common -> azure-arm-rest -> jsonwebtoken -> jws.
Safe version: jws 4.0.1


Task Name

AzureTestPlanV0
ContainerStructureTestV0


Description

Regenerate package-lock.json for AzureTestPlanV0 and ContainerStructureTestV0 to resolve jws to 4.0.1 (safe version) for CVE-2025-65945. Updated transitive dependencies including docker-common and azure-arm-rest to latest versions.


Risk Assessment (Low / Medium / High)

Low


Change Behind Feature Flag (Yes / No)

No - dependency version update only


Tech Design / Approach

  • Deleted package-lock.json and ran npm install to regenerate with safe jws version for both tasks.

Documentation Changes Required (Yes/No)

No


Unit Tests Added or Updated (Yes / No)

No - dependency update only, no code changes


Additional Testing Performed

Verified jws resolves to 4.0.1 in regenerated lock files for both tasks.


Logging Added/Updated (Yes/No)

No


Telemetry Added/Updated (Yes/No)

No


Rollback Scenario and Process (Yes/No)

Revert the package-lock.json changes.


Dependency Impact Assessed and Regression Tested (Yes/No)

Yes - only transitive dependency versions changed.


Checklist

  • Related issue linked (if applicable)
  • Task version was bumped
  • Verified the task behaves as expected

Regenerate package-lock.json to resolve jws to safe version
for CVE-2025-65945. Bump task patch versions.

AB#2339822
@v-gayatrij v-gayatrij requested a review from a team as a code owner April 9, 2026 06:23
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant