bump @redocly/cli version #37
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Title
bump @redocly/cli version
Description
Vulnerability Details:
CVE: CVE-2025-7783
Severity:
CRITICAL (CVSS 9.4)
Issue:
Use of Insufficiently Random Values in form-data package allowing HTTP Parameter Pollution (HPP)
Affected versions: form-data < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3
Root Cause:
The vulnerability was introduced through the @redocly/cli package (version 1.31.2) which depended on vulnerable versions of form-data:
Resolution:
Updated @redocly/cli from ^1.31.2 to ^2.0.6 in your root package.json
Verified that the new version uses form-data@^4.0.4 (patched)
Confirmed all vulnerable versions have been removed from pnpm-lock.yaml
Tested that the API validation still works correctly
Current Status:
✅ Vulnerability Resolved: All vulnerable form-data versions have been replaced with the patched form-data@4.0.4
✅ Functionality Preserved: Your API validation and build processes continue to work correctly
✅ No Breaking Changes: The update to @redocly/cli v2.x is backward compatible
The CVE-2025-7783 vulnerability has been completely resolved, and your project is now using secure versions of all dependencies.
Type of change