Skip to content

Drop dependency on qs#1377

Merged
haines merged 1 commit intocerbos:mainfrom
haines:drop-qs
Feb 23, 2026
Merged

Drop dependency on qs#1377
haines merged 1 commit intocerbos:mainfrom
haines:drop-qs

Conversation

@haines
Copy link
Member

@haines haines commented Feb 23, 2026

We've been getting vulnerability alerts for qs (GHSA-6rw7-vpxm-498p, GHSA-w7fw-mjwx-w883), which are spurious because we only use it for encoding. We're not really using much of the library's featureset anyway so this PR drops the dependency.

Signed-off-by: Andrew Haines <haines@cerbos.dev>
@haines haines marked this pull request as ready for review February 23, 2026 14:49
@haines haines requested a review from charithe February 23, 2026 14:49
@haines haines enabled auto-merge (squash) February 23, 2026 14:49
@haines haines merged commit eb40ac1 into cerbos:main Feb 23, 2026
63 checks passed
@haines haines deleted the drop-qs branch February 23, 2026 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants