Skip to content

fix(web): override devalue to patch prototype pollution (#19)#78

Merged
maskedsyntax merged 1 commit intomainfrom
fix/devalue-proto-pollution
Apr 6, 2026
Merged

fix(web): override devalue to patch prototype pollution (#19)#78
maskedsyntax merged 1 commit intomainfrom
fix/devalue-proto-pollution

Conversation

@maskedsyntax
Copy link
Copy Markdown
Member

Overrides devalue to ^5.6.4 (transitive via @sveltejs/kit and svelte) to patch prototype pollution in devalue.parse / devalue.unflatten. Fixes Dependabot alert #19.

@vercel
Copy link
Copy Markdown

vercel bot commented Apr 6, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hashprep Ready Ready Preview, Comment Apr 6, 2026 10:10am

@maskedsyntax maskedsyntax merged commit e28ce36 into main Apr 6, 2026
6 checks passed
@maskedsyntax maskedsyntax deleted the fix/devalue-proto-pollution branch April 6, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant