From f5256421e734e06766f098bdbcef6320075fb7b2 Mon Sep 17 00:00:00 2001 From: maskedsyntax Date: Mon, 6 Apr 2026 15:39:53 +0530 Subject: [PATCH] fix(web): override devalue to ^5.6.4 to patch prototype pollution --- web/package-lock.json | 6 +++--- web/package.json | 3 ++- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/web/package-lock.json b/web/package-lock.json index ce8a60e..00b8224 100644 --- a/web/package-lock.json +++ b/web/package-lock.json @@ -1127,9 +1127,9 @@ } }, "node_modules/devalue": { - "version": "5.6.2", - "resolved": "https://registry.npmjs.org/devalue/-/devalue-5.6.2.tgz", - "integrity": "sha512-nPRkjWzzDQlsejL1WVifk5rvcFi/y1onBRxjaFMjZeR9mFpqu2gmAZ9xUB9/IEanEP/vBtGeGganC/GO1fmufg==", + "version": "5.6.4", + "resolved": "https://registry.npmjs.org/devalue/-/devalue-5.6.4.tgz", + "integrity": "sha512-Gp6rDldRsFh/7XuouDbxMH3Mx8GMCcgzIb1pDTvNyn8pZGQ22u+Wa+lGV9dQCltFQ7uVw0MhRyb8XDskNFOReA==", "dev": true, "license": "MIT" }, diff --git a/web/package.json b/web/package.json index e7bb826..78a9070 100644 --- a/web/package.json +++ b/web/package.json @@ -18,6 +18,7 @@ "vite": "^6.0.0" }, "overrides": { - "rollup": "^4.59.0" + "rollup": "^4.59.0", + "devalue": "^5.6.4" } }