Skip to content

fix(web): bump svelte to patch SSR XSS issues (#8, #9, #10, #15, #16)#80

Merged
maskedsyntax merged 1 commit intomainfrom
fix/svelte-ssr-xss
Apr 6, 2026
Merged

fix(web): bump svelte to patch SSR XSS issues (#8, #9, #10, #15, #16)#80
maskedsyntax merged 1 commit intomainfrom
fix/svelte-ssr-xss

Conversation

@maskedsyntax
Copy link
Copy Markdown
Member

Bumps svelte to ^5.53.5 (resolved 5.55.1) to patch multiple SSR XSS/HTML-injection issues: contenteditable bindings, spread attributes, dynamic svelte:element tags, content, and prototype-chain enumeration. Fixes Dependabot alerts #8, #9, #10, #15, #16.

@vercel
Copy link
Copy Markdown

vercel bot commented Apr 6, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hashprep Ready Ready Preview, Comment Apr 6, 2026 10:15am

@maskedsyntax maskedsyntax merged commit 98072cf into main Apr 6, 2026
6 checks passed
@maskedsyntax maskedsyntax deleted the fix/svelte-ssr-xss branch April 6, 2026 10:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant