Skip to content

Commit 65ff30b

Browse files
fix: update serialize-javascript to >=7.0.3
1 parent a9ae0cd commit 65ff30b

3 files changed

Lines changed: 17 additions & 15 deletions

File tree

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"nostream": patch
3+
---
4+
5+
Security: override serialize-javascript to >=7.0.3 (CVE RCE, GHSA-5c6j-r48x-rmvq)

package.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -175,7 +175,9 @@
175175
"optionalDependencies": {
176176
"lzma-native": "^8.0.6"
177177
},
178-
"overrides": {
179-
"axios@<0.31.0": ">=0.31.0"
178+
"pnpm": {
179+
"overrides": {
180+
"serialize-javascript": ">=7.0.3"
181+
}
180182
}
181183
}

pnpm-lock.yaml

Lines changed: 8 additions & 13 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)