Skip to content

chore(deps-dev): bump devalue 5.6.3 → 5.6.4 (CVE-2026-30226)#155

Closed
Copilot wants to merge 1 commit intodependabot/npm_and_yarn/npm_and_yarn-daaf7f4cc1from
copilot/sub-pr-152-another-one
Closed

chore(deps-dev): bump devalue 5.6.3 → 5.6.4 (CVE-2026-30226)#155
Copilot wants to merge 1 commit intodependabot/npm_and_yarn/npm_and_yarn-daaf7f4cc1from
copilot/sub-pr-152-another-one

Conversation

Copy link
Contributor

Copilot AI commented Mar 12, 2026

Patches prototype pollution in devalue.parse / devalue.unflatten (CVE-2026-30226, CVSS 6.3) — crafted payloads could trigger DoS or type confusion via __proto__ injection.

Changes

  • package-lock.json: devalue resolved to 5.6.4, integrity hash updated
  • web/svelte/package-lock.json: same

📱 Kick off Copilot coding agent tasks wherever you are with GitHub Mobile, available on iOS and Android.

Copilot AI changed the title [WIP] Update dev dependencies for devalue package chore(deps-dev): bump devalue 5.6.3 → 5.6.4 (CVE-2026-30226) Mar 12, 2026
Copilot AI requested a review from kayodebristol March 12, 2026 19:07
@kayodebristol
Copy link
Contributor

Closing this PR to enforce the 1-PR-per-repo rule. Only one Copilot PR is allowed per repository at a time. The oldest PR (#151) will be kept active.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants