Skip to content

Commit 0119c74

Browse files
fix: update serialize-javascript to >=7.0.3 <8 (#592)
Co-authored-by: Ricardo Cabral <me@ricardocabral.io>
1 parent dfa2838 commit 0119c74

3 files changed

Lines changed: 17 additions & 15 deletions

File tree

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"nostream": patch
3+
---
4+
5+
Security: override serialize-javascript to >=7.0.3 (CVE RCE, GHSA-5c6j-r48x-rmvq)

package.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -180,7 +180,9 @@
180180
"optionalDependencies": {
181181
"lzma-native": "^8.0.6"
182182
},
183-
"overrides": {
184-
"axios@<0.31.0": ">=0.31.0"
183+
"pnpm": {
184+
"overrides": {
185+
"serialize-javascript": ">=7.0.3 <8"
186+
}
185187
}
186188
}

pnpm-lock.yaml

Lines changed: 8 additions & 13 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)