@csrf-armor/express@1.2.3
·
2 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Patch Changes
-
#52
440e0afThanks @muneebs! - chore(deps): patch transitive dev dependency security advisoriesBumps pnpm overrides for
vite(^6.4.1→^6.4.2) andunhead(>=2.1.11→>=2.1.13) to pull in patched versions. These are dev/build-time dependencies only — no runtime behavior or published API changes.Addresses:
- GHSA: Vite arbitrary file read via dev server WebSocket (high, <=6.4.1)
- GHSA: Vite path traversal in optimized deps
.maphandling (medium, <=6.4.1) - GHSA: Unhead
hasDangerousProtocol()bypass via leading-zero padded HTML entities inuseHeadSafe()(medium, <2.1.13)
-
Updated dependencies [
440e0af]:- @csrf-armor/core@1.2.3