Skip to content
This repository was archived by the owner on Jun 23, 2026. It is now read-only.

Commit dbcc24e

Browse files
committed
fix(deps): bump devalue to 5.8.1 to resolve GHSA-77vg-94rm-hx3p
devalue 5.6.3-5.8.0 has a high-severity DoS vulnerability via sparse array deserialization. Pulled in transitively via astro and @astrojs/react. Bump the lockfile entry to 5.8.1 to unblock `npm audit` (and therefore CI) on all open PRs.
1 parent a266a05 commit dbcc24e

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

package-lock.json

Lines changed: 3 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)