This repository was archived by the owner on Jun 23, 2026. It is now read-only.
Commit dbcc24e
committed
fix(deps): bump devalue to 5.8.1 to resolve GHSA-77vg-94rm-hx3p
devalue 5.6.3-5.8.0 has a high-severity DoS vulnerability via
sparse array deserialization. Pulled in transitively via astro
and @astrojs/react. Bump the lockfile entry to 5.8.1 to unblock
`npm audit` (and therefore CI) on all open PRs.1 parent a266a05 commit dbcc24e
1 file changed
Lines changed: 3 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments