Skip to content

Commit 0c2cff9

Browse files
committed
chore(deps): patch devalue + yaml in docs site
Resolves dependabot alerts: - devalue prototype pollution (CVE-2026-42570, high) - yaml stack overflow on deeply nested collections (GHSA-48c2-rrv3-qjmp, moderate) yaml is a deep transitive of @astrojs/check (via @astrojs/language-server → volar-service-yaml → yaml-language-server). Pinned via package.json overrides to bypass the unpatched upstream chain. devalue patched transitively via astro upgrade.
1 parent f69d233 commit 0c2cff9

2 files changed

Lines changed: 330 additions & 48 deletions

File tree

0 commit comments

Comments
 (0)