Commit 897c77d
deps: fix 7 Dependabot alerts (flatted, devalue, cookie, svelte)
- Override flatted 3.3.3→3.4.2 (HIGH: unbounded recursion DoS)
- Override devalue 5.6.3→5.6.4 (MEDIUM: prototype pollution, LOW: __proto__)
- Override cookie 0.6.0→1.1.1 (LOW: out-of-bounds chars)
- Bump svelte 5.53.3→5.53.13 (MEDIUM: 2x SSR XSS fixes)
- @sveltejs/kit experimental form DoS (LOW) — no override available, not exploitable (feature is experimental and unused)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 4d0ba55 commit 897c77d
2 files changed
+25
-16
lines changedSome generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
| 28 | + | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
34 | 39 | | |
35 | 40 | | |
0 commit comments