Skip to content

Commit 897c77d

Browse files
ccross2claude
andcommitted
deps: fix 7 Dependabot alerts (flatted, devalue, cookie, svelte)
- Override flatted 3.3.3→3.4.2 (HIGH: unbounded recursion DoS) - Override devalue 5.6.3→5.6.4 (MEDIUM: prototype pollution, LOW: __proto__) - Override cookie 0.6.0→1.1.1 (LOW: out-of-bounds chars) - Bump svelte 5.53.3→5.53.13 (MEDIUM: 2x SSR XSS fixes) - @sveltejs/kit experimental form DoS (LOW) — no override available, not exploitable (feature is experimental and unused) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 4d0ba55 commit 897c77d

File tree

2 files changed

+25
-16
lines changed

2 files changed

+25
-16
lines changed

package-lock.json

Lines changed: 19 additions & 15 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,16 @@
2525
"prettier": "^3.4.0",
2626
"prettier-plugin-svelte": "^3.3.0",
2727
"satori": "^0.19.2",
28-
"svelte": "^5.45.2",
28+
"svelte": "^5.53.13",
2929
"svelte-check": "^4.4.4",
3030
"vite": "^7.3.1"
3131
},
3232
"dependencies": {
3333
"geist": "^1.7.0"
34+
},
35+
"overrides": {
36+
"flatted": "^3.4.2",
37+
"devalue": "^5.6.4",
38+
"cookie": "^1.1.1"
3439
}
3540
}

0 commit comments

Comments
 (0)