Skip to content

fix: update devalue to resolve CVE-2026-42570#79

Closed
dannyneira wants to merge 2 commits into
mainfrom
independabot/devalue-cve-2026-42570
Closed

fix: update devalue to resolve CVE-2026-42570#79
dannyneira wants to merge 2 commits into
mainfrom
independabot/devalue-cve-2026-42570

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

  • Updates the transitive devalue npm dependency from 5.7.1 to 5.8.1 in package-lock.json.
  • Resolves CVE-2026-42570 / GHSA-77vg-94rm-hx3p for sparse array deserialization DoS in Svelte devalue.
  • This is a lockfile-only transitive dependency update; no source changes or overrides were needed.

Security context

Verification

  • npm audit --json confirms devalue_present=false; remaining audit findings are unrelated existing alerts.
  • npm run build
  • npm run typecheck (0 errors; existing hints only)

Conversation: https://staging.warp.dev/conversation/a53b4723-b805-4dc6-b28c-a0d226156c20
Run: https://oz.staging.warp.dev/runs/019e2c5d-c6c2-79b5-bc29-b0c2d63f16f6
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira requested a review from rachaelrenk May 15, 2026 16:06
@cla-bot cla-bot Bot added the cla-signed label May 15, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented May 15, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs Ready Ready Preview, Comment May 15, 2026 7:47pm

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant