Skip to content

Commit 240d168

Browse files
committed
fix(security): patch devalue DoS and h3 request smuggling vulnerabilities
- Update devalue override to >=5.6.2 (fixes memory exhaustion DoS) - Add h3 override >=1.15.5 (fixes HTTP Request Smuggling TE.TE) - Update pnpm to v10.28.0
1 parent e83e911 commit 240d168

File tree

2 files changed

+17
-10
lines changed

2 files changed

+17
-10
lines changed

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,8 @@
4040
"overrides": {
4141
"path-to-regexp": ">=6.3.0",
4242
"esbuild": ">=0.25.0",
43-
"devalue": ">=5.6.2"
43+
"devalue": ">=5.6.2",
44+
"h3": ">=1.15.5"
4445
}
4546
}
4647
}

pnpm-lock.yaml

Lines changed: 15 additions & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)