Skip to content

Conversation

@tomwheeler
Copy link
Collaborator

What was changed

I updated Svelte kit and adapter-node libraries and specified explicit dependency on devalue

Why?

This should hopefully address a high-severity dependabot alert opened a few hours ago.

Checklist

  1. Closes

https://github.com/temporalio/reference-app-orders-web/security/dependabot/20

  1. How was this tested:

After making the changes, I ran pnpm into && pnpm dev and then processed an order to completion. I then looked at node_modules/devalue/package.json and verified that the devalue library was version 5.3.2, which dependabot specifies contains the fix.

  1. Any docs updates needed?

No

@tomwheeler tomwheeler merged commit 63d9ac0 into main Aug 29, 2025
5 checks passed
@tomwheeler tomwheeler deleted the tw-dependabot-fixes branch August 29, 2025 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants