Skip to content

Commit 34679a3

Browse files
authored
fix(deps): bump h3 and flatted overrides to fix security vulnerabilities (#1281)
Bump `pnpm.overrides` floor versions to resolve 3 open Dependabot alerts: | Alert | Package | Severity | Vulnerability | Override Change | |-------|---------|----------|---------------|-----------------| | #188 | `flatted` | HIGH | Prototype Pollution via `parse()` (CVE-2026-33228) | `>=3.4.0` → `>=3.4.2` | | #187 | `h3` | HIGH | SSE Injection via unsanitized newlines (CVE-2026-33128) | `>=1.15.5` → `>=1.15.6` | | #186 | `h3` | MEDIUM | Path Traversal via `%2e%2e` in `serveStatic` | `>=1.15.5` → `>=1.15.6` | Both parent packages (`flat-cache ^3.4.1`, `unstorage ^1.15.5`) accept the patched versions via semver — no forced incompatible upgrades. **Resolved versions:** flatted 3.4.2, h3 1.15.9
1 parent d6b6dbe commit 34679a3

3 files changed

Lines changed: 13 additions & 15 deletions

File tree

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,10 +24,10 @@
2424
"overrides": {
2525
"vite@>=6.0.0 <6.3.6": ">=6.3.6",
2626
"tar": ">=7.5.11",
27-
"h3": ">=1.15.5",
27+
"h3": ">=1.15.6",
2828
"@sveltejs/kit": ">=2.49.5",
2929
"diff": ">=5.2.2",
30-
"flatted": ">=3.4.0",
30+
"flatted": ">=3.4.2",
3131
"yauzl@>=3.0.0": ">=3.2.1",
3232
"devalue": ">=5.6.4",
3333
"rollup@>=4.0.0": ">=4.59.0",

packages/spotlight/package.json

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -32,9 +32,7 @@
3232
"test:e2e:electron": "playwright test tests/electron.test.ts",
3333
"sample": "node ./_fixtures/send_to_sidecar.cjs"
3434
},
35-
"files": [
36-
"dist"
37-
],
35+
"files": ["dist"],
3836
"bin": {
3937
"spotlight": "./dist/run.js"
4038
},

pnpm-lock.yaml

Lines changed: 10 additions & 10 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)