Commit 34679a3
authored
fix(deps): bump h3 and flatted overrides to fix security vulnerabilities (#1281)
Bump `pnpm.overrides` floor versions to resolve 3 open Dependabot
alerts:
| Alert | Package | Severity | Vulnerability | Override Change |
|-------|---------|----------|---------------|-----------------|
| #188 | `flatted` | HIGH | Prototype Pollution via `parse()`
(CVE-2026-33228) | `>=3.4.0` → `>=3.4.2` |
| #187 | `h3` | HIGH | SSE Injection via unsanitized newlines
(CVE-2026-33128) | `>=1.15.5` → `>=1.15.6` |
| #186 | `h3` | MEDIUM | Path Traversal via `%2e%2e` in `serveStatic` |
`>=1.15.5` → `>=1.15.6` |
Both parent packages (`flat-cache ^3.4.1`, `unstorage ^1.15.5`) accept
the patched versions via semver — no forced incompatible upgrades.
**Resolved versions:** flatted 3.4.2, h3 1.15.91 parent d6b6dbe commit 34679a3
3 files changed
Lines changed: 13 additions & 15 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
35 | | - | |
36 | | - | |
37 | | - | |
| 35 | + | |
38 | 36 | | |
39 | 37 | | |
40 | 38 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments