Skip to content

Commit ab8d518

Browse files
authored
Merge pull request #195 from Axosoft/fix/dependabot-serialize-javascript
Fix serialize-javascript CPU exhaustion vulnerability (GHSA-qj8w-gfj5-8c6v)
2 parents 52e3b07 + 8864695 commit ab8d518

2 files changed

Lines changed: 5 additions & 5 deletions

File tree

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@
4040
"mocha": "^10.6.0"
4141
},
4242
"resolutions": {
43-
"serialize-javascript": "^7.0.3",
43+
"serialize-javascript": "^7.0.5",
4444
"picomatch": "^2.3.2"
4545
},
4646
"keywords": [

yarn.lock

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -851,10 +851,10 @@ run-parallel@^1.1.9:
851851
dependencies:
852852
queue-microtask "^1.2.2"
853853

854-
serialize-javascript@^6.0.2, serialize-javascript@^7.0.3:
855-
version "7.0.4"
856-
resolved "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.4.tgz#c517735bd5b7631dd1fc191ee19cbb713ff8e05c"
857-
integrity sha512-DuGdB+Po43Q5Jxwpzt1lhyFSYKryqoNjQSA9M92tyw0lyHIOur+XCalOUe0KTJpyqzT8+fQ5A0Jf7vCx/NKmIg==
854+
serialize-javascript@^6.0.2, serialize-javascript@^7.0.5:
855+
version "7.0.5"
856+
resolved "https://registry.yarnpkg.com/serialize-javascript/-/serialize-javascript-7.0.5.tgz#c798cc0552ffbb08981914a42a8756e339d0d5b1"
857+
integrity sha512-F4LcB0UqUl1zErq+1nYEEzSHJnIwb3AF2XWB94b+afhrekOUijwooAYqFyRbjYkm2PAKBabx6oYv/xDxNi8IBw==
858858

859859
shebang-command@^2.0.0:
860860
version "2.0.0"

0 commit comments

Comments
 (0)