Skip to content

Bump devalue to 5.9.4 to clear npm audit advisory - #5

Merged
SimmoDev merged 1 commit into
mainfrom
deps/devalue-audit-fix
Sep 20, 2026
Merged

SimmoDev merged 1 commit into
mainfrom
deps/devalue-audit-fix

Conversation

@SimmoDev

Copy link
Copy Markdown
Owner

Resolves GHSA-9rgm-9g3h-6x36 (DoS via malformed input) in the transitive devalue dependency pulled in by svelte.

  • Lockfile-only: devalue 5.8.1 -> 5.9.4, inside svelte's ^5.8.1 range. package.json is unchanged.
  • The new integrity hash matches the npm registry.
  • npm audit reports 0 vulnerabilities after a clean npm ci.
  • 61/61 webui tests, svelte-check and vite build pass; the build output is unchanged in size.
  • devalue is not in the embedded bundle (dist/app.js), so this affects only the dev toolchain.

Resolves GHSA-9rgm-9g3h-6x36 (DoS via malformed input) in the transitive
devalue dependency pulled in by svelte. The lockfile moves from 5.8.1 to
5.9.4, inside svelte's ^5.8.1 range, so package.json is unchanged.
@SimmoDev
SimmoDev merged commit 7c7d43b into main Sep 20, 2026
6 checks passed
@SimmoDev
SimmoDev deleted the deps/devalue-audit-fix branch September 20, 2026 23:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant