Commit e70df01
UID2-6676: upgrade serialize-javascript to fix GHSA-5c6j-r48x-rmvq RCE
Adds serialize-javascript override to pin to patched version:
- overrides/serialize-javascript: (new) ^7.0.3
GHSA-5c6j-r48x-rmvq: Critical RCE via unsanitized RegExp.flags and
Date.prototype.toISOString() in serialized output, affects
serialize-javascript <= 7.0.2.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 93c117a commit e70df01
2 files changed
Lines changed: 29 additions & 16 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
80 | 80 | | |
81 | 81 | | |
82 | 82 | | |
83 | | - | |
| 83 | + | |
| 84 | + | |
84 | 85 | | |
85 | 86 | | |
86 | 87 | | |
| |||
0 commit comments