Skip to content

Fix serialize-javascript CPU exhaustion vulnerability (GHSA-qj8w-gfj5-8c6v)#195

Merged
zawata merged 2 commits intomasterfrom
fix/dependabot-serialize-javascript
Apr 1, 2026
Merged

Fix serialize-javascript CPU exhaustion vulnerability (GHSA-qj8w-gfj5-8c6v)#195
zawata merged 2 commits intomasterfrom
fix/dependabot-serialize-javascript

Conversation

@zawata
Copy link
Copy Markdown
Contributor

@zawata zawata commented Mar 31, 2026

Summary

Test plan

  • All 27 existing tests pass

🤖 Generated with Claude Code

…-8c6v)

Update serialize-javascript resolution from ^7.0.3 to ^7.0.5 to address
CVE for CPU Exhaustion Denial of Service via crafted array-like objects.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@zawata zawata requested a review from Mr-Wallet March 31, 2026 23:42
@zawata zawata self-assigned this Mar 31, 2026
@Mr-Wallet
Copy link
Copy Markdown
Contributor

Mr-Wallet commented Apr 1, 2026

Performed evil merge: resolved conflict in resolutions. (Adjacent line had a version change.)

@zawata zawata merged commit ab8d518 into master Apr 1, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants