Skip to content

chore: bump devalue from 5.6.4 to 5.8.1#664

Merged
Fgerthoffert merged 3 commits into
mainfrom
devalue-upgrade
May 19, 2026
Merged

chore: bump devalue from 5.6.4 to 5.8.1#664
Fgerthoffert merged 3 commits into
mainfrom
devalue-upgrade

Conversation

@Fgerthoffert

Copy link
Copy Markdown
Member

Although the vulnerability (https://security.snyk.io/vuln/SNYK-JS-DEVALUE-16697433) is not exploitable in Jahia, this updates the dependency to prevent false alerts in security scanners.

See associated security tickets for details.

@Fgerthoffert
Fgerthoffert requested a review from a team as a code owner May 19, 2026 12:30
@Fgerthoffert
Fgerthoffert requested review from GauBen and Copilot May 19, 2026 12:30
@github-actions

github-actions Bot commented May 19, 2026

Copy link
Copy Markdown

🦜 Chachalog

javascript-modules patch

Create a new entry online or run npx chachalog@0.5.1 prompt to create a new entry locally.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the direct devalue dependency used by the JavaScript modules engine to reduce security scanner noise, but the lockfile still retains another devalue 5.6.4 resolution.

Changes:

  • Bumps javascript-modules-engine’s direct devalue dependency from 5.6.4 to 5.8.1.
  • Adds a new devalue@5.8.1 lockfile entry while preserving the existing devalue@5.6.4 resolution for another selector.

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.

File Description
javascript-modules-engine/package.json Updates the engine package dependency version for devalue.
yarn.lock Records the new direct dependency resolution, but still includes devalue 5.6.4.

Comment thread yarn.lock Outdated
@Fgerthoffert
Fgerthoffert enabled auto-merge (squash) May 19, 2026 12:37
@Fgerthoffert
Fgerthoffert merged commit 8208c8d into main May 19, 2026
23 checks passed
@Fgerthoffert
Fgerthoffert deleted the devalue-upgrade branch May 19, 2026 13:07
@github-actions github-actions Bot mentioned this pull request Jul 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants