Skip to content

fix(security): pin serialize-javascript to >=7.0.5 via npm overrides …#1097

Merged
yash6195 merged 1 commit intopre_prodfrom
security/fix-serialize-javascript-rce-aps-18800
May 7, 2026
Merged

fix(security): pin serialize-javascript to >=7.0.5 via npm overrides …#1097
yash6195 merged 1 commit intopre_prodfrom
security/fix-serialize-javascript-rce-aps-18800

Conversation

@yash6195
Copy link
Copy Markdown
Collaborator

@yash6195 yash6195 commented May 7, 2026

APS-18800

Fixes GHSA-5c6j-r48x-rmvq (RCE) and GHSA-qj8w-gfj5-8c6v (DoS) in the transitive serialize-javascript dependency pulled in by mocha. Uses npm's native overrides field — no third-party workarounds needed.

…[APS-18800]

Fixes GHSA-5c6j-r48x-rmvq (RCE) and GHSA-qj8w-gfj5-8c6v (DoS) in the
transitive serialize-javascript dependency pulled in by mocha. Uses npm's
native `overrides` field — no third-party workarounds needed.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@yash6195 yash6195 merged commit 088ddaa into pre_prod May 7, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants