Skip to content

Add express video#1408

Merged
zachkirsch merged 1 commit into
mainfrom
zk/express-video
Mar 18, 2023
Merged

Add express video#1408
zachkirsch merged 1 commit into
mainfrom
zk/express-video

Conversation

@zachkirsch
Copy link
Copy Markdown
Contributor

No description provided.

@zachkirsch zachkirsch enabled auto-merge (squash) March 18, 2023 05:11
@zachkirsch zachkirsch merged commit c8d8e5e into main Mar 18, 2023
@zachkirsch zachkirsch deleted the zk/express-video branch March 18, 2023 05:13
github-actions Bot added a commit that referenced this pull request Apr 4, 2026
davidkonigsberg pushed a commit that referenced this pull request Apr 4, 2026
* [Dependabot Alert #1408] Scaffold PR for defu

* chore(deps): fix defu prototype pollution vulnerability (CVE-2026-35209)

Add pnpm override to force defu>=6.1.5, resolving the prototype pollution
vulnerability via __proto__ key in defaults argument (GHSA-737v-mqg7-c878).

defu is a transitive dependency of tsdown. The override ensures all
resolved versions are patched.

Co-Authored-By: unknown <>

* chore(deps): remove unnecessary defu override

Regenerating the lockfile resolves defu to 6.1.6 naturally without
an override, since tsdown declares "defu": "^6.1.4" which is
semver-compatible with the patched version.

Co-Authored-By: unknown <>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
github-actions Bot added a commit that referenced this pull request Apr 7, 2026
davidkonigsberg added a commit that referenced this pull request Apr 7, 2026
…) (#14693)

* [Dependabot Alert #1408] Scaffold PR for defu

* chore(deps): fix defu prototype pollution vulnerability (CVE-2026-35209)

- Add pnpm override for defu>=6.1.5 to resolve HIGH severity prototype pollution
- defu updated from 6.1.4 to 6.1.6 (transitive dep of tsdown)
- Remove dependabot alert scaffold file

Co-Authored-By: unknown <>

* chore(deps): minimize lockfile diff - surgical defu 6.1.4 -> 6.1.6 update

Co-Authored-By: unknown <>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: David Konigsberg <72822263+davidkonigsberg@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant