Skip to content

fix: vulnerable dep expr-eval-fork#371

Merged
six7 merged 1 commit intotokens-studio:mainfrom
jorenbroekema:fix-vulns
Dec 10, 2025
Merged

fix: vulnerable dep expr-eval-fork#371
six7 merged 1 commit intotokens-studio:mainfrom
jorenbroekema:fix-vulns

Conversation

@jorenbroekema
Copy link
Contributor

@jorenbroekema jorenbroekema commented Dec 9, 2025

@six7 it seems I have adopted expr-eval lib via a fork now and I've been getting a lot of security CVEs raised on it. Worked a fair bit with some of the security researchers behind it to get it fixed on my fork (since origin is fully abandoned).

I think a fair amount of the expr-eval-fork users are via sd-transforms actually, so this'll need a bump now that it's fixed.
Not sure if the NPM token is still valid, you may need to refresh it in NPM and update in this repo settings -> actions secrets

FYI: I also had NPM audit fix a couple of other vulnerable dev deps via pkg lock

@changeset-bot
Copy link

changeset-bot bot commented Dec 9, 2025

🦋 Changeset detected

Latest commit: bc0d51c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@tokens-studio/sd-transforms Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@six7 six7 merged commit 6bd0aff into tokens-studio:main Dec 10, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants