Skip to content

[CVE] Bump serialize-javascript#5689

Open
cmalonzo wants to merge 1 commit intomicrosoft:mainfrom
cmalonzo:cmalonzo/cve/serialize-javascript
Open

[CVE] Bump serialize-javascript#5689
cmalonzo wants to merge 1 commit intomicrosoft:mainfrom
cmalonzo:cmalonzo/cve/serialize-javascript

Conversation

@cmalonzo
Copy link
Contributor

@cmalonzo cmalonzo commented Mar 6, 2026

Addresses 5686

"@rushstack/heft": "workspace:*",
"@types/node": "20.17.19",
"@types/serialize-javascript": "5.0.2",
"@types/serialize-javascript": "5.0.4",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The major version mismatch is concerning.

"changes": [
{
"packageName": "@rushstack/module-minifier",
"comment": "Bump serialize-javascript",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
"comment": "Bump serialize-javascript",
"comment": "Bump `serialize-javascript` to partially mitigate CVE-2020-7660.",

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Needs triage

Development

Successfully merging this pull request may close these issues.

2 participants