From 10039d29be3f7d60eb840e8276f9f4cac420ea3f Mon Sep 17 00:00:00 2001 From: frantuma Date: Fri, 2 Oct 2026 15:19:00 +0200 Subject: [PATCH] fix(deps): update serialize-javascript to 7.1.2 Resolves GHSA-gfhx-hw2g-v5hg (CVE-2026-97711), an XSS regression in 7.1.1 where a function body could carry an unescaped into the output. It fails the dependency-audit job. copy-webpack-plugin and mocha already allow 7.1.2, so only the lockfile changes. The package is build and test tooling only and is not bundled into the extension or the server. --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 923b560..3623ae9 100644 --- a/package-lock.json +++ b/package-lock.json @@ -12452,9 +12452,9 @@ } }, "node_modules/serialize-javascript": { - "version": "7.1.1", - "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.1.1.tgz", - "integrity": "sha512-k3CMsaIvvdSwm8oLB4MXSl0wH2/cwlH7xGcnRd2DaeRmBkbzYmyT8j0tsX60DwD1eRwHTpNpH8ljKu9oUT1MeQ==", + "version": "7.1.2", + "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.1.2.tgz", + "integrity": "sha512-GL2BWwVa6JydKO6l/ljVgjAZF4QJ3S7dWDWi53s5GZT8PJzD2fNxi67HANQGKAqPrwEpL5ba7gUBGi0Ls/sEoQ==", "dev": true, "license": "BSD-3-Clause", "engines": {