Skip to content

chore(release): version packages#47

Merged
muneebs merged 1 commit intomainfrom
changeset-release/main
Apr 5, 2026
Merged

chore(release): version packages#47
muneebs merged 1 commit intomainfrom
changeset-release/main

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Apr 5, 2026

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@csrf-armor/core@1.2.2

Patch Changes

  • #46 2eded88 Thanks @muneebs! - fix: resolve high/moderate severity vulnerabilities in transitive dependencies

    Added pnpm overrides to force patched versions of lodash (>=4.18.0) and defu (>=6.1.5), which were pulled in transitively through the nuxt dependency chain. Addresses GHSA-r5fr-rjxr-66jc (lodash code injection), GHSA-f23m-r3pf-42rh (lodash prototype pollution), and GHSA-737v-mqg7-c878 (defu prototype pollution).

@csrf-armor/express@1.2.2

Patch Changes

  • #46 2eded88 Thanks @muneebs! - fix: resolve high/moderate severity vulnerabilities in transitive dependencies

    Added pnpm overrides to force patched versions of lodash (>=4.18.0) and defu (>=6.1.5), which were pulled in transitively through the nuxt dependency chain. Addresses GHSA-r5fr-rjxr-66jc (lodash code injection), GHSA-f23m-r3pf-42rh (lodash prototype pollution), and GHSA-737v-mqg7-c878 (defu prototype pollution).

  • Updated dependencies [2eded88]:

    • @csrf-armor/core@1.2.2

@csrf-armor/nextjs@1.4.2

Patch Changes

  • #46 2eded88 Thanks @muneebs! - fix: resolve high/moderate severity vulnerabilities in transitive dependencies

    Added pnpm overrides to force patched versions of lodash (>=4.18.0) and defu (>=6.1.5), which were pulled in transitively through the nuxt dependency chain. Addresses GHSA-r5fr-rjxr-66jc (lodash code injection), GHSA-f23m-r3pf-42rh (lodash prototype pollution), and GHSA-737v-mqg7-c878 (defu prototype pollution).

  • Updated dependencies [2eded88]:

    • @csrf-armor/core@1.2.2

@csrf-armor/nuxt@1.1.1

Patch Changes

  • #46 2eded88 Thanks @muneebs! - fix: resolve high/moderate severity vulnerabilities in transitive dependencies

    Added pnpm overrides to force patched versions of lodash (>=4.18.0) and defu (>=6.1.5), which were pulled in transitively through the nuxt dependency chain. Addresses GHSA-r5fr-rjxr-66jc (lodash code injection), GHSA-f23m-r3pf-42rh (lodash prototype pollution), and GHSA-737v-mqg7-c878 (defu prototype pollution).

  • Updated dependencies [2eded88]:

    • @csrf-armor/core@1.2.2

@muneebs muneebs merged commit 31156ca into main Apr 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant