Skip to content

Commit b865a0a

Browse files
committed
fix: override vulnerable serialize-javascript
Keep Mocha on the latest stable release while forcing its transitive serializer dependency to a patched version.
1 parent de6a355 commit b865a0a

2 files changed

Lines changed: 10 additions & 16 deletions

File tree

package-lock.json

Lines changed: 6 additions & 15 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -123,7 +123,10 @@
123123
"overrides": {
124124
"diff": "8.0.3",
125125
"esbuild": "0.27.3",
126-
"tar": "7.5.13"
126+
"tar": "7.5.13",
127+
"mocha": {
128+
"serialize-javascript": "7.0.5"
129+
}
127130
},
128131
"contributors": [
129132
"Michael Taylor <5665004+MichaelTaylor3D@users.noreply.github.com>",

0 commit comments

Comments
 (0)