Skip to content

fix(deps): upgrade deepmerge-ts to 8.0.1 to fix GHSA-ggr8-5vv4-36mx - #48

Merged
orbivort merged 1 commit into
mainfrom
fix/vulnerability-fix
Aug 18, 2026
Merged

fix(deps): upgrade deepmerge-ts to 8.0.1 to fix GHSA-ggr8-5vv4-36mx#48
orbivort merged 1 commit into
mainfrom
fix/vulnerability-fix

Conversation

@orbivort

Copy link
Copy Markdown
Owner

Description

fix vulnerability

Type of Change

  • Security improvement

Changes Made

Security

  • deepmerge-ts: fix high stack exhaustion (DoS) vulnerability - override to ^8.0.0
    • GHSA-ggr8-5vv4-36mx / CVE-2026-40345: unbounded recursion in deepmerge()/deepmergeInto() when merging recursive object graphs can crash the process with RangeError: Maximum call stack size exceeded (availability only; plain JSON is not affected)

@orbivort
orbivort merged commit 34846a8 into main Aug 18, 2026
34 of 35 checks passed
@orbivort
orbivort deleted the fix/vulnerability-fix branch August 18, 2026 00:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant