Skip to content

Override flatted >=3.4.2 to fix GHSA-rf6f-7fwh-wjgh#452

Merged
remusao merged 4 commits intomainfrom
security/override-flatted
Mar 20, 2026
Merged

Override flatted >=3.4.2 to fix GHSA-rf6f-7fwh-wjgh#452
remusao merged 4 commits intomainfrom
security/override-flatted

Conversation

@kdenhartog
Copy link
Copy Markdown
Member

@kdenhartog kdenhartog commented Mar 20, 2026

Adds an overrides entry for flatted to force >=3.4.2, resolving the prototype pollution vulnerability reported in GHSA-rf6f-7fwh-wjgh.

connected to brave/brave-browser#53816

flatted is a transitive dependency (eslint → file-entry-cache → flat-cache → flatted). flat-cache@4.0.1 allows ^3.2.9 so 3.4.2 satisfies the range — this override forces the resolved version up to the patched release.

Force flatted >=3.4.2 to resolve prototype pollution via parse()
reported in brave/brave-browser#53816
@kdenhartog kdenhartog requested review from a team, mihaiplesa, remusao and yshym as code owners March 20, 2026 05:35
- jsdom 22.1.0 → 29.0.1 (fixes GHSA-vpq2-c234-7xj6 via @tootallnate/once)
- mocha 10.2.0 → 10.8.2 (fixes GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74 via minimatch)
- web-ext 9.3.0 → 9.4.0 (fixes GHSA-2g4f-4pwh-qvx6 via ajv in addons-linter)

Remaining 4 moderate findings (yauzl via addons-scanner-utils) require
web-ext@10 which is a breaking change — deferred.
@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 20, 2026

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@remusao remusao merged commit 965f795 into main Mar 20, 2026
10 of 11 checks passed
@remusao remusao deleted the security/override-flatted branch March 20, 2026 09:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants