What
pnpm audit in frontend/ reports 1 moderate: devalue <5.9.1 DoS via malformed input (GHSA-9rgm-9g3h-6x36), patched in >=5.9.2.
Where
frontend/pnpm-lock.yaml: @sveltejs/kit@2.70.3 depends on devalue: 5.8.1 (vulnerable). svelte@5.57.0 already uses devalue: 5.9.2 (patched).
@sveltejs/kit@2.70.3 is the latest upstream release, so no fixed Kit version exists yet. This is blocked on upstream.
Risk in this app: low
frontend/src uses no Kit remote functions and no direct devalue calls (checked). The attacker-reachable devalue.parse path (remote-function payloads) is not used here. Remaining use is server-serialize to client-parse of page data, which an attacker cannot supply.
Options
- Wait for upstream Kit to bump devalue, then
pnpm update @sveltejs/kit. Preferred.
- Short-term
pnpm.override pinning devalue@>=5.9.2. Only with full frontend test pass, since it overrides a serialization lib under Kit.
Found by the 0.10.1 pre-release audit (Layer 1). The clean-security-scan manifest claim covers the Go backend only, so this does not contradict it, but AUDIT.md tells operators to run pnpm audit and they will see this.
What
pnpm auditinfrontend/reports 1 moderate:devalue <5.9.1DoS via malformed input (GHSA-9rgm-9g3h-6x36), patched in >=5.9.2.Where
frontend/pnpm-lock.yaml:@sveltejs/kit@2.70.3depends ondevalue: 5.8.1(vulnerable).svelte@5.57.0already usesdevalue: 5.9.2(patched).@sveltejs/kit@2.70.3is the latest upstream release, so no fixed Kit version exists yet. This is blocked on upstream.Risk in this app: low
frontend/srcuses no Kit remote functions and no directdevaluecalls (checked). The attacker-reachabledevalue.parsepath (remote-function payloads) is not used here. Remaining use is server-serialize to client-parse of page data, which an attacker cannot supply.Options
pnpm update @sveltejs/kit. Preferred.pnpm.overridepinningdevalue@>=5.9.2. Only with full frontend test pass, since it overrides a serialization lib under Kit.Found by the 0.10.1 pre-release audit (Layer 1). The
clean-security-scanmanifest claim covers the Go backend only, so this does not contradict it, butAUDIT.mdtells operators to runpnpm auditand they will see this.