From cbecdd18f4a511d1515e8b6d83ec0e30cc0d894a Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 22 Mar 2026 13:26:50 +0100 Subject: [PATCH] =?UTF-8?q?=20=20Bump=20flatted=203.4.1=20=E2=86=92=203.4.?= =?UTF-8?q?2=20to=20fix=20prototype=20pollution?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fixes GHSA-rf6f-7fwh-wjgh (CWE-1321). Dev-only dependency via eslint → file-entry-cache → flat-cache → flatted. --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9b5e3c645..536858bc5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -50,6 +50,7 @@ All notable changes to Bambuddy will be documented in this file. ### Security - **Bump pyOpenSSL 25.3.0 → 26.0.0** — Fixes CVE-2026-27448 (exception swallowing in TLS servername callback) and CVE-2026-27459 (buffer overflow in DTLS cookie callback). - **Bump pyasn1 0.6.2 → 0.6.3** — Fixes CVE-2026-30922 (stack overflow from deeply nested ASN.1 structures). +- **Bump flatted 3.4.1 → 3.4.2** — Fixes GHSA-rf6f-7fwh-wjgh (prototype pollution via `parse()`). Dev-only dependency (eslint). ## [0.2.2] - 2026-03-16