Skip to content

Bump devalue from 5.9.2 to 5.9.4 - #1393

Merged
AdmiringWorm merged 1 commit into
masterfrom
dependabot/npm_and_yarn/devalue-5.9.4
Oct 8, 2026
Merged

AdmiringWorm merged 1 commit into
masterfrom
dependabot/npm_and_yarn/devalue-5.9.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps devalue from 5.9.2 to 5.9.4.

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Changelog

Sourced from devalue's changelog.

5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Commits

@AdmiringWorm

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [devalue](https://github.com/sveltejs/devalue) from 5.9.2 to 5.9.4.
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

---
updated-dependencies:
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/devalue-5.9.4 branch from 1ef6ff7 to ca511d4 Compare October 8, 2026 10:08
@AdmiringWorm
AdmiringWorm enabled auto-merge October 8, 2026 10:10

@AdmiringWorm AdmiringWorm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@AdmiringWorm
AdmiringWorm disabled auto-merge October 8, 2026 10:11
@AdmiringWorm
AdmiringWorm merged commit 03f42cd into master Oct 8, 2026
1 check passed
@AdmiringWorm
AdmiringWorm deleted the dependabot/npm_and_yarn/devalue-5.9.4 branch October 8, 2026 10:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant