Newly disclosed RCE vulnerability (GHSA-5c6j-r48x-rmvq) in serialize-javascript <=7.0.2, pulled in as a transitive devDependency via @nestjs/cli > webpack > terser-webpack-plugin. pnpm override bumps it to the patched version. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2.6 KiB
2.6 KiB