All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Svelte Ecosystem Releases Security Patches for 5 Vulnerabilities

By

tobr

4mo ago· 2 min readenNews

Summary

The Svelte ecosystem has released security patches for 5 vulnerabilities affecting multiple packages including devalue, svelte, @sveltejs/kit, and @sveltejs/adapter-node. Users are urged to upgrade to patched versions immediately, with cross-dependent packages already including upgraded dependencies. The article acknowledges security researchers and Vercel's security team for responsible disclosure and collaboration in fixing the vulnerabilities.

Key quotes

· 4 pulled
We've released patches for 5 vulnerabilities across devalue, svelte, @sveltejs/kit, and @sveltejs/adapter-node.
Upgrade now: If you're using any of these packages, upgrade them to their corresponding non-vulnerable versions.
For cross-dependent packages — svelte and @sveltejs/kit depend on devalue — patched versions already include upgraded dependencies.
We're extremely thankful to all of the security researchers who responsibly disclosed these vulnerabilities and worked with us to get them fixed, to the security team at Vercel who helped us navigate the disclosure.
Snippet from the RSS feed
Time to upgrade

You might also wanna read