{ "schemaVersion": 1, "reviewedOn": "2026-07-24", "accepted": [ { "id": 1103907, "package": "cookie", "severity": "low", "vulnerableRange": "<0.7.0", "expiresOn": "2026-10-19", "rationale": "GHSA-pxg6-pf52-xh8x: Static site has no cookies, hooks, actions, or forms; cookie serialization is not exercised." }, { "id": 1113319, "package": "devalue", "severity": "low", "vulnerableRange": "<=5.6.2", "expiresOn": "2026-10-19", "rationale": "GHSA-33hq-fvwr-56pm: Prerender serialization receives fixed price/rating/count data; the site does not call parse, unflatten, or uneval." }, { "id": 1113320, "package": "devalue", "severity": "low", "vulnerableRange": "<=5.6.2", "expiresOn": "2026-10-19", "rationale": "GHSA-8qm3-746x-r74r: Prerender serialization receives fixed price/rating/count data; the site does not call parse, unflatten, or uneval." }, { "id": 1114438, "package": "devalue", "severity": "moderate", "vulnerableRange": "<5.6.4", "expiresOn": "2026-10-19", "rationale": "GHSA-cfw5-2vxh-hr84: Prerender serialization receives fixed price/rating/count data; the site does not call parse, unflatten, or uneval." }, { "id": 1121800, "package": "devalue", "severity": "low", "vulnerableRange": ">=4.0.0 <5.6.4", "expiresOn": "2026-10-19", "rationale": "GHSA-mwv9-gp5h-frr4: Prerender serialization receives fixed price/rating/count data; the site does not call parse, unflatten, or uneval." }, { "id": 1115551, "package": "picomatch", "severity": "moderate", "vulnerableRange": ">=4.0.0 <4.0.4", "expiresOn": "2026-10-19", "rationale": "GHSA-3v7f-55p6-f55p: Build-only glob tooling consumes repository-controlled patterns; no deployed runtime or untrusted glob input exists." }, { "id": 1115554, "package": "picomatch", "severity": "high", "vulnerableRange": ">=4.0.0 <4.0.4", "expiresOn": "2026-10-19", "rationale": "GHSA-c2c7-rcm5-vvqj: Build-only glob tooling consumes repository-controlled patterns; no deployed runtime or untrusted glob input exists." }, { "id": 1113515, "package": "rollup", "severity": "high", "vulnerableRange": ">=4.0.0 <4.59.0", "expiresOn": "2026-10-19", "rationale": "GHSA-mw96-cpmx-2vgc: Build-only bundling processes repository-controlled paths and is absent from the deployed static output." }, { "id": 1113416, "package": "svelte", "severity": "moderate", "vulnerableRange": "<=5.51.4", "expiresOn": "2026-10-19", "rationale": "GHSA-crpf-4hrx-3jrp: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1113418, "package": "svelte", "severity": "moderate", "vulnerableRange": "<=5.51.4", "expiresOn": "2026-10-19", "rationale": "GHSA-m56q-vw4c-c2cp: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1113419, "package": "svelte", "severity": "moderate", "vulnerableRange": "<=5.51.4", "expiresOn": "2026-10-19", "rationale": "GHSA-f7gr-6p89-r883: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1113420, "package": "svelte", "severity": "moderate", "vulnerableRange": ">=5.39.3 <5.51.5", "expiresOn": "2026-10-19", "rationale": "GHSA-h7h7-mm68-gmrc: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1114402, "package": "svelte", "severity": "moderate", "vulnerableRange": "<=5.53.4", "expiresOn": "2026-10-19", "rationale": "GHSA-phwv-c562-gvmh: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1118900, "package": "svelte", "severity": "moderate", "vulnerableRange": ">=5.46.0 <=5.55.6", "expiresOn": "2026-10-19", "rationale": "GHSA-f3cj-j4f6-wq85: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1120446, "package": "svelte", "severity": "moderate", "vulnerableRange": "<=5.55.6", "expiresOn": "2026-10-19", "rationale": "GHSA-rcqx-6q8c-2c42: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1120449, "package": "svelte", "severity": "moderate", "vulnerableRange": "<=5.55.6", "expiresOn": "2026-10-19", "rationale": "GHSA-pr6f-5x2q-rwfp: Source trace found none of the affected SSR constructs; the only HTML input is a checked-in constant." }, { "id": 1114591, "package": "undici", "severity": "high", "vulnerableRange": ">=7.0.0 <7.24.0", "expiresOn": "2026-10-19", "rationale": "GHSA-f269-vfmq-vjvj: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1114593, "package": "undici", "severity": "moderate", "vulnerableRange": ">=7.0.0 <7.24.0", "expiresOn": "2026-10-19", "rationale": "GHSA-2mjp-6q6p-2qxm: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1114637, "package": "undici", "severity": "high", "vulnerableRange": ">=7.0.0 <7.24.0", "expiresOn": "2026-10-19", "rationale": "GHSA-vrm6-8vpv-qv8q: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1114639, "package": "undici", "severity": "high", "vulnerableRange": ">=7.0.0 <7.24.0", "expiresOn": "2026-10-19", "rationale": "GHSA-v9p9-hfj2-hcw8: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1114641, "package": "undici", "severity": "moderate", "vulnerableRange": ">=7.0.0 <7.24.0", "expiresOn": "2026-10-19", "rationale": "GHSA-4992-7rv2-5pvq: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1114643, "package": "undici", "severity": "moderate", "vulnerableRange": ">=7.17.0 <7.24.0", "expiresOn": "2026-10-19", "rationale": "GHSA-phc3-fgpg-7m6h: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1121241, "package": "undici", "severity": "moderate", "vulnerableRange": ">=7.0.0 <7.28.0", "expiresOn": "2026-10-19", "rationale": "GHSA-p88m-4jfj-68fv: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1121244, "package": "undici", "severity": "high", "vulnerableRange": ">=7.0.0 <7.28.0", "expiresOn": "2026-10-19", "rationale": "GHSA-vxpw-j846-p89q: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1121249, "package": "undici", "severity": "low", "vulnerableRange": ">=7.0.0 <7.28.0", "expiresOn": "2026-10-19", "rationale": "GHSA-35p6-xmwp-9g52: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1121254, "package": "undici", "severity": "low", "vulnerableRange": ">=7.0.0 <7.28.0", "expiresOn": "2026-10-19", "rationale": "GHSA-g8m3-5g58-fq7m: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." }, { "id": 1121428, "package": "undici", "severity": "moderate", "vulnerableRange": ">=7.0.0 <7.28.0", "expiresOn": "2026-10-19", "rationale": "GHSA-pr7r-676h-xcf6: Build-only scraper calls a fixed Google endpoint; no WebSockets, upgrades, shared cache, cookie parsing, or attacker-selected endpoint." } ] }