| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Bumps [vm2](https://github.com/patriksimek/vm2) from 3.9.5 to 3.11.5. - [Release notes](https://github.com/patriksimek/vm2/releases) - [Changelog](https://github.com/patriksimek/vm2/blob/main/CHANGELOG.md) - [Commits](patriksimek/vm2@3.9.5...v3.11.5) --- updated-dependencies: - dependency-name: vm2 dependency-version: 3.11.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
| Back | FazBrowse Home | New Git URL |
Bumps vm2 from 3.9.5 to 3.11.5.
Release notesSourced from vm2's releases.
... (truncated)
ChangelogSourced from vm2's changelog.
... (truncated)
Commits- 7a1f510 Fix .node typo (#568)
- fac7fb4 fix: test compatibility
- 2da83ed fix(#567): restore array iteration on vm.freeze()'d host arrays
- 51cc4bc fix(#566): restore util.inspect output on Node 26+
- 27354d5 fix: test compatibility
- 59ccba9 feat: add merge-fix skill for integrating confirmed vulnerability fixes
- 86ab819 fix(GHSA-m4wx-m65x-ghrr): widen NESTING_OVERRIDE guard to all input shapes
- e1c48fc fix(GHSA-9g8x-92q2-p28f): deny process-wide observability builtins in NodeVM
- 436053e fix(GHSA-r9pm-gxmw-wv6p): exclude underscored builtins from NodeVM '*' wildca...
- a1ed47a fix(GHSA-rp36-8xq3-r6c4): close NodeVM builtin denylist bypass via process/in...
- Additional commits viewable in compare view
Maintainer changesThis version was pushed to npm by GitHub Actions, a new releaser for vm2 since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
You can disable automated security fix PRs for this repo from the Security Alerts page.