Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Conversation

dargmuesli
Copy link
Contributor

@dargmuesli dargmuesli commented Jul 20, 2025

Resolves GHSA-76c9-3jph-rj3q

Closes #825

Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcompression@​1.7.4 ⏵ 1.8.199 +1100100 +189100

View full report

@MikeMcC399

This comment was marked as resolved.

@dargmuesli

This comment was marked as resolved.

@shlomisas
Copy link

Hi guys any idea when it'll be released?

@MikeMcC399
Copy link

@shlomisas

Hi guys any idea when it'll be released?

That would depend on actions from a maintainer and so far there has been no response to this PR or to the related issue #825

@PieterT2000
Copy link

See #825 (comment) for a temporary workaround

@jimthedev
Copy link

I sent vercel a message on social media to see if they will send someone over to hit the button.

@MikeMcC399
Copy link

@jimthedev

I sent vercel a message on social media to see if they will send someone over to hit the button.

... and did you succeed in getting any response?

@jimthedev
Copy link

Sadly no.

@MikeMcC399
Copy link

@jimthedev

Thanks for trying!

@MikeMcC399

This comment was marked as resolved.

@AndyBitz
Copy link
Contributor

AndyBitz commented Sep 4, 2025

@dargmuesli Thanks for the PR! I'll create a new release shortly

@AndyBitz AndyBitz merged commit cfaff36 into vercel:main Sep 4, 2025
1 check passed
@MikeMcC399
Copy link

MikeMcC399 commented Sep 4, 2025

@AndyBitz

Thanks for merging the PR! Unfortunately it seems that CI is failing due to some outdated usage.

Do you need any assistance in updating the GitHub Action workflows to get them to work?

@AndyBitz
Copy link
Contributor

AndyBitz commented Sep 4, 2025

@MikeMcC399 I'm already on it, no worries

@AndyBitz
Copy link
Contributor

AndyBitz commented Sep 4, 2025

We've just published serve@14.2.5 which includes those changes. Thanks again!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Low severity vulnerability in on-headers@1.0.2 CVE-2025-7339

6 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.