Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 7, 2025

This PR contains the following updates:

Package Change Age Confidence
@nuxt/devtools (source) 2.5.0 -> 2.6.4 age confidence

GitHub Vulnerability Alerts

CVE-2025-52662

A vulnerability in Nuxt DevTools has been fixed in version 2.6.4*. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade.


Release Notes

nuxt/devtools (@​nuxt/devtools)

v2.6.4

Compare Source

Bug Fixes
  • using textContent instead of innerHtml for auth pagechore: update lock (7cadbbe)

v2.6.3

Compare Source

v2.6.2

Compare Source

Bug Fixes

v2.6.1

Compare Source

Bug Fixes

v2.6.0

Compare Source

Bug Fixes
Features

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Nov 7, 2025
@coderabbitai
Copy link

coderabbitai bot commented Nov 7, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security
Copy link

socket-security bot commented Nov 7, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedplaywright@​1.53.11009310099100
Added@​nuxt/​kit@​3.20.19910010095100
Updated@​nuxt/​devtools@​2.5.0 ⏵ 2.6.498 +1100 +810099100

View full report

@renovate renovate bot force-pushed the renovate/npm-nuxt-devtools-vulnerability branch from f181506 to cfe4c83 Compare November 11, 2025 02:36
@pkg-pr-new
Copy link

pkg-pr-new bot commented Nov 11, 2025

Open in StackBlitz

@poupe/css

npm i https://pkg.pr.new/poupe-ui/poupe/@poupe/css@474

@poupe/nuxt

npm i https://pkg.pr.new/poupe-ui/poupe/@poupe/nuxt@474

@poupe/tailwindcss

npm i https://pkg.pr.new/poupe-ui/poupe/@poupe/tailwindcss@474

@poupe/theme-builder

npm i https://pkg.pr.new/poupe-ui/poupe/@poupe/theme-builder@474

@poupe/vue

npm i https://pkg.pr.new/poupe-ui/poupe/@poupe/vue@474

commit: 89a6a86

@renovate renovate bot force-pushed the renovate/npm-nuxt-devtools-vulnerability branch from cfe4c83 to 89a6a86 Compare November 19, 2025 23:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant