π¨ a CVE for `devalue` has been published we use devalue in @nuxt.com@bsky.brid.gy to send payloads to the client - so you'll get automated warnings. π BUT nuxt users are not vulnerable to this particular issue still, it's an important reminder to refresh your lockfile to update your transitive dependencies.
If you have a fediverse account, you can quote this note from your own instance. Search https://bsky.brid.gy/convert/ap/at://did:plc:jbeaa5kdaladzwq3r7f5xgwe/app.bsky.feed.post/3mcidtc4ttt2a on your instance and quote it. (Note that quoting is not supported in Mastodon.)