Debian Package Tracker
Register | Log in
Subscribe

node-deepmerge

Node.js module to merge properties of two objects deeply

Choose email to subscribe with

general
  • source: node-deepmerge (main)
  • version: 4.3.1+~1.1.1-1
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Yadd [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.2.2-3
  • oldstable: 4.2.2+~1.1.1-3
  • stable: 4.3.1+~1.1.1-1
  • testing: 4.3.1+~1.1.1-1
  • unstable: 4.3.1+~1.1.1-1
versioned links
  • 4.2.2-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2.2+~1.1.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.3.1+~1.1.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-deepmerge
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-93753: deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Created: 2026-09-19 Last update: 2026-09-19 21:00
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-93753: deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Created: 2026-09-19 Last update: 2026-09-19 21:00
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 4.3.1+~1.1.1-2, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit cfd3dfd1664fdc7f1d9613b68649a4cd8eb4bb45
Author: Xavier Guimard <yadd@debian.org>
Date:   Sat Sep 19 17:49:52 2026 +0200

    Update d/ch

commit 1a9cfa625f8d3312e388c2ce942322c26417b256
Author: Xavier Guimard <yadd@debian.org>
Date:   Sat Sep 19 17:48:00 2026 +0200

    debian/watch version 5

commit 2a4f503e9011a6e3ed2a41cc057765fdb5bfed94
Author: Xavier Guimard <yadd@debian.org>
Date:   Sat Sep 19 17:47:54 2026 +0200

    Drop "Priority: optional"

commit 004fb269ad0e5fd14bd3fa1f007c43d06c5991b2
Author: Xavier Guimard <yadd@debian.org>
Date:   Sat Sep 19 17:47:54 2026 +0200

    Drop "Rules-Requires-Root: no"

commit d820fa3453f56765289c1bfe228fb7c779f35e02
Author: Xavier Guimard <yadd@debian.org>
Date:   Sat Sep 19 17:47:54 2026 +0200

    Declare compliance with policy 4.7.4


https://salsa.debian.org/api/v4/projects/js-team%2Fnode-deepmerge API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-09-19 Last update: 2026-09-19 17:31
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-93753: (needs triaging) deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-19 Last update: 2026-09-19 21:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.2).
Created: 2024-04-07 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2023-11-21] node-deepmerge 4.3.1+~1.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-19] Accepted node-deepmerge 4.3.1+~1.1.1-1 (source) into unstable (Godwin Nweke) (signed by: Praveen Arimbrathodiyil)
  • [2022-10-28] node-deepmerge 4.2.2+~1.1.1-3 MIGRATED to testing (Debian testing watch)
  • [2022-10-28] node-deepmerge 4.2.2+~1.1.1-3 MIGRATED to testing (Debian testing watch)
  • [2022-10-26] Accepted node-deepmerge 4.2.2+~1.1.1-3 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-10-26] Accepted node-deepmerge 4.2.2+~1.1.1-2 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2021-11-24] node-deepmerge 4.2.2+~1.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-11-22] Accepted node-deepmerge 4.2.2+~1.1.1-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2021-01-13] Accepted node-deepmerge 4.2.2-3~bpo10+1 (source all) into buster-backports, buster-backports (Debian FTP Masters) (signed by: Praveen Arimbrathodiyil)
  • [2021-01-03] node-deepmerge 4.2.2-3 MIGRATED to testing (Debian testing watch)
  • [2020-12-31] Accepted node-deepmerge 4.2.2-3 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-10-24] node-deepmerge 4.2.2-2 MIGRATED to testing (Debian testing watch)
  • [2020-10-22] Accepted node-deepmerge 4.2.2-2 (source) into unstable (Xavier Guimard)
  • [2020-10-21] Accepted node-deepmerge 4.2.2-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Xavier Guimard)
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.3.1+~1.1.1-1build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing