
Security-hardened fork of sift 17.1.3 for CVE-2026-85625. Not affiliated with crcn/sift.js.
Drop-in replacement for sift 17.1.3 that remediates CVE-2026-85625.
Not affiliated with crcn/sift.js.
Object.keys (own properties only), so a polluted Object.prototype.$where is not treated as an operator.$where values are rejected. Function $where still works."overrides": {
"sift": "github:lgranadoi/sift-hardened#17.1.4"
}