From c8fff037498c2dda58fa42dc2b7b86b68476c246 Mon Sep 17 00:00:00 2001 From: escouade-bot Date: Thu, 9 Apr 2026 10:01:14 -0400 Subject: [PATCH] fix(deps): bump vite to resolve high severity vulnerabilities (#59) Update vite past 6.4.1 to fix path traversal (GHSA-4w7w-66w2-5vf9) and arbitrary file read via WebSocket (GHSA-p9ff-h696-f583). --- package-lock.json | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index b7a498e..a80a1da 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "simpl_result_scaffold", - "version": "0.6.6", + "version": "0.6.7", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "simpl_result_scaffold", - "version": "0.6.6", + "version": "0.6.7", "license": "GPL-3.0-only", "dependencies": { "@dnd-kit/core": "^6.3.1", @@ -3297,10 +3297,11 @@ } }, "node_modules/vite": { - "version": "6.4.1", - "resolved": "https://registry.npmjs.org/vite/-/vite-6.4.1.tgz", - "integrity": "sha512-+Oxm7q9hDoLMyJOYfUYBuHQo+dkAloi33apOPP56pzj+vsdJDzr+j1NISE5pyaAuKL4A3UD34qd0lx5+kfKp2g==", + "version": "6.4.2", + "resolved": "https://registry.npmjs.org/vite/-/vite-6.4.2.tgz", + "integrity": "sha512-2N/55r4JDJ4gdrCvGgINMy+HH3iRpNIz8K6SFwVsA+JbQScLiC+clmAxBgwiSPgcG9U15QmvqCGWzMbqda5zGQ==", "dev": true, + "license": "MIT", "dependencies": { "esbuild": "^0.25.0", "fdir": "^6.4.4",