fix(deps): bump vite to 6.4.2 (GHSA-4w7w-66w2-5vf9, GHSA-p9ff-h696-f583) #77

Merged
maximus merged 1 commit from issue-59-bump-vite into main 2026-04-14 12:29:09 +00:00
Owner

Summary

  • Bumped vite 6.4.1 → 6.4.2 via npm audit fix
  • Resolves 1 HIGH severity vulnerability (path traversal in .map handling + arbitrary file read via dev server WebSocket)

Verification

  • npm audit → 0 vulnerabilities
  • npm run build → ok (vite 6.4.2, built in 5.25s)
  • npm test → 25/25 passing

Closes #59

## Summary - Bumped `vite` 6.4.1 → 6.4.2 via `npm audit fix` - Resolves 1 HIGH severity vulnerability (path traversal in `.map` handling + arbitrary file read via dev server WebSocket) ## Verification - `npm audit` → 0 vulnerabilities - `npm run build` → ok (vite 6.4.2, built in 5.25s) - `npm test` → 25/25 passing Closes #59
maximus added 1 commit 2026-04-13 22:05:46 +00:00
fix(deps): bump vite to 6.4.2 to resolve GHSA-4w7w-66w2-5vf9 and GHSA-p9ff-h696-f583
All checks were successful
PR Check / rust (push) Successful in 17m28s
PR Check / frontend (push) Successful in 2m15s
PR Check / rust (pull_request) Successful in 17m33s
PR Check / frontend (pull_request) Successful in 2m17s
813d29e38a
Closes #59

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
maximus merged commit 440a43683d into main 2026-04-14 12:29:09 +00:00
maximus deleted branch issue-59-bump-vite 2026-04-14 12:29:09 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: maximus/Simpl-Resultat#77
No description provided.