Skip to content

Upgrade Vite past security advisories - #11

Merged
MuteJester merged 1 commit into
mainfrom
agent/vite-security-upgrade
Jul 18, 2026
Merged

Upgrade Vite past security advisories#11
MuteJester merged 1 commit into
mainfrom
agent/vite-security-upgrade

Conversation

@MuteJester

Copy link
Copy Markdown
Owner

What changed

  • upgrade Vite from 5.4.21 to 6.4.3
  • upgrade the bundled esbuild dependency from 0.21.5 to 0.25.12
  • refresh the npm lockfile

Why

Dependabot reported one high- and three medium-severity development-server advisories. Vite 6.4.3 and esbuild 0.25.12 contain the published fixes. The deployed website is a static bundle and was not exposed to these dev-server issues, but the release should not ship with known fixable alerts.

Validation

  • npm audit — zero vulnerabilities
  • npm run build
  • npm exec tsc -- --noEmit

@MuteJester
MuteJester marked this pull request as ready for review July 18, 2026 12:47
@MuteJester
MuteJester merged commit 3d656f8 into main Jul 18, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant