chore(deps): update dependency vite to v6.3.4 [security]#4968
Merged
renovate[bot] merged 1 commit intodevelopfrom May 13, 2025
Merged
chore(deps): update dependency vite to v6.3.4 [security]#4968renovate[bot] merged 1 commit intodevelopfrom
renovate[bot] merged 1 commit intodevelopfrom
Conversation
|
abbf27d to
e169d20
Compare
e169d20 to
5847d4c
Compare
5847d4c to
c3c9185
Compare
e477518 to
0a394fd
Compare
0a394fd to
e178603
Compare
e178603 to
1f18cd9
Compare
1f18cd9 to
b1cd7a0
Compare
1c9d117 to
b910151
Compare
b910151 to
801ae16
Compare
801ae16 to
fa67c9e
Compare
fa67c9e to
13c6b86
Compare
13c6b86 to
49059e4
Compare
49059e4 to
e1fe9ef
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.3.1->6.3.4GitHub Vulnerability Alerts
CVE-2025-46565
Summary
The contents of files in the project
rootthat are denied by a file matching pattern can be returned to the browser.Impact
Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.
Only files that are under project
rootand are denied by a file matching pattern can be bypassed..env,.env.*,*.{crt,pem},**/.env**/.git/**,.git/**,.git/**/*Details
server.fs.denycan contain patterns matching against files (by default it includes.env,.env.*,*.{crt,pem}as such patterns).These patterns were able to bypass for files under
rootby using a combination of slash and dot (/.).PoC
Release Notes
vitejs/vite (vite)
v6.3.4Compare Source
requireto import externals in optimized dependenci (efc5eab), closes #19940v6.3.3Compare Source
ssrTransformre-export deps and test stacktrace with first line (#19629) (9399cda), closes #19629v6.3.2Compare Source
css.lightningcssoption in css minification process (#19879) (b5055e0), closes #19879Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.