Skip to content

Conversation

@peterpeterparker
Copy link
Member

Motivation

Another week, anoter security issue in vite. Similarly to latest incident (#610), we are not affected but, for the state of the art, let's bump vite to resolve CVE-2025-31125.

Changes

  • Bump vite v6.2.4

Copy link
Contributor

@yhabib yhabib left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@peterpeterparker peterpeterparker enabled auto-merge (squash) April 2, 2025 07:51
@peterpeterparker peterpeterparker merged commit 06bec75 into main Apr 2, 2025
11 checks passed
@peterpeterparker peterpeterparker deleted the build/bump-vite-again branch April 2, 2025 07:53
github-merge-queue bot pushed a commit to dfinity/nns-dapp that referenced this pull request Apr 8, 2025
# Motivation

Another week, anoter security issue in vite. Similarly to latest
incidents (dfinity/gix-components#610 and
dfinity/gix-components#614), we are not affected
but, for the state of the art, let's bump vite to resolve
[CVE-2025-31486](GHSA-xcj6-pq6g-qj4x).

# Changes

- Bump vite v6.2.5
- Bumo related dev dependencies

Signed-off-by: David Dal Busco <[email protected]>
peterpeterparker added a commit that referenced this pull request Apr 8, 2025
# Motivation

Another week, anoter security issue in vite. Similarly to latest
incidents (#610 and #614), we are not affected but, for the state of the
art, let's bump vite to resolve
[CVE-2025-31486](GHSA-xcj6-pq6g-qj4x).

# Changes

- Bump vite v6.2.5
- Bumo related dev dependencies
bitdivine pushed a commit that referenced this pull request Apr 10, 2025
# Motivation

Another day, anoter security issue in vite. Similarly to latest
incidents (#610, #614 and #617), we are not affected but, for the state
of the art, let's bump vite to resolve
[GHSA-356w-63v5-8wf4](GHSA-356w-63v5-8wf4).

# Changes

- Bump vite v6.2.6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants