Commit cf91ada
committed
deps: upgrade vitest 2→4 (vite 8 / esbuild patched) — clears Dependabot alerts
Fixes the 4 Dependabot advisories (all dev-only, in the vitest/vite/esbuild
test toolchain, never shipped to the production bundle): Vitest UI arbitrary
file RCE, esbuild dev-server request/NPM_CONFIG_REGISTRY issues, and Vite .map
path traversal. npm audit: 0 vulnerabilities. 30 tests still pass.1 parent aeefa3c commit cf91ada
2 files changed
Lines changed: 702 additions & 943 deletions
0 commit comments