chore: [security] bump vite from 5.4.11 to 5.4.12 #370
No reviewers
Labels
No labels
bug
confirmed
critical
dependencies
discussion
docker
documentation
enhancement
go
javascript
security
severity:high
severity:low
severity:moderate
suggestion
support
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
marty-media/server!370
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "dependabot-npm_and_yarn-develop-vite-5.4.12"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Bumps vite from 5.4.11 to 5.4.12. This update includes a security fix.
Vulnerabilities fixed
... (truncated)
Changelog
Sourced from vite's changelog.
Commits
f428aa9release: v5.4.129da4abcfix!: check host header to prevent DNS rebinding attacks and introduce `serve...b71a5c8fix: verify token for HMR WebSocket connectiondfea38ffix!: defaultserver.cors: falseto disallow fetching from untrusted originsecd2375chore: add deps update changelogassigned to @martinr92
mentioned in merge request !345
restored source branch
dependabot-npm_and_yarn-develop-vite-5.4.12added 12 commits
develop7abb9133- chore: [security] bump vite from 5.4.11 to 5.4.12Compare with previous version
SonarQube Cloud Code Analysis
Quality Gate passed
Issues
0 New issues
0 Accepted issues
Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code
See analysis details on SonarQube Cloud
🎉 This MR is included in version 0.6.0-beta.1 🎉
The release is available on GitLab release.
Your semantic-release bot 📦 🚀
🎉 This MR is included in version 0.6.0 🎉
The release is available on GitLab release.
Your semantic-release bot 📦 🚀