chore: [security] bump vite from 6.2.2 to 6.2.6 #442
No reviewers
Labels
No labels
bug
confirmed
critical
dependencies
discussion
docker
documentation
enhancement
go
javascript
security
severity:high
severity:low
severity:moderate
suggestion
support
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
marty-media/server!442
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "dependabot-npm_and_yarn-develop-vite-6.2.6"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Bumps vite from 6.2.2 to 6.2.6. This update includes security fixes.
Vulnerabilities fixed
... (truncated)
... (truncated)
... (truncated)
... (truncated)
Changelog
Sourced from vite's changelog.
Commits
d3dbf25release: v6.2.63bb0883fix: reject requests with#in request-target (#19830)c176acfrelease: v6.2.5fdb196efix: backport #19782, fs check with svg and relative paths037f801release: v6.2.47a4fabafix: fs check in transform middleware (#19761)16869d7release: v6.2.3f234b57fix: fs raw query with query separators (#19702)assigned to @martinr92
mentioned in merge request !415
added 5 commits
developd9607113- chore: [security] bump vite from 6.2.2 to 6.2.6Compare with previous version
SonarQube Cloud Code Analysis
Quality Gate passed
Issues
0 New issues
0 Accepted issues
Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code
See analysis details on SonarQube Cloud
🎉 This MR is included in version 0.8.0-beta.1 🎉
The release is available on GitLab release.
Your semantic-release bot 📦 🚀
🎉 This MR is included in version 0.8.0 🎉
The release is available on GitLab release.
Your semantic-release bot 📦 🚀