Skip to content

bump vite from 8.0.8 to 8.1.0 - #3407

Merged
epszaw merged 1 commit into
mainfrom
bump/vite-8.1.0
Jun 29, 2026
Merged

bump vite from 8.0.8 to 8.1.0#3407
epszaw merged 1 commit into
mainfrom
bump/vite-8.1.0

Conversation

@todti

@todti todti commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bump vite from 8.0.8 to 8.1.0 to fix security vulnerabilities
  • Resolves Dependabot alert for server.fs.deny bypass on Windows alternate paths (High, CVE-2026-53571)
  • Resolves Dependabot alert for NTLMv2 hash disclosure via UNC path handling on Windows (Moderate)

Test plan

  • Verify npm run build completes successfully
  • Verify npm run start works
  • Verify no regressions in e2e tests

@todti todti added pr:dependencies Pull requests that update a dependency pr:security Security vulnerability or fix javascript Pull requests that update Javascript code and removed pr:security Security vulnerability or fix labels Jun 26, 2026
@github-actions

Copy link
Copy Markdown

Allure Report Summary

Name Duration Stats New Flaky Retry Report
Allure 2 – Pull request #3407 12m 58s Passed tests 391   Skipped tests 1 4 0 0 View

@epszaw
epszaw merged commit 705fdab into main Jun 29, 2026
103 of 111 checks passed
@epszaw
epszaw deleted the bump/vite-8.1.0 branch June 29, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

javascript Pull requests that update Javascript code pr:dependencies Pull requests that update a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants