Commit 1a38f2a
committed
fix: resolve all security vulnerabilities
Main project:
- Add overrides for esbuild (^0.25.0) and vite (^6.1.7)
- Force release-it to use undici ^6.24.0 (fixes 3 high severity issues)
Docs project:
- Add overrides for esbuild (^0.27.4) and vite (^8.0.3)
- All vulnerabilities resolved (0 vulnerabilities)
Fixed vulnerabilities:
- GHSA-67mh-4wv8-2f99: esbuild dev server request vulnerability
- GHSA-f269-vfmq-vjvj: undici WebSocket overflow
- GHSA-2mjp-6q6p-2qxm: undici HTTP smuggling
- GHSA-vrm6-8vpv-qv8q: undici memory consumption
- GHSA-v9p9-hfj2-hcw8: undici exception handling
- GHSA-4992-7rv2-5pvq: undici CRLF injection
All tests passing (86/86), build successful.1 parent 640aa81 commit 1a38f2a
File tree
4 files changed
+2022
-1614
lines changed- docs
4 files changed
+2022
-1614
lines changed
0 commit comments