From 9eb188d3dbd2029cc9cf5bae75cd81fde3533ee9 Mon Sep 17 00:00:00 2001 From: hs2323 Date: Sat, 18 Apr 2026 09:10:25 -0400 Subject: [PATCH] Updating sub-dependency vite to 6.42. and 7.3.2 due to CVE-2026-39363, CVE-2026-39364 and CVE-2026-39365 --- CHANGELOG.md | 1 + package-lock.json | 18 +++++++++--------- 2 files changed, 10 insertions(+), 9 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e472afe..bf60810 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Security +- Updated sub-dependency vite to 6.42. and 7.3.2 due to CVE-2026-39363, CVE-2026-39364 and CVE-2026-39365. - Updated sub-dependency defu to 6.1.6 due to CVE-2026-35209. - Updated sub-dependency yaml to 1.10.3 and 2.8.3 due to CVE-2026-33532. - Updated sub-dependency smol-toml to 1.6.1 due to GHSA-v3rj-xjv7-4jmq. diff --git a/package-lock.json b/package-lock.json index a80acf0..0f95c49 100644 --- a/package-lock.json +++ b/package-lock.json @@ -640,9 +640,9 @@ } }, "node_modules/@astrojs/react/node_modules/vite": { - "version": "6.4.1", - "resolved": "https://registry.npmjs.org/vite/-/vite-6.4.1.tgz", - "integrity": "sha512-+Oxm7q9hDoLMyJOYfUYBuHQo+dkAloi33apOPP56pzj+vsdJDzr+j1NISE5pyaAuKL4A3UD34qd0lx5+kfKp2g==", + "version": "6.4.2", + "resolved": "https://registry.npmjs.org/vite/-/vite-6.4.2.tgz", + "integrity": "sha512-2N/55r4JDJ4gdrCvGgINMy+HH3iRpNIz8K6SFwVsA+JbQScLiC+clmAxBgwiSPgcG9U15QmvqCGWzMbqda5zGQ==", "license": "MIT", "dependencies": { "esbuild": "^0.25.0", @@ -4712,9 +4712,9 @@ } }, "node_modules/astro/node_modules/vite": { - "version": "6.4.1", - "resolved": "https://registry.npmjs.org/vite/-/vite-6.4.1.tgz", - "integrity": "sha512-+Oxm7q9hDoLMyJOYfUYBuHQo+dkAloi33apOPP56pzj+vsdJDzr+j1NISE5pyaAuKL4A3UD34qd0lx5+kfKp2g==", + "version": "6.4.2", + "resolved": "https://registry.npmjs.org/vite/-/vite-6.4.2.tgz", + "integrity": "sha512-2N/55r4JDJ4gdrCvGgINMy+HH3iRpNIz8K6SFwVsA+JbQScLiC+clmAxBgwiSPgcG9U15QmvqCGWzMbqda5zGQ==", "license": "MIT", "dependencies": { "esbuild": "^0.25.0", @@ -12392,9 +12392,9 @@ } }, "node_modules/vite": { - "version": "7.3.1", - "resolved": "https://registry.npmjs.org/vite/-/vite-7.3.1.tgz", - "integrity": "sha512-w+N7Hifpc3gRjZ63vYBXA56dvvRlNWRczTdmCBBa+CotUzAPf5b7YMdMR/8CQoeYE5LX3W4wj6RYTgonm1b9DA==", + "version": "7.3.2", + "resolved": "https://registry.npmjs.org/vite/-/vite-7.3.2.tgz", + "integrity": "sha512-Bby3NOsna2jsjfLVOHKes8sGwgl4TT0E6vvpYgnAYDIF/tie7MRaFthmKuHx1NSXjiTueXH3do80FMQgvEktRg==", "devOptional": true, "license": "MIT", "dependencies": {