Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerability fix : Upgrade vite #72

Merged
merged 1 commit into from
May 21, 2024
Merged

vulnerability fix : Upgrade vite #72

merged 1 commit into from
May 21, 2024

Conversation

yen-tt
Copy link
Collaborator

@yen-tt yen-tt commented May 20, 2024

Upgrade the transitive dependency vite from v4.4.3 to v4.5.3 to address a vulnerability in the package. Specifically to include this fix for fs.deny for case insensitive systems. Note that vite is a transitive dependency for storybook development so this doesn't affect the library build itself.

J=VULN-38716
TEST=auto

Ran unit tests, storybook, and test-site

@yen-tt yen-tt requested a review from a team as a code owner May 20, 2024 17:37
@yen-tt yen-tt changed the title vulnerability fix : Upgrade vite dependency vulnerability fix : Upgrade vite May 21, 2024
@yen-tt yen-tt merged commit 1b7154c into main May 21, 2024
9 checks passed
@yen-tt yen-tt deleted the dev/sec-fix-vite branch May 21, 2024 16:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants