Compare commits

...

1 Commits

Author SHA1 Message Date
harshgupta-mem0 638924c544 fix(deps): upgrade vitest 1.5→4.1 + add vite 6 to patch CVE-2026-47429
CVE-2026-47429: vitest < 4.1.0 — arbitrary file read/execute when the
Vitest UI server is listening. dev-only tool but still flagged as critical
by Dependabot.

  vitest  ^1.5.0 → ^4.1.0  (resolved: 4.1.8)
  vite    (new)  → ^6.0.0  (resolved: 6.4.3, required peer dep for vitest 4.x)

115/115 tests pass with the upgraded versions.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 20:36:25 +05:30
2 changed files with 343 additions and 478 deletions
+2 -1
View File
@@ -40,7 +40,8 @@
"typescript": "^5.4.0",
"tsup": "^8.0.0",
"tsx": "^4.7.0",
"vitest": "^1.5.0",
"vite": "^6.0.0",
"vitest": "^4.1.0",
"@biomejs/biome": "^1.7.0",
"@types/node": "^20.0.0"
}
+341 -477
View File
File diff suppressed because it is too large Load Diff