From 77ec3e2170b7e178b848d70542ac151ea3682ff5 Mon Sep 17 00:00:00 2001 From: Panagiotis Papadopoulos Date: Mon, 14 Apr 2025 19:33:37 +0200 Subject: [PATCH] fix(deps): update vite from 6.2.5 to 6.2.6 fixes vulnerability vite 6.2.0 - 6.2.5 Severity: moderate Vite has an `server.fs.deny` bypass with an invalid `request-target` - https://github.com/advisories/GHSA-356w-63v5-8wf4 --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 125fbb4c9..1fb750095 100644 --- a/package-lock.json +++ b/package-lock.json @@ -20763,9 +20763,9 @@ } }, "node_modules/vite": { - "version": "6.2.5", - "resolved": "https://registry.npmjs.org/vite/-/vite-6.2.5.tgz", - "integrity": "sha512-j023J/hCAa4pRIUH6J9HemwYfjB5llR2Ps0CWeikOtdR8+pAURAk0DoJC5/mm9kd+UgdnIy7d6HE4EAvlYhPhA==", + "version": "6.2.6", + "resolved": "https://registry.npmjs.org/vite/-/vite-6.2.6.tgz", + "integrity": "sha512-9xpjNl3kR4rVDZgPNdTL0/c6ao4km69a/2ihNQbcANz8RuCOK3hQBmLSJf3bRKVQjVMda+YvizNE8AwvogcPbw==", "dev": true, "license": "MIT", "dependencies": {