Skip to content

chore(deps): 升级 vite 6.4.1 → 6.4.2(安全修复)#17

Merged
BlueSkyXN merged 1 commit into
mainfrom
dependabot/npm_and_yarn/panel/npm_and_yarn-9b2ff1f3aa
Apr 21, 2026
Merged

chore(deps): 升级 vite 6.4.1 → 6.4.2(安全修复)#17
BlueSkyXN merged 1 commit into
mainfrom
dependabot/npm_and_yarn/panel/npm_and_yarn-9b2ff1f3aa

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

背景

Dependabot 安全更新,修复 vite 6.4.1 中的两个安全漏洞:

  1. 路径遍历漏洞 — optimize deps sourcemap handler 中的路径遍历问题 (#22161)
  2. server.fs 绕过 — env transport 未正确应用 server.fs 检查 (#22163)

变更

文件 变更说明
panel/package-lock.json vite 6.4.1 → 6.4.2

验证

基于最新 main rebase 后 npm update vite 更新,仅修改 lockfile。

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 21, 2026
Security fix: patches path traversal in optimize deps sourcemap handler
and server.fs check for env transport.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@BlueSkyXN BlueSkyXN force-pushed the dependabot/npm_and_yarn/panel/npm_and_yarn-9b2ff1f3aa branch from bfc06bd to 9a791ef Compare April 21, 2026 06:42
@BlueSkyXN BlueSkyXN merged commit 9a791ef into main Apr 21, 2026
14 checks passed
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/panel/npm_and_yarn-9b2ff1f3aa branch April 21, 2026 06:43
@BlueSkyXN BlueSkyXN changed the title chore(deps-dev): Bump vite from 6.4.1 to 6.4.2 in /panel in the npm_and_yarn group across 1 directory chore(deps): 升级 vite 6.4.1 → 6.4.2(安全修复) Apr 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant