Skip to content

Conversation

@github-actions
Copy link
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@equinor/[email protected]

Patch Changes

  • #3652 8d50adc Thanks @dependabot! - Security: Update Vite to v7.1.12

    This update addresses a security vulnerability in Vite's development server and includes bug fixes for improved compatibility. The update ensures secure development environments and better plugin ecosystem compatibility.

    Changes:

    • Updated Vite from v7.1.10 to v7.1.12
    • Includes security fix for development server file system checks
    • Includes compatibility fix for CommonJS plugin
    • No breaking changes or API modifications

    Security Fix (v7.1.11):

    • dev: trim trailing slash before server.fs.deny check (#20968)
      • Prevents potential path traversal vulnerability in development server
      • Only affects development environment, not production builds

    Bug Fix (v7.1.12):

    • deps: downgrade commonjs plugin to 28.0.6 to avoid rollup/plugins issues (#20990)
      • Improves compatibility with Rollup plugin ecosystem
      • Prevents potential build issues

    All packages using Vite as a development dependency are updated to the latest secure version. This is a patch-level security and bug fix update that maintains full compatibility with existing functionality.

    closes: https://github.com/equinor/fusion/issues/723

  • Updated dependencies [8d50adc]:

@equinor/[email protected]

Patch Changes

  • #3652 8d50adc Thanks @dependabot! - Security: Update Vite to v7.1.12

    This update addresses a security vulnerability in Vite's development server and includes bug fixes for improved compatibility. The update ensures secure development environments and better plugin ecosystem compatibility.

    Changes:

    • Updated Vite from v7.1.10 to v7.1.12
    • Includes security fix for development server file system checks
    • Includes compatibility fix for CommonJS plugin
    • No breaking changes or API modifications

    Security Fix (v7.1.11):

    • dev: trim trailing slash before server.fs.deny check (#20968)
      • Prevents potential path traversal vulnerability in development server
      • Only affects development environment, not production builds

    Bug Fix (v7.1.12):

    • deps: downgrade commonjs plugin to 28.0.6 to avoid rollup/plugins issues (#20990)
      • Improves compatibility with Rollup plugin ecosystem
      • Prevents potential build issues

    All packages using Vite as a development dependency are updated to the latest secure version. This is a patch-level security and bug fix update that maintains full compatibility with existing functionality.

    closes: https://github.com/equinor/fusion/issues/723

@equinor/[email protected]

Patch Changes

  • #3652 8d50adc Thanks @dependabot! - Security: Update Vite to v7.1.12

    This update addresses a security vulnerability in Vite's development server and includes bug fixes for improved compatibility. The update ensures secure development environments and better plugin ecosystem compatibility.

    Changes:

    • Updated Vite from v7.1.10 to v7.1.12
    • Includes security fix for development server file system checks
    • Includes compatibility fix for CommonJS plugin
    • No breaking changes or API modifications

    Security Fix (v7.1.11):

    • dev: trim trailing slash before server.fs.deny check (#20968)
      • Prevents potential path traversal vulnerability in development server
      • Only affects development environment, not production builds

    Bug Fix (v7.1.12):

    • deps: downgrade commonjs plugin to 28.0.6 to avoid rollup/plugins issues (#20990)
      • Improves compatibility with Rollup plugin ecosystem
      • Prevents potential build issues

    All packages using Vite as a development dependency are updated to the latest secure version. This is a patch-level security and bug fix update that maintains full compatibility with existing functionality.

    closes: https://github.com/equinor/fusion/issues/723

  • Updated dependencies [8d50adc]:

@equinor/[email protected]

Patch Changes

  • #3652 8d50adc Thanks @dependabot! - Security: Update Vite to v7.1.12

    This update addresses a security vulnerability in Vite's development server and includes bug fixes for improved compatibility. The update ensures secure development environments and better plugin ecosystem compatibility.

    Changes:

    • Updated Vite from v7.1.10 to v7.1.12
    • Includes security fix for development server file system checks
    • Includes compatibility fix for CommonJS plugin
    • No breaking changes or API modifications

    Security Fix (v7.1.11):

    • dev: trim trailing slash before server.fs.deny check (#20968)
      • Prevents potential path traversal vulnerability in development server
      • Only affects development environment, not production builds

    Bug Fix (v7.1.12):

    • deps: downgrade commonjs plugin to 28.0.6 to avoid rollup/plugins issues (#20990)
      • Improves compatibility with Rollup plugin ecosystem
      • Prevents potential build issues

    All packages using Vite as a development dependency are updated to the latest secure version. This is a patch-level security and bug fix update that maintains full compatibility with existing functionality.

    closes: https://github.com/equinor/fusion/issues/723

@equinor/[email protected]

Patch Changes

  • #3652 8d50adc Thanks @dependabot! - Security: Update Vite to v7.1.12

    This update addresses a security vulnerability in Vite's development server and includes bug fixes for improved compatibility. The update ensures secure development environments and better plugin ecosystem compatibility.

    Changes:

    • Updated Vite from v7.1.10 to v7.1.12
    • Includes security fix for development server file system checks
    • Includes compatibility fix for CommonJS plugin
    • No breaking changes or API modifications

    Security Fix (v7.1.11):

    • dev: trim trailing slash before server.fs.deny check (#20968)
      • Prevents potential path traversal vulnerability in development server
      • Only affects development environment, not production builds

    Bug Fix (v7.1.12):

    • deps: downgrade commonjs plugin to 28.0.6 to avoid rollup/plugins issues (#20990)
      • Improves compatibility with Rollup plugin ecosystem
      • Prevents potential build issues

    All packages using Vite as a development dependency are updated to the latest secure version. This is a patch-level security and bug fix update that maintains full compatibility with existing functionality.

    closes: https://github.com/equinor/fusion/issues/723

[email protected]

Patch Changes

  • #3652 8d50adc Thanks @dependabot! - Security: Update Vite to v7.1.12

    This update addresses a security vulnerability in Vite's development server and includes bug fixes for improved compatibility. The update ensures secure development environments and better plugin ecosystem compatibility.

    Changes:

    • Updated Vite from v7.1.10 to v7.1.12
    • Includes security fix for development server file system checks
    • Includes compatibility fix for CommonJS plugin
    • No breaking changes or API modifications

    Security Fix (v7.1.11):

    • dev: trim trailing slash before server.fs.deny check (#20968)
      • Prevents potential path traversal vulnerability in development server
      • Only affects development environment, not production builds

    Bug Fix (v7.1.12):

    • deps: downgrade commonjs plugin to 28.0.6 to avoid rollup/plugins issues (#20990)
      • Improves compatibility with Rollup plugin ecosystem
      • Prevents potential build issues

    All packages using Vite as a development dependency are updated to the latest secure version. This is a patch-level security and bug fix update that maintains full compatibility with existing functionality.

    closes: https://github.com/equinor/fusion/issues/723

  • Updated dependencies [8d50adc]:

[email protected]

Patch Changes

@github-actions github-actions bot requested review from a team and odinr as code owners October 29, 2025 08:25
@github-actions github-actions bot marked this pull request as draft October 29, 2025 08:25
@Noggling Noggling marked this pull request as ready for review October 29, 2025 08:25
Copilot AI review requested due to automatic review settings October 29, 2025 08:25
@github-actions github-actions bot added 👨🏻‍🍳 cookbooks 💾 CLI fusion framework CLI 📚 documentation Improvements or additions to documentation labels Oct 29, 2025
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This is an automated Changesets release PR that publishes patch versions for multiple Fusion Framework packages following a Vite security update. The release addresses a security vulnerability in Vite's development server and includes compatibility fixes.

  • Updated Vite dependency from v7.1.10 to v7.1.12 across affected packages
  • Published patch versions for 6 packages and 2 cookbooks
  • Removed the changeset file that triggered this release

Reviewed Changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated no comments.

Show a summary per file
File Description
packages/vite-plugins/spa/package.json Version bump from 2.0.0 to 2.0.1
packages/vite-plugins/spa/CHANGELOG.md Added release notes for v2.0.1 with Vite security update details
packages/vite-plugins/api-service/package.json Version bump from 1.2.2 to 1.2.3
packages/vite-plugins/api-service/CHANGELOG.md Added release notes for v1.2.3 with Vite security update details
packages/dev-server/package.json Version bump from 1.1.8 to 1.1.9
packages/dev-server/CHANGELOG.md Added release notes for v1.1.9 including dependency updates
packages/dev-portal/package.json Version bump from 1.2.2 to 1.2.3
packages/dev-portal/CHANGELOG.md Added release notes for v1.2.3 with Vite security update details
packages/cli/package.json Version bump from 12.3.5 to 12.3.6
packages/cli/CHANGELOG.md Added release notes for v12.3.6 including dependency updates
cookbooks/portal/package.json Version bump from 0.1.4 to 0.1.5
cookbooks/portal/CHANGELOG.md Added release notes for v0.1.5 with dependency update
cookbooks/poc-portal/package.json Version bump from 1.1.14 to 1.1.15
cookbooks/poc-portal/CHANGELOG.md Added release notes for v1.1.15 with Vite security update details
.changeset/honest-bats-pay.md Removed changeset file that triggered this release

@github-actions
Copy link
Contributor Author

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 6.96% 53537 / 768140
🔵 Statements 6.96% 53537 / 768140
🔵 Functions 43.8% 530 / 1210
🔵 Branches 64.02% 952 / 1487
File CoverageNo changed files found.
Generated in workflow #10930 for commit 43d4223 by the Vitest Coverage Report Action

@Noggling Noggling merged commit 4f2e610 into main Oct 29, 2025
6 checks passed
@Noggling Noggling deleted the changeset-release/main branch October 29, 2025 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

💾 CLI fusion framework CLI 👨🏻‍🍳 cookbooks 📚 documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants