π¨ [security] Update vite 5.4.19 β 5.4.20 (patch)#38
Conversation
|
You've used up your 5 PR reviews for this month under the Korbit Starter Plan. You'll get 5 more reviews on October 5th, 2025 or you can upgrade to Pro for unlimited PR reviews and enhanced features in your Korbit Console. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
guibranco
left a comment
There was a problem hiding this comment.
Automatically approved by gstraccini[bot]
|
Here's the code health analysis summary for commits Analysis Summary
|
|
@depfu merge |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
03cf70e to
051b90d
Compare
|
Infisical secrets check: π¨ Secrets leaked! Caution The Infisical CLI tool found secrets leaked in your repository. π» Scan logsA new release of infisical is available: 0.41.90 -> 0.41.99
To update, run: sudo apt-get update && sudo apt-get install infisical
10:28PM INF scanning for exposed secrets...
10:28PM INF 37 commits scanned.
10:28PM INF scan completed in 327ms
10:28PM WRN leaks found: 6
π Detected secrets in your GIT history
Warning The above table only displays the first 10 leaked secrets. πΎ Secrets fingerprint2e1522054d3009edd4cc682e479341776b266eb0:src/mockData.ts:generic-api-key:505
2e1522054d3009edd4cc682e479341776b266eb0:src/pages/Integrations.tsx:generic-api-key:12
2e1522054d3009edd4cc682e479341776b266eb0:src/pages/RepositoryDetail.tsx:generic-api-key:124
2e1522054d3009edd4cc682e479341776b266eb0:src/pages/RepositoryDetail.tsx:generic-api-key:160
2e1522054d3009edd4cc682e479341776b266eb0:src/pages/RepositoryDetail.tsx:generic-api-key:178
2e1522054d3009edd4cc682e479341776b266eb0:src/pages/Settings.tsx:generic-api-key:127
Tip If you want to ignore these leaked secrets, add the above fingerprint content to a file named |
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ vite (5.4.19 β 5.4.20) Β· Repo Β· Changelog
Security Advisories π¨
π¨ Vite's `server.fs` settings were not applied to HTML files
π¨ Vite middleware may serve files starting with the same name with the public directory
Release Notes
5.4.20
Does any of this look wrong? Please let us know.
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands
Go to the Depfu Dashboard to see the state of your dependencies and to customize how Depfu works.