Skip to content

chore(deps): bump vitest to ^4.1.11 (GHSA-82fw-gwwq-j7x9) - #223

Merged
ajianaz merged 1 commit into
developfrom
fix/vitest-security-bump
Sep 11, 2026
Merged

ajianaz merged 1 commit into
developfrom
fix/vitest-security-bump

Conversation

@ajianaz

@ajianaz ajianaz commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

What

  • web/: vitest ^4.1.10 → ^4.1.11 + regenerated bun.lock. No source changes.

Why

GHSA-82fw-gwwq-j7x9 (moderate): Vitest path traversal / arbitrary file read via @vitest/mocker redirect mock, fixed in 4.1.11. The advisory was published after develop's last green CI run, which is why the Bun Audit check now fails on PRs whose dependency set is byte-identical to develop (verified before this change — including this repo's open cla-check PR #222).

Testing

  • RED: CI run 34563284871 (Bun Audit fail) on the untouched dependency set
  • GREEN: bun audit --audit-level=moderate locally after the bump → exits clean
  • Diff scope: web/package.json (1 line) + web/bun.lock (lockfile regen only)
  • Unblocks the currently open cla-check PR once green

GHSA-82fw-gwwq-j7x9 (moderate): Vitest path traversal / arbitrary file
read via @vitest/mocker redirect mock. Fixed in 4.1.11. The advisory
was published after develop's last green CI run, so the dependency
audit now fails on unchanged develop.

Red proven by CI run 34563284871 on the untouched dependency set;
green proven locally after the bump: 'bun audit' exits clean.
No source changes.
@github-actions

Copy link
Copy Markdown

🔍 Cora AI Code Review

⚠️ Review could not complete. LLM API error after retries: Unknown error — check workflow logs


Review powered by cora-code · BYOK · MIT

@ajianaz
ajianaz merged commit e88e88f into develop Sep 11, 2026
14 checks passed
@ajianaz
ajianaz deleted the fix/vitest-security-bump branch September 11, 2026 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant