Repository navigation
fix(dev-1703): bump vite to 6.4.3 - #74
Merged
Merged
Conversation
There was a problem hiding this comment.
Verified diff scope is package.json and pnpm-lock.yaml only. Gate 3 PASS via gate3-check.sh: pr_version 6.4.4 meets required 6.4.3 across alerts 54, 82, 83; state open; extra_files 0. No .github changes. All commits authored by spur-vuln-author bot. CI all green.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
Three open Dependabot advisories against
viteinpnpm-lock.yaml(GHSA-v6wh-96g9-6wx3, GHSA-fx2h-pf6j-xcff, GHSA-4w7w-66w2-5vf9 — medium/high/medium) are fixed by the same version bump.viteis a transitive dependency here (pulled in byvitest/@vitejs/plugin-react; no package.json declares it directly), currently resolved at5.4.21. No Dependabot PR exists for this finding, so this PR was constructed directly from the alerts' ownfirst_patched_versiondata (highest across the group:6.4.3), per the vulnerability-remediation policy'sconstruct-prpath.Because
vitehas no direct specifier anywhere in the workspace, the fix adds apnpm.overridesentry ("vite": "^6.4.3") to the rootpackage.jsonand regeneratespnpm-lock.yamlwithpnpm install --lockfile-only. This resolved tovite@6.4.4.Note this is a cross-major bump (5.4.x → 6.4.4) for the affected transitive dependency;
remediate.shdid not flag this finding with ahigh_scrutinysignal, so it is submitted as a standard mechanical construct-pr forspur-vuln-reviewto evaluate on its own merits (real CI result, diff review).Test evidence
pnpm install --lockfile-onlycompleted successfully with the override in place;pnpm-lock.yamlnow resolvesviteat6.4.4(>= the6.4.3first_patched_version for all three advisories). No Dependabot PR existed to replay, so there is no prior CI run to compare against — CI on this PR is the first real signal. A companion-file scan (companion-scan.sh pnpm-lock.yaml 5.4.21) found no hardcoded companion files referencing the old version.Risk
Medium — one-way-ish door: this is a major-version bump of a transitive build/test tool (
vite), done via a forced override rather than a direct dependency bump, so there's a real chance of incompatibility withvitest/@vitejs/plugin-react's expectedvitepeer range that only CI (or a human reviewer) can confirm. Blast radius is limited to the build/test toolchain —viteis not a published runtime dependency of any package in this workspace.