Skip to content

fix(dev-1703): bump vite to 6.4.3 - #74

Merged
spur-vuln-reviewer[bot] merged 1 commit into
mainfrom
fix/dev-1703
Oct 6, 2026
Merged

spur-vuln-reviewer[bot] merged 1 commit into
mainfrom
fix/dev-1703

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

Three open Dependabot advisories against vite in pnpm-lock.yaml (GHSA-v6wh-96g9-6wx3, GHSA-fx2h-pf6j-xcff, GHSA-4w7w-66w2-5vf9 — medium/high/medium) are fixed by the same version bump. vite is a transitive dependency here (pulled in by vitest/@vitejs/plugin-react; no package.json declares it directly), currently resolved at 5.4.21. No Dependabot PR exists for this finding, so this PR was constructed directly from the alerts' own first_patched_version data (highest across the group: 6.4.3), per the vulnerability-remediation policy's construct-pr path.

Because vite has no direct specifier anywhere in the workspace, the fix adds a pnpm.overrides entry ("vite": "^6.4.3") to the root package.json and regenerates pnpm-lock.yaml with pnpm install --lockfile-only. This resolved to vite@6.4.4.

Note this is a cross-major bump (5.4.x → 6.4.4) for the affected transitive dependency; remediate.sh did not flag this finding with a high_scrutiny signal, so it is submitted as a standard mechanical construct-pr for spur-vuln-review to evaluate on its own merits (real CI result, diff review).

Test evidence

pnpm install --lockfile-only completed successfully with the override in place; pnpm-lock.yaml now resolves vite at 6.4.4 (>= the 6.4.3 first_patched_version for all three advisories). No Dependabot PR existed to replay, so there is no prior CI run to compare against — CI on this PR is the first real signal. A companion-file scan (companion-scan.sh pnpm-lock.yaml 5.4.21) found no hardcoded companion files referencing the old version.

Risk

Medium — one-way-ish door: this is a major-version bump of a transitive build/test tool (vite), done via a forced override rather than a direct dependency bump, so there's a real chance of incompatibility with vitest/@vitejs/plugin-react's expected vite peer range that only CI (or a human reviewer) can confirm. Blast radius is limited to the build/test toolchain — vite is not a published runtime dependency of any package in this workspace.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Oct 6, 2026

@spur-vuln-reviewer spur-vuln-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified diff scope is package.json and pnpm-lock.yaml only. Gate 3 PASS via gate3-check.sh: pr_version 6.4.4 meets required 6.4.3 across alerts 54, 82, 83; state open; extra_files 0. No .github changes. All commits authored by spur-vuln-author bot. CI all green.

@spur-vuln-reviewer
spur-vuln-reviewer Bot merged commit eb4ee06 into main Oct 6, 2026
5 checks passed
@spur-vuln-reviewer
spur-vuln-reviewer Bot deleted the fix/dev-1703 branch October 6, 2026 21:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants