Skip to content

Conversation

@ematipico
Copy link
Member

Changes

Upgrades vite to the latest due to a CVE of theirs: GHSA-x574-m823-4x7w

Testing

CI should stay green

Docs

N/A

@changeset-bot
Copy link

changeset-bot bot commented Mar 24, 2025

🦋 Changeset detected

Latest commit: 28d9265

The changes in this PR will be included in the next version bump.

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions github-actions bot added pkg: svelte Related to Svelte (scope) pkg: vue Related to Vue (scope) pkg: react Related to React (scope) pkg: preact Related to Preact (scope) pkg: solid Related to Solid (scope) pkg: integration Related to any renderer integration (scope) pkg: astro Related to the core `astro` package (scope) labels Mar 24, 2025
@ascorbic
Copy link
Contributor

Vitest being Vitest again. Is it a peer dep thing?

@ematipico
Copy link
Member Author

Vitest being Vitest again. Is it a peer dep thing?

The failure comes from the examples/, so vitest is a direct dependency. Not sure how to fix it. I just used a dedupe, let's see if that works

@ascorbic
Copy link
Contributor

Yeah, the same test failed last time we did a manual Vite update

@ematipico ematipico merged commit a98ae5b into main Mar 25, 2025
15 checks passed
@ematipico ematipico deleted the fix/vite-security branch March 25, 2025 15:28
@astrobot-houston astrobot-houston mentioned this pull request Mar 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pkg: astro Related to the core `astro` package (scope) pkg: integration Related to any renderer integration (scope) pkg: preact Related to Preact (scope) pkg: react Related to React (scope) pkg: solid Related to Solid (scope) pkg: svelte Related to Svelte (scope) pkg: vue Related to Vue (scope)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants