Skip to content

Conversation

@darinlarimore
Copy link
Owner

@darinlarimore darinlarimore commented Dec 6, 2025

Summary

Updates npm dependencies to address security vulnerabilities reported by Dependabot.

Changes

  • vite: ^4.0.0^6.4.1
  • laravel-vite-plugin: ^0.7.2^1.2.0

Security Issues Fixed

  • Multiple vite server.fs.deny bypass vulnerabilities (medium)
  • esbuild development server request vulnerability (moderate)
  • glob command injection vulnerability (high)
  • cross-spawn ReDoS vulnerability (high)
  • Various other medium/low severity issues

Remaining Issues

2 low severity vulnerabilities in Vue 2.x (ReDoS in parseHTML). These require migrating to Vue 3 which is out of scope for this PR.

Test Plan

  • npm run build succeeds
  • CI passes

🤖 Generated with Claude Code

- Upgrade vite from ^4.0.0 to ^6.4.1
- Upgrade laravel-vite-plugin from ^0.7.2 to ^1.2.0

Fixes high/medium severity issues in vite and esbuild.
Remaining low severity issues in vue 2.x require Vue 3 migration.
@darinlarimore darinlarimore self-assigned this Dec 6, 2025
@darinlarimore darinlarimore merged commit c265e61 into main Dec 6, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants