Skip to content

fix(html): filename passed to transformIndexHtml should not include queries - #23653

Merged
sapphi-red merged 3 commits into
mainfrom
fix/html-filename
Oct 6, 2026
Merged

sapphi-red merged 3 commits into
mainfrom
fix/html-filename

Conversation

@sapphi-red

@sapphi-red sapphi-red commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

The first commit is the fix for the attack. The second commit is a hardening to avoid generating <script src="//evil.example.com/...">.

fixes GHSA-9jrq-w75r-8gcw

@sapphi-red
sapphi-red merged commit 7dafd8e into main Oct 6, 2026
30 of 34 checks passed
@sapphi-red
sapphi-red deleted the fix/html-filename branch October 6, 2026 03:23
@github-actions github-actions Bot mentioned this pull request Oct 6, 2026
This was referenced Oct 6, 2026
This was referenced Oct 6, 2026
@sapphi-red sapphi-red added p5-urgent Fix build-breaking bugs affecting most users, should be released ASAP (priority) security labels Oct 6, 2026
renovate Bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request Oct 6, 2026
| datasource | package | from  | to    |
| ---------- | ------- | ----- | ----- |
| npm        | vite    | 8.3.0 | 8.3.3 |


## [v8.3.3](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-833-2026-10-06-small)

##### Bug Fixes

- **deps:** update launch-editor to v2.14.2 ([#23654](vitejs/vite#23654)) ([22fd1d5](vitejs/vite@22fd1d5))
- **html:** filename passed to transformIndexHtml should not include queries ([#23653](vitejs/vite#23653)) ([7dafd8e](vitejs/vite@7dafd8e))
- **server:** check `fs.serve` for `?vite-wasm-instance` ([#23655](vitejs/vite#23655)) ([ba8b7ab](vitejs/vite@ba8b7ab))
- **server:** store ids to `safeModulePaths` rather than URLs ([#23656](vitejs/vite#23656)) ([c3e06f9](vitejs/vite@c3e06f9))


## [v8.3.2](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-832-2026-10-01-small)

##### Bug Fixes

- **build:** preload CSS correctly when `renderBuiltUrl` returns URLs with queries ([#23611](vitejs/vite#23611)) ([64e0a21](vitejs/vite@64e0a21))
- **bundled-dev:** serve lazy chunk sourcemaps ([#23026](vitejs/vite#23026)) ([eb7aa9a](vitejs/vite@eb7aa9a))
- **bundled-dev:** serve the rolldown runtime from the installed rolldown ([#23568](vitejs/vite#23568)) ([bc598a6](vitejs/vite@bc598a6))
- **deps:** update all non-major dependencies ([#23601](vitejs/vite#23601)) ([9944fa6](vitejs/vite@9944fa6))
- **deps:** update rolldown-related dependencies ([#23602](vitejs/vite#23602)) ([88c1741](vitejs/vite@88c1741))
- **html:** resolve percent-encoded srcset urls ([#23609](vitejs/vite#23609)) ([53f1ce7](vitejs/vite@53f1ce7))
- limit size of object and array printing via `forwardConsole` ([#23565](vitejs/vite#23565)) ([e64a587](vitejs/vite@e64a587))
- merge `build.rolldownOptions.output.minify` correctly ([#23536](vitejs/vite#23536)) ([bba3bb8](vitejs/vite@bba3bb8))
- **optimize-deps:** avoid "unsupported" warnings for browser:false mappings ([#23590](vitejs/vite#23590)) ([5e4b9ca](vitejs/vite@5e4b9ca))
- **optimizer:** preserve excluded optional peer require fallbacks ([#23600](vitejs/vite#23600)) ([a2bd6fa](vitejs/vite@a2bd6fa))
- pass queries to `renderBuiltUrl` ([#23586](vitejs/vite#23586)) ([744269e](vitejs/vite@744269e))
- **server:** handle file watcher errors without crashing ([#23503](vitejs/vite#23503)) ([6894f5c](vitejs/vite@6894f5c))
- **server:** release previous environments after initialization ([#23499](vitejs/vite#23499)) ([5a3a010](vitejs/vite@5a3a010))
- **ssr:** encode whitespace in module runner sourceURL ([#23513](vitejs/vite#23513)) ([bbc8812](vitejs/vite@bbc8812))
- **worker:** align worker urls in client and server when using terser ([#23614](vitejs/vite#23614)) ([24bd331](vitejs/vite@24bd331))

##### Performance Improvements

- avoid encoding intermediate source maps ([#23461](vitejs/vite#23461)) ([89574f6](vitejs/vite@89574f6))
- **build:** avoid quadratic link scan in the preload helper ([#23510](vitejs/vite#23510)) ([cf5c028](vitejs/vite@cf5c028))
- only register time middleware when debug logging is enabled ([#23621](vitejs/vite#23621)) ([94d0080](vitejs/vite@94d0080))

##### Documentation

- fix dead og-image PNG links in vite6/vite7 changelog entries ([#23594](vitejs/vite#23594)) ([1929b4c](vitejs/vite@1929b4c))

##### Miscellaneous Chores

- **deps:** update vitest monorepo to v5 ([#23604](vitejs/vite#23604)) ([24339f4](vitejs/vite@24339f4))

##### Code Refactoring

- use `tinyexec` instead of `cross-spawn` ([#23583](vitejs/vite#23583)) ([db915e5](vitejs/vite@db915e5))

##### Tests

- **bundled-dev:** accept a rolldown dev runtime with no helper imports ([#23606](vitejs/vite#23606)) ([634745d](vitejs/vite@634745d))


## [v8.3.1](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-831-2026-09-24-small)

##### Bug Fixes

- **deps:** update all non-major dependencies ([#23482](vitejs/vite#23482)) ([3c752c8](vitejs/vite@3c752c8))
- **deps:** update all non-major dependencies ([#23537](vitejs/vite#23537)) ([e8990c4](vitejs/vite@e8990c4))
- **deps:** update rolldown-related dependencies ([#23483](vitejs/vite#23483)) ([9aecbbf](vitejs/vite@9aecbbf))
- handle `server.ws: false` in mergeConfig ([#23511](vitejs/vite#23511)) ([f68c0d5](vitejs/vite@f68c0d5))
- merge `build.rolldownOptions.output.comments` correctly ([#23514](vitejs/vite#23514)) ([4aba8d8](vitejs/vite@4aba8d8))
- **optimizer:** don't skip imports whose binding starts with type ([#23540](vitejs/vite#23540)) ([39330f4](vitejs/vite@39330f4))
- **optimizer:** resolve pending discovered dep processing on close before init ([#23567](vitejs/vite#23567)) ([5f89433](vitejs/vite@5f89433))
- **server:** avoid reinitializing watcher when adding file after server close ([#23572](vitejs/vite#23572)) ([6f831f9](vitejs/vite@6f831f9))
- **sourcemap:** skip URL source roots when injecting sources content ([#23519](vitejs/vite#23519)) ([04fc30a](vitejs/vite@04fc30a))

##### Miscellaneous Chores

- merge prereleases in changelog ([#23466](vitejs/vite#23466)) ([99bd9d1](vitejs/vite@99bd9d1))
- **optimizer:** add debug log when waiting for dep before init ([#23566](vitejs/vite#23566)) ([63567c7](vitejs/vite@63567c7))
- update `optimizeDeps.include` comment ([#23489](vitejs/vite#23489)) ([6a84c72](vitejs/vite@6a84c72))

##### Code Refactoring

- assets regexp use non-capture ([#23491](vitejs/vite#23491)) ([f4b4431](vitejs/vite@f4b4431))
- remove duplicate configurations ([#23532](vitejs/vite#23532)) ([9abd99b](vitejs/vite@9abd99b))
- replace `find` with `some` ([#23554](vitejs/vite#23554)) ([af7cdf6](vitejs/vite@af7cdf6))
james-elicx added a commit to cloudflare/vinext that referenced this pull request Oct 7, 2026
Vite 8.3.3 (vitejs/vite#23653) strips the query before mapping the
transformIndexHtml URL to a file, so `/?q` now resolves to the project
root directory. Because that directory exists and the query hides the
trailing slash, Vite treats `/?q` as a real file and gives each inline
<style> proxy module the file `/`, then calls watcher.add("/"). On
Linux chokidar crawls the whole filesystem with one fs.watch per file,
which ran the Pages _document integration tests out of memory.

The query has no meaning for the HTML transform, so the Pages dev server
now passes the bare path, which keeps Vite's virtual proxy modules.
james-elicx added a commit to cloudflare/vinext that referenced this pull request Oct 7, 2026
* chore(deps): upgrade vite-plus to 1.1.0

Bumps vite-plus and the vite-plus-core vite alias from 0.3.2 to 1.1.0
across the workspace catalog, along with vitest and
@vitest/coverage-istanbul 5.0.3 to match the vitest version vite-plus
1.1.0 bundles. Reformats apps/web globals.css for the new oxfmt.

* fix: adapt CI to vite-plus 1.1.0

vite-plus no longer ships an oxlint bin, so knip now treats the oxlint
that `vinext lint` invokes as a consumer-project binary, like eslint.

Vitest 5 clears mocks between tests by default, so the prerender
Cloudflare loader test captures the once-per-process register() call
before any test runs.

* fix(dev): stop Vite from watching the filesystem root for /?query pages

Vite 8.3.3 (vitejs/vite#23653) strips the query before mapping the
transformIndexHtml URL to a file, so `/?q` now resolves to the project
root directory. Because that directory exists and the query hides the
trailing slash, Vite treats `/?q` as a real file and gives each inline
<style> proxy module the file `/`, then calls watcher.add("/"). On
Linux chokidar crawls the whole filesystem with one fs.watch per file,
which ran the Pages _document integration tests out of memory.

The query has no meaning for the HTML transform, so the Pages dev server
now passes the bare path, which keeps Vite's virtual proxy modules.

* ci: point vitest 5 merge-reports at the downloaded shard blobs

Vitest 5 reads --merge-reports from .vitest/blob by default, but the
integration shards upload and the report job downloads their blobs into
.vitest-reports.
dadezzz pushed a commit to dadezzz/university_notes that referenced this pull request Oct 9, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [vite](https://vite.dev) ([source](https://github.com/vitejs/vite/tree/HEAD/packages/vite)) | [`8.3.2` → `8.3.3`](https://renovatebot.com/diffs/npm/vite/8.3.2/8.3.3) | ![age](https://developer.mend.io/api/mc/badges/age/npm/vite/8.3.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vite/8.3.2/8.3.3?slim=true) |

---

### Release Notes

<details>
<summary>vitejs/vite (vite)</summary>

### [`v8.3.3`](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-833-2026-10-06-small)

[Compare Source](vitejs/vite@v8.3.2...v8.3.3)

##### Bug Fixes

- **deps:** update launch-editor to v2.14.2 ([#&#8203;23654](vitejs/vite#23654)) ([22fd1d5](vitejs/vite@22fd1d5))
- **html:** filename passed to transformIndexHtml should not include queries ([#&#8203;23653](vitejs/vite#23653)) ([7dafd8e](vitejs/vite@7dafd8e))
- **server:** check `fs.serve` for `?vite-wasm-instance` ([#&#8203;23655](vitejs/vite#23655)) ([ba8b7ab](vitejs/vite@ba8b7ab))
- **server:** store ids to `safeModulePaths` rather than URLs ([#&#8203;23656](vitejs/vite#23656)) ([c3e06f9](vitejs/vite@c3e06f9))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNDUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjE0NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
dadezzz pushed a commit to dadezzz/events-cash-register that referenced this pull request Oct 9, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [vite](https://vite.dev) ([source](https://github.com/vitejs/vite/tree/HEAD/packages/vite)) | [`8.3.2` → `8.3.3`](https://renovatebot.com/diffs/npm/vite/8.3.2/8.3.3) | ![age](https://developer.mend.io/api/mc/badges/age/npm/vite/8.3.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vite/8.3.2/8.3.3?slim=true) |

---

### Release Notes

<details>
<summary>vitejs/vite (vite)</summary>

### [`v8.3.3`](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-833-2026-10-06-small)

[Compare Source](vitejs/vite@v8.3.2...v8.3.3)

##### Bug Fixes

- **deps:** update launch-editor to v2.14.2 ([#&#8203;23654](vitejs/vite#23654)) ([22fd1d5](vitejs/vite@22fd1d5))
- **html:** filename passed to transformIndexHtml should not include queries ([#&#8203;23653](vitejs/vite#23653)) ([7dafd8e](vitejs/vite@7dafd8e))
- **server:** check `fs.serve` for `?vite-wasm-instance` ([#&#8203;23655](vitejs/vite#23655)) ([ba8b7ab](vitejs/vite@ba8b7ab))
- **server:** store ids to `safeModulePaths` rather than URLs ([#&#8203;23656](vitejs/vite#23656)) ([c3e06f9](vitejs/vite@c3e06f9))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNDUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjE0NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

p5-urgent Fix build-breaking bugs affecting most users, should be released ASAP (priority) security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant