Repository navigation
fix(html): filename passed to transformIndexHtml should not include queries - #23653
Merged
Merged
Conversation
Merged
This was referenced Oct 6, 2026
sapphi-red
added a commit
that referenced
this pull request
Oct 6, 2026
sapphi-red
added a commit
that referenced
this pull request
Oct 6, 2026
This was referenced Oct 6, 2026
Merged
Merged
sapphi-red
added a commit
that referenced
this pull request
Oct 6, 2026
sapphi-red
added a commit
that referenced
this pull request
Oct 6, 2026
sapphi-red
added a commit
that referenced
this pull request
Oct 6, 2026
sapphi-red
added a commit
that referenced
this pull request
Oct 6, 2026
renovate Bot
added a commit
to andrei-picus-tink/auto-renovate
that referenced
this pull request
Oct 6, 2026
| datasource | package | from | to | | ---------- | ------- | ----- | ----- | | npm | vite | 8.3.0 | 8.3.3 | ## [v8.3.3](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-833-2026-10-06-small) ##### Bug Fixes - **deps:** update launch-editor to v2.14.2 ([#23654](vitejs/vite#23654)) ([22fd1d5](vitejs/vite@22fd1d5)) - **html:** filename passed to transformIndexHtml should not include queries ([#23653](vitejs/vite#23653)) ([7dafd8e](vitejs/vite@7dafd8e)) - **server:** check `fs.serve` for `?vite-wasm-instance` ([#23655](vitejs/vite#23655)) ([ba8b7ab](vitejs/vite@ba8b7ab)) - **server:** store ids to `safeModulePaths` rather than URLs ([#23656](vitejs/vite#23656)) ([c3e06f9](vitejs/vite@c3e06f9)) ## [v8.3.2](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-832-2026-10-01-small) ##### Bug Fixes - **build:** preload CSS correctly when `renderBuiltUrl` returns URLs with queries ([#23611](vitejs/vite#23611)) ([64e0a21](vitejs/vite@64e0a21)) - **bundled-dev:** serve lazy chunk sourcemaps ([#23026](vitejs/vite#23026)) ([eb7aa9a](vitejs/vite@eb7aa9a)) - **bundled-dev:** serve the rolldown runtime from the installed rolldown ([#23568](vitejs/vite#23568)) ([bc598a6](vitejs/vite@bc598a6)) - **deps:** update all non-major dependencies ([#23601](vitejs/vite#23601)) ([9944fa6](vitejs/vite@9944fa6)) - **deps:** update rolldown-related dependencies ([#23602](vitejs/vite#23602)) ([88c1741](vitejs/vite@88c1741)) - **html:** resolve percent-encoded srcset urls ([#23609](vitejs/vite#23609)) ([53f1ce7](vitejs/vite@53f1ce7)) - limit size of object and array printing via `forwardConsole` ([#23565](vitejs/vite#23565)) ([e64a587](vitejs/vite@e64a587)) - merge `build.rolldownOptions.output.minify` correctly ([#23536](vitejs/vite#23536)) ([bba3bb8](vitejs/vite@bba3bb8)) - **optimize-deps:** avoid "unsupported" warnings for browser:false mappings ([#23590](vitejs/vite#23590)) ([5e4b9ca](vitejs/vite@5e4b9ca)) - **optimizer:** preserve excluded optional peer require fallbacks ([#23600](vitejs/vite#23600)) ([a2bd6fa](vitejs/vite@a2bd6fa)) - pass queries to `renderBuiltUrl` ([#23586](vitejs/vite#23586)) ([744269e](vitejs/vite@744269e)) - **server:** handle file watcher errors without crashing ([#23503](vitejs/vite#23503)) ([6894f5c](vitejs/vite@6894f5c)) - **server:** release previous environments after initialization ([#23499](vitejs/vite#23499)) ([5a3a010](vitejs/vite@5a3a010)) - **ssr:** encode whitespace in module runner sourceURL ([#23513](vitejs/vite#23513)) ([bbc8812](vitejs/vite@bbc8812)) - **worker:** align worker urls in client and server when using terser ([#23614](vitejs/vite#23614)) ([24bd331](vitejs/vite@24bd331)) ##### Performance Improvements - avoid encoding intermediate source maps ([#23461](vitejs/vite#23461)) ([89574f6](vitejs/vite@89574f6)) - **build:** avoid quadratic link scan in the preload helper ([#23510](vitejs/vite#23510)) ([cf5c028](vitejs/vite@cf5c028)) - only register time middleware when debug logging is enabled ([#23621](vitejs/vite#23621)) ([94d0080](vitejs/vite@94d0080)) ##### Documentation - fix dead og-image PNG links in vite6/vite7 changelog entries ([#23594](vitejs/vite#23594)) ([1929b4c](vitejs/vite@1929b4c)) ##### Miscellaneous Chores - **deps:** update vitest monorepo to v5 ([#23604](vitejs/vite#23604)) ([24339f4](vitejs/vite@24339f4)) ##### Code Refactoring - use `tinyexec` instead of `cross-spawn` ([#23583](vitejs/vite#23583)) ([db915e5](vitejs/vite@db915e5)) ##### Tests - **bundled-dev:** accept a rolldown dev runtime with no helper imports ([#23606](vitejs/vite#23606)) ([634745d](vitejs/vite@634745d)) ## [v8.3.1](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-831-2026-09-24-small) ##### Bug Fixes - **deps:** update all non-major dependencies ([#23482](vitejs/vite#23482)) ([3c752c8](vitejs/vite@3c752c8)) - **deps:** update all non-major dependencies ([#23537](vitejs/vite#23537)) ([e8990c4](vitejs/vite@e8990c4)) - **deps:** update rolldown-related dependencies ([#23483](vitejs/vite#23483)) ([9aecbbf](vitejs/vite@9aecbbf)) - handle `server.ws: false` in mergeConfig ([#23511](vitejs/vite#23511)) ([f68c0d5](vitejs/vite@f68c0d5)) - merge `build.rolldownOptions.output.comments` correctly ([#23514](vitejs/vite#23514)) ([4aba8d8](vitejs/vite@4aba8d8)) - **optimizer:** don't skip imports whose binding starts with type ([#23540](vitejs/vite#23540)) ([39330f4](vitejs/vite@39330f4)) - **optimizer:** resolve pending discovered dep processing on close before init ([#23567](vitejs/vite#23567)) ([5f89433](vitejs/vite@5f89433)) - **server:** avoid reinitializing watcher when adding file after server close ([#23572](vitejs/vite#23572)) ([6f831f9](vitejs/vite@6f831f9)) - **sourcemap:** skip URL source roots when injecting sources content ([#23519](vitejs/vite#23519)) ([04fc30a](vitejs/vite@04fc30a)) ##### Miscellaneous Chores - merge prereleases in changelog ([#23466](vitejs/vite#23466)) ([99bd9d1](vitejs/vite@99bd9d1)) - **optimizer:** add debug log when waiting for dep before init ([#23566](vitejs/vite#23566)) ([63567c7](vitejs/vite@63567c7)) - update `optimizeDeps.include` comment ([#23489](vitejs/vite#23489)) ([6a84c72](vitejs/vite@6a84c72)) ##### Code Refactoring - assets regexp use non-capture ([#23491](vitejs/vite#23491)) ([f4b4431](vitejs/vite@f4b4431)) - remove duplicate configurations ([#23532](vitejs/vite#23532)) ([9abd99b](vitejs/vite@9abd99b)) - replace `find` with `some` ([#23554](vitejs/vite#23554)) ([af7cdf6](vitejs/vite@af7cdf6))
This was referenced Oct 7, 2026
james-elicx
added a commit
to cloudflare/vinext
that referenced
this pull request
Oct 7, 2026
Vite 8.3.3 (vitejs/vite#23653) strips the query before mapping the transformIndexHtml URL to a file, so `/?q` now resolves to the project root directory. Because that directory exists and the query hides the trailing slash, Vite treats `/?q` as a real file and gives each inline <style> proxy module the file `/`, then calls watcher.add("/"). On Linux chokidar crawls the whole filesystem with one fs.watch per file, which ran the Pages _document integration tests out of memory. The query has no meaning for the HTML transform, so the Pages dev server now passes the bare path, which keeps Vite's virtual proxy modules.
james-elicx
added a commit
to cloudflare/vinext
that referenced
this pull request
Oct 7, 2026
* chore(deps): upgrade vite-plus to 1.1.0 Bumps vite-plus and the vite-plus-core vite alias from 0.3.2 to 1.1.0 across the workspace catalog, along with vitest and @vitest/coverage-istanbul 5.0.3 to match the vitest version vite-plus 1.1.0 bundles. Reformats apps/web globals.css for the new oxfmt. * fix: adapt CI to vite-plus 1.1.0 vite-plus no longer ships an oxlint bin, so knip now treats the oxlint that `vinext lint` invokes as a consumer-project binary, like eslint. Vitest 5 clears mocks between tests by default, so the prerender Cloudflare loader test captures the once-per-process register() call before any test runs. * fix(dev): stop Vite from watching the filesystem root for /?query pages Vite 8.3.3 (vitejs/vite#23653) strips the query before mapping the transformIndexHtml URL to a file, so `/?q` now resolves to the project root directory. Because that directory exists and the query hides the trailing slash, Vite treats `/?q` as a real file and gives each inline <style> proxy module the file `/`, then calls watcher.add("/"). On Linux chokidar crawls the whole filesystem with one fs.watch per file, which ran the Pages _document integration tests out of memory. The query has no meaning for the HTML transform, so the Pages dev server now passes the bare path, which keeps Vite's virtual proxy modules. * ci: point vitest 5 merge-reports at the downloaded shard blobs Vitest 5 reads --merge-reports from .vitest/blob by default, but the integration shards upload and the report job downloads their blobs into .vitest-reports.
dadezzz
pushed a commit
to dadezzz/university_notes
that referenced
this pull request
Oct 9, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [vite](https://vite.dev) ([source](https://github.com/vitejs/vite/tree/HEAD/packages/vite)) | [`8.3.2` → `8.3.3`](https://renovatebot.com/diffs/npm/vite/8.3.2/8.3.3) |  |  | --- ### Release Notes <details> <summary>vitejs/vite (vite)</summary> ### [`v8.3.3`](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-833-2026-10-06-small) [Compare Source](vitejs/vite@v8.3.2...v8.3.3) ##### Bug Fixes - **deps:** update launch-editor to v2.14.2 ([#​23654](vitejs/vite#23654)) ([22fd1d5](vitejs/vite@22fd1d5)) - **html:** filename passed to transformIndexHtml should not include queries ([#​23653](vitejs/vite#23653)) ([7dafd8e](vitejs/vite@7dafd8e)) - **server:** check `fs.serve` for `?vite-wasm-instance` ([#​23655](vitejs/vite#23655)) ([ba8b7ab](vitejs/vite@ba8b7ab)) - **server:** store ids to `safeModulePaths` rather than URLs ([#​23656](vitejs/vite#23656)) ([c3e06f9](vitejs/vite@c3e06f9)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNDUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjE0NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
dadezzz
pushed a commit
to dadezzz/events-cash-register
that referenced
this pull request
Oct 9, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [vite](https://vite.dev) ([source](https://github.com/vitejs/vite/tree/HEAD/packages/vite)) | [`8.3.2` → `8.3.3`](https://renovatebot.com/diffs/npm/vite/8.3.2/8.3.3) |  |  | --- ### Release Notes <details> <summary>vitejs/vite (vite)</summary> ### [`v8.3.3`](https://github.com/vitejs/vite/blob/HEAD/packages/vite/CHANGELOG.md#small-833-2026-10-06-small) [Compare Source](vitejs/vite@v8.3.2...v8.3.3) ##### Bug Fixes - **deps:** update launch-editor to v2.14.2 ([#​23654](vitejs/vite#23654)) ([22fd1d5](vitejs/vite@22fd1d5)) - **html:** filename passed to transformIndexHtml should not include queries ([#​23653](vitejs/vite#23653)) ([7dafd8e](vitejs/vite@7dafd8e)) - **server:** check `fs.serve` for `?vite-wasm-instance` ([#​23655](vitejs/vite#23655)) ([ba8b7ab](vitejs/vite@ba8b7ab)) - **server:** store ids to `safeModulePaths` rather than URLs ([#​23656](vitejs/vite#23656)) ([c3e06f9](vitejs/vite@c3e06f9)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNDUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjE0NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The first commit is the fix for the attack. The second commit is a hardening to avoid generating
<script src="//evil.example.com/...">.fixes GHSA-9jrq-w75r-8gcw