Skip to content

Dependency roundup: frontend bumps + docs vite/esbuild security patch#23

Merged
Akarithos merged 1 commit into
mainfrom
deps/dependabot-roundup
May 26, 2026
Merged

Dependency roundup: frontend bumps + docs vite/esbuild security patch#23
Akarithos merged 1 commit into
mainfrom
deps/dependabot-roundup

Conversation

@Akarithos
Copy link
Copy Markdown
Contributor

Consolidates the open Dependabot updates into one PR and patches the two security advisories on docs/.

ident/

Verified: pnpm build and full vitest run (587 tests) pass.

docs/ (security)

Pinned vite ≥6.4.2 and esbuild ≥0.25.0 via pnpm overrides (resolved to vite 6.4.2 / esbuild 0.25.12) to clear:

Verified: pnpm audit reports no known vulnerabilities; vitepress build succeeds on vite 6.

CI

Bumped GitHub Pages actions in site.yml (configure-pages v6, upload-pages-artifact v5, deploy-pages v5) — this carries #21's intent, since its target docs.yml was replaced by site.yml.

Supersedes

Closes #15 (Dockerfile node:26 already on main), #19, #20, #21, #22.

ident: frontend-tooling group (@types/node, @types/react, vite, vitest),
lint-staged 16 -> 17, @vitejs/plugin-react 5 -> 6.

docs: pin vite >=6.4.2 and esbuild >=0.25.0 to clear GHSA-4w7w-66w2-5vf9
(path traversal) and GHSA-67mh-4wv8-2f99 (dev-server request leak).

site workflow: bump Pages actions (configure-pages v6,
upload-pages-artifact v5, deploy-pages v5).

Supersedes #15, #19, #20, #21, #22.
@Akarithos Akarithos merged commit 6a38d49 into main May 26, 2026
14 checks passed
@Akarithos Akarithos deleted the deps/dependabot-roundup branch May 26, 2026 19:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant