Skip to content

release/v0.1.1 - Update CHANGELOG.md for release v0.1.1#3

Merged
garotm merged 1 commit into
mainfrom
release/v0.1.1
Apr 28, 2026
Merged

release/v0.1.1 - Update CHANGELOG.md for release v0.1.1#3
garotm merged 1 commit into
mainfrom
release/v0.1.1

Conversation

@garotm
Copy link
Copy Markdown
Member

@garotm garotm commented Apr 28, 2026

[0.1.1] — 2026-04-28

Security

  • vite upgraded 6.4.16.4.2, resolving two CVEs in the Vite dev server (arbitrary file read via WebSocket — GHSA-p9ff-h696-f583, High; path traversal in optimised deps .map handling — GHSA-4w7w-66w2-5vf9, Moderate)
  • postcss minimum bumped to ^8.5.10, resolving a moderate XSS via unescaped </style> in CSS stringify output (GHSA-qx2v-qp2m-jg93)
  • rustls-webpki 0.103.100.103.13, resolving three CVEs: DoS via panic on malformed CRL BIT STRING (High); name constraints accepted for wildcard certificates (Low); name constraints for URI names incorrectly accepted (Low)
  • rand 0.8.50.8.6 (transitive Tauri dependency; latest compatible patch)
  • Replaced abandoned pkg (vercel/pkg, GHSA-22r3-9w55-cj54 — Local Privilege Escalation) with @yao-pkg/pkg, the actively maintained community fork; no API changes required

@garotm garotm requested a review from gmichalac April 28, 2026 05:09
@garotm garotm self-assigned this Apr 28, 2026
@garotm garotm added the security Dependabot security package updates label Apr 28, 2026
@sonarqubecloud
Copy link
Copy Markdown

Copy link
Copy Markdown
Collaborator

@gmichalac gmichalac left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVED

@garotm garotm merged commit 801005f into main Apr 28, 2026
5 checks passed
@garotm garotm deleted the release/v0.1.1 branch April 28, 2026 05:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Dependabot security package updates

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants