Repository navigation
chore(deps-dev): bump vite from 6.3.5 to 6.4.3 - #4873
dependabot[bot] wants to merge 1 commit into
Conversation
PR SummaryMedium Risk Overview The root workspace bumps Reviewed by Cursor Bugbot for commit 1b4c00c. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
|
|
560202f to
88440f7
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 88440f7. Configure here.
| "typescript-eslint": "^8.71.0", | ||
| "unplugin-vue-components": "^32.1.0", | ||
| "vite": "^7.3.2", | ||
| "vite": "^6.4.3", |
There was a problem hiding this comment.
Frontend Vite unexpectedly downgraded
Medium Severity
This PR patches root vite from 6.3.5 to 6.4.3, but frontend/package.json also changes vite from ^7.3.2 to ^6.4.3. That is a major-version downgrade of the production bundler and sits outside the stated bump.
Reviewed by Cursor Bugbot for commit 88440f7. Configure here.
gaspergrom
left a comment
There was a problem hiding this comment.
This needs changes before it can merge.
| "typescript-eslint": "^8.71.0", | ||
| "unplugin-vue-components": "^32.1.0", | ||
| "vite": "^7.3.2", | ||
| "vite": "^6.4.3", |
There was a problem hiding this comment.
On main this is ^7.3.2, so this change downgrades the frontend from Vite 7 to 6.4.3. Dependabot built the bump against the root pin and rewrote this range too. Please keep the frontend on 7.x and only touch the root pin if that is the intent.
| "oxlint": "^1.83.0", | ||
| "typescript": "catalog:", | ||
| "vite": "6.3.5", | ||
| "vite": "6.4.3", |
There was a problem hiding this comment.
pnpm install fails in build, lint and storybook-build with ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION for one lockfile entry, and the test job fails too. Vite 6.4.3 is newer than the repo's minimum release age allows. The lockfile needs to resolve cleanly before CI can go green.
88440f7 to
7686123
Compare
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 6.3.5 to 6.4.3. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v6.4.3/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 6.4.3 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
7686123 to
1b4c00c
Compare


Bumps vite from 6.3.5 to 6.4.3.
Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
Commits
6c2c881release: v6.4.396b0c10fix: backport #22572, reject windows alternate paths (#22576)8fed5cffix(deps): backport #22571, reject UNC paths for launch-editor-middleware (#2...6b3fad0release: v6.4.2ca4da5dfix: avoid path traversal with optimize deps sourcemap handler (#22161)fe28e47fix: apply server.fs check to env transport (#22159) (#22163)5487f4frelease: v6.4.11114b5dfix(dev): trim trailing slash beforeserver.fs.denycheck (#20968) (#20969)f12697crelease: v6.4.0ca6455efeat: allow passing down resolved config to vite's createServer (#20932)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for vite since your current version.