Skip to content

chore(frontend): bump vitest to 4.1.11 to clear the mocker path-traversal advisory - #60

Merged
KassaSana merged 1 commit into
masterfrom
chore/vitest-4-1-11
Sep 14, 2026
Merged

KassaSana merged 1 commit into
masterfrom
chore/vitest-4-1-11

Conversation

@KassaSana

Copy link
Copy Markdown
Owner

Clears the three moderate advisories npm audit was reporting in frontend/. All three (vitest, @vitest/coverage-v8, @vitest/mocker) trace back to a single advisory: GHSA-82fw-gwwq-j7x9, path traversal / arbitrary file read via the @vitest/mocker redirect mock.

The advisory range is >=2.1.0 <4.1.11, so this is a patch bump — no vitest 5 migration needed.

Why the manifest changed too

vitest and @vitest/coverage-v8 pin each other at an exact version ("vitest": "4.1.10" as a peer of coverage-v8, and vice versa). That circular exact pin makes both npm audit fix and npm update no-ops — verified, both left the tree at 4.1.10. The two have to move together via an explicit install, which also raises the declared floor above the vulnerable range rather than leaving the caret pointed at ^4.1.10.

Beyond the vitest packages, four of vitest's own transitive deps floated within their existing caret ranges: es-module-lexer, obug, tinyexec, tinyrainbow.

Verification

All run from frontend/ against the new lockfile:

  • npm ci — clean
  • npm audit --package-lock-only — found 0 vulnerabilities
  • npm run test:ci — exit 0; 31 test files, 165 tests, all passed (covers both the runner and the v8 coverage provider that were bumped)
  • npm run build — exit 0, bundle still self-contained and CSP hash-pinned
  • npm run typecheck — exit 0
  • npm run lint — exit 0 (13 pre-existing warnings, 0 errors)

Note this was never gating CI: the security-audit job runs npm audit --audit-level=high, and these were moderates. This is cleanup.

…rsal advisory

GHSA-82fw-gwwq-j7x9 (path traversal / arbitrary file read via the
@vitest/mocker redirect mock) covers >=2.1.0 <4.1.11, so the fix is a
patch release rather than a major bump.

vitest and @vitest/coverage-v8 pin each other at an exact version, which
makes both 'npm audit fix' and 'npm update' no-ops here; the two have to
move together via an explicit install. That also raises the declared
floor above the vulnerable range instead of leaving the caret pointing
at 4.1.10.

npm audit now reports 0 vulnerabilities.
Copilot AI lite review requested due to automatic review settings September 14, 2026 00:55

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The advisory is addressed, and all supplied verification checks pass.

Pull request overview

Updates frontend Vitest dependencies to 4.1.11, addressing the mocker path-traversal advisory.

Changes:

  • Bumps Vitest and coverage provider dependency floors.
  • Refreshes patched Vitest and transitive lockfile entries.
File summaries
File Description
frontend/package.json Raises Vitest dependency floors to 4.1.11.
frontend/package-lock.json Locks patched Vitest packages and refreshed transitive dependencies.
Review details

Files not reviewed (1)

  • frontend/package-lock.json: Generated file
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@KassaSana
KassaSana merged commit e126120 into master Sep 14, 2026
16 checks passed
@KassaSana
KassaSana deleted the chore/vitest-4-1-11 branch September 14, 2026 01:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants