Skip to content

security: bump vitest to 4.1.0 in all FaceForge snapshots (CVE-2026-47429) - #6

Merged
ShugokiFable merged 1 commit into
mainfrom
security/bump-vitest-4.1.0
Sep 4, 2026
Merged

security: bump vitest to 4.1.0 in all FaceForge snapshots (CVE-2026-47429)#6
ShugokiFable merged 1 commit into
mainfrom
security/bump-vitest-4.1.0

Conversation

@ShugokiFable

Copy link
Copy Markdown
Owner

Summary

Bump vitest from 4.0.18 to 4.1.0 in all FaceForge snapshot web packages to close GHSA-5xrq-8626-4rwp / CVE-2026-47429 (critical path traversal / missing authorization in Vitest UI).

Patched version is 4.1.0. Lockfiles regenerated with pnpm@11.9.0 (no hand-edits).

Snapshots updated

  • FaceForge 0.23.0/src/FaceForge.Web
  • FaceForge 0.23.1/src/FaceForge.Web
  • FaceForge 0.23.2/src/FaceForge.Web
  • FaceForge 0.24.0/src/FaceForge.Web
  • FaceForge 0.24.1/src/FaceForge.Web
  • FaceForge 0.24.2/src/FaceForge.Web
  • FaceForge 0.24.3/src/FaceForge.Web (current)

Notes

Supersedes Dependabot PR #5, which only bumped the 0.24.2 snapshot.

Test plan

  • CI green on this PR (Build + run core tests on latest snapshot)
  • Confirm no remaining vitest@4.0.18 in any snapshot lockfile

…7429)

Fixes GHSA-5xrq-8626-4rwp. vitest 4.0.18 is vulnerable; 4.1.0 is the first patched 4.x release. Regenerated pnpm-lock.yaml in every FaceForge 0.23.0-0.24.3 web snapshot with pnpm@11.9.0.
@ShugokiFable
ShugokiFable merged commit b8526cb into main Sep 4, 2026
6 checks passed
@ShugokiFable
ShugokiFable deleted the security/bump-vitest-4.1.0 branch September 4, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant