security(deps): bump chat-ui to vite 6.4.3 to clear vite/esbuild alerts - #163
Open
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
Open
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
Conversation
chat-ui declares vite ^5.0.0, so the patched 6.4.3 release is out of range and Dependabot cannot reach it. Raise the range and move @vitejs/plugin-react to ^5 for vite 6 peer compatibility. vite 5.4.21 -> 6.4.3 (alerts 63, 118, 119) esbuild 0.21.5 -> 0.25.12 (alert 4, transitive of vite) npm audit: 0 vulnerabilities. This is a major bump and is split from the lockfile sweep deliberately. It is NOT build-verified: `npm run build` fails identically on vite 5 and vite 6 with `Could not resolve "../../aws-exports"`, because aws-exports.js is generated by Amplify at build time and is not tracked in the repo. Amplify CI is the only place this builds, so the PR check is the real verification. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the remaining 4 Dependabot alerts on
frontend/chat-ui.npm auditreports 0 vulnerabilities after this change.Split from #162 deliberately, because this one is a major version bump and needs a closer look.
Why Dependabot could not do this
chat-uideclaresvite: ^5.0.0. The patched release is 6.4.3, outside that range, so Dependabot cannot reach it — the alerts stay open no matter how many times it retries. This PR raises the declared range and moves@vitejs/plugin-reactto^5for vite 6 peer compatibility.Note that #153 previously bumped vite to 5.4.20 (now 5.4.21 on
main), which is within range but still vulnerable — the advisory covers all of<= 6.4.2.Changes
The only evidence behind it is that the dependency tree resolves cleanly and
npm auditis clean. Nothing has compiled this code against vite 6.Two independent gaps:
Local builds are impossible.
npm run buildfails withCould not resolve "../../aws-exports" from "src/App.jsx". This is pre-existing and unrelated to the bump — it reproduces identically onmainat vite 5.4.21.aws-exports.jsis generated by Amplify at build time and is not tracked in the repo.CI does not build either. The repo has no build or test workflow on pull requests. The only PR-triggered workflow is
check-hardcoded-urls; the others are CodeQL,create-release(tag-triggered) andversion-and-tag(push tomain). A green CI run on this PR therefore says nothing about whether vite 6 builds.An earlier revision of this description claimed the Amplify check would verify the upgrade. That was incorrect — no such check exists on this PR.
Reviewer guidance: please build
frontend/chat-uiagainst vite 6 in an environment that hasaws-exports.jsbefore merging. If it breaks, the likely culprits are the vite 6 config format or the@vitejs/plugin-reactv5 peer bump rather than anything insrc/.Post-merge note
version-and-tagruns on push tomainfiltered to the threepackage.jsonpaths, which this PR touches. That workflow has a pre-existing failure onchat-uiversion0.0.1, so expect it to go red onmainafter merge independently of this change.🤖 Generated with Claude Code