Skip to content

security(deps): bump chat-ui to vite 6.4.3 to clear vite/esbuild alerts - #163

Open
NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
mainfrom
fix/chat-ui-vite6
Open

NetworkTheoryAppliedResearchInstitute wants to merge 1 commit into
mainfrom
fix/chat-ui-vite6

Conversation

@NetworkTheoryAppliedResearchInstitute

@NetworkTheoryAppliedResearchInstitute NetworkTheoryAppliedResearchInstitute commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

Closes the remaining 4 Dependabot alerts on frontend/chat-ui. npm audit reports 0 vulnerabilities after this change.

Split from #162 deliberately, because this one is a major version bump and needs a closer look.

Why Dependabot could not do this

chat-ui declares vite: ^5.0.0. The patched release is 6.4.3, outside that range, so Dependabot cannot reach it — the alerts stay open no matter how many times it retries. This PR raises the declared range and moves @vitejs/plugin-react to ^5 for vite 6 peer compatibility.

Note that #153 previously bumped vite to 5.4.20 (now 5.4.21 on main), which is within range but still vulnerable — the advisory covers all of <= 6.4.2.

Changes

Package Before After Alerts
vite 5.4.21 6.4.3 63, 118, 119
esbuild 0.21.5 0.25.12 4 (transitive of vite)

⚠️ This bump is not build-verified anywhere

The only evidence behind it is that the dependency tree resolves cleanly and npm audit is clean. Nothing has compiled this code against vite 6.

Two independent gaps:

Local builds are impossible. npm run build fails with Could not resolve "../../aws-exports" from "src/App.jsx". This is pre-existing and unrelated to the bump — it reproduces identically on main at vite 5.4.21. aws-exports.js is generated by Amplify at build time and is not tracked in the repo.

CI does not build either. The repo has no build or test workflow on pull requests. The only PR-triggered workflow is check-hardcoded-urls; the others are CodeQL, create-release (tag-triggered) and version-and-tag (push to main). A green CI run on this PR therefore says nothing about whether vite 6 builds.

An earlier revision of this description claimed the Amplify check would verify the upgrade. That was incorrect — no such check exists on this PR.

Reviewer guidance: please build frontend/chat-ui against vite 6 in an environment that has aws-exports.js before merging. If it breaks, the likely culprits are the vite 6 config format or the @vitejs/plugin-react v5 peer bump rather than anything in src/.

Post-merge note

version-and-tag runs on push to main filtered to the three package.json paths, which this PR touches. That workflow has a pre-existing failure on chat-ui version 0.0.1, so expect it to go red on main after merge independently of this change.

🤖 Generated with Claude Code

chat-ui declares vite ^5.0.0, so the patched 6.4.3 release is out of range
and Dependabot cannot reach it. Raise the range and move @vitejs/plugin-react
to ^5 for vite 6 peer compatibility.

  vite     5.4.21 -> 6.4.3    (alerts 63, 118, 119)
  esbuild  0.21.5 -> 0.25.12  (alert 4, transitive of vite)

npm audit: 0 vulnerabilities.

This is a major bump and is split from the lockfile sweep deliberately.
It is NOT build-verified: `npm run build` fails identically on vite 5 and
vite 6 with `Could not resolve "../../aws-exports"`, because aws-exports.js
is generated by Amplify at build time and is not tracked in the repo. Amplify
CI is the only place this builds, so the PR check is the real verification.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant