Skip to content

security: bump vitest to 4.1.0 in all FaceForge snapshots (CVE-2026-47429) - #6

Merged
SenjuWoo merged 1 commit into
mainfrom
security/bump-vitest-4.1.0
Sep 4, 2026
Merged

SenjuWoo merged 1 commit into
mainfrom
security/bump-vitest-4.1.0

Conversation

@SenjuWoo

@SenjuWoo SenjuWoo commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

Bump vitest from 4.0.18 to 4.1.0 in all FaceForge snapshot web packages to close GHSA-5xrq-8626-4rwp / CVE-2026-47429 (critical path traversal / missing authorization in Vitest UI).

Patched version is 4.1.0. Lockfiles regenerated with pnpm@11.9.0 (no hand-edits).

Snapshots updated

  • FaceForge 0.23.0/src/FaceForge.Web
  • FaceForge 0.23.1/src/FaceForge.Web
  • FaceForge 0.23.2/src/FaceForge.Web
  • FaceForge 0.24.0/src/FaceForge.Web
  • FaceForge 0.24.1/src/FaceForge.Web
  • FaceForge 0.24.2/src/FaceForge.Web
  • FaceForge 0.24.3/src/FaceForge.Web (current)

Notes

Supersedes Dependabot PR #5, which only bumped the 0.24.2 snapshot.

Test plan

  • CI green on this PR (Build + run core tests on latest snapshot)
  • Confirm no remaining vitest@4.0.18 in any snapshot lockfile

…7429)

Fixes GHSA-5xrq-8626-4rwp. vitest 4.0.18 is vulnerable; 4.1.0 is the first patched 4.x release. Regenerated pnpm-lock.yaml in every FaceForge 0.23.0-0.24.3 web snapshot with pnpm@11.9.0.
@SenjuWoo
SenjuWoo merged commit b8526cb into main Sep 4, 2026
6 checks passed
@SenjuWoo
SenjuWoo deleted the security/bump-vitest-4.1.0 branch September 4, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant