Repository navigation
build(deps-dev): bump vite from 7.3.2 to 7.3.5 - #275
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.2 to 7.3.5. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v7.3.5/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 7.3.5 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
|
Superseded by #284, merged as efdf3a7. That PR bumps both It also removes |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
> **Stack of 4 — merge bottom to top.** Review each layer against the one below it, not `main`. > > **→** 1. dfinity#284 — security fix: dependency advisories, `bun.lock` removal > 2. dfinity#285 — contributor setup docs > 3. dfinity#286 — `consumer_install` job, retires `e2e_test_bun` > 4. dfinity#288 — consumer install guidance > > Repo installs are pnpm-only: `pnpm.overrides`, `minimumReleaseAge` and `onlyBuiltDependencies` are pnpm-only fields, so a second installer resolves a graph that bypasses them. Bun remains a supported **consumer** runtime, covered by `consumer_install (bun)` from layer 3. > > Scoped to the security fix and the install-path change it forces. Pre-existing documentation gaps in `README.md` and `examples/README.md`, including the `pnpm run setup` step and the canister toolchain, are fixed in dfinity#285. Clears all 24 open Dependabot alerts (1 critical, 13 high, 8 moderate, 2 low). Supersedes dfinity#275 and dfinity#283. Bumps `vite` to `^7.3.5` and `vitest` to `^4.1.11`, and extends `pnpm.overrides` to cover the 21 transitive advisories. Drops the `minimumReleaseAgeExclude: [vite]` entry, annotated for removal after 2026-04-16. ## Removing `bun.lock` `pnpm.overrides`, `minimumReleaseAge` and `onlyBuiltDependencies` are pnpm-only, so `bun.lock` resolved a second dependency graph that bypassed them. Against the overrides as they stood on `main`: | `pnpm.overrides` on `main` | pnpm-lock.yaml | bun.lock | | --- | --- | --- | | `brace-expansion@>=1 <2` → `^1.1.13` | 1.1.13 | 1.1.12 | | `brace-expansion@>=2 <2.0.3` → `^2.0.3` | 2.0.3 | 2.0.2 | | `picomatch@>=2 <3` → `^2.3.2` | 2.3.2 | 2.3.1 | | `picomatch@>=4 <4.0.4` → `4.0.4` | 4.0.4 | 4.0.3 | | `yaml@>=2 <2.8.3` → `2.8.3` | 2.8.3 | 2.8.2 | This PR then raises several of those bounds to clear the open advisories, so the versions now resolved are `brace-expansion` 1.1.18 / 2.1.4, `picomatch` 2.3.2 / 4.0.4 and `yaml` 2.8.3. Dependabot cannot keep `bun.lock` current either: bun is supported for [version updates but not security updates](https://docs.github.com/en/code-security/dependabot/ecosystems-supported-by-dependabot/supported-ecosystems-and-repositories), so security PRs updated `package.json` and `pnpm-lock.yaml` only, leaving it stale and failing `bun i --frozen-lockfile`. `e2e_test_bun` now installs with pnpm and still builds and tests with bun. Contributor-facing commands move to pnpm to match, including the eight per-example READMEs. ## Verified `pnpm audit` clean · `pnpm i --frozen-lockfile` up to date · `pnpm test:pic` 65 passed · `bun run build` against the pnpm tree 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps vite from 7.3.2 to 7.3.5.
Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
Commits
077945crelease: v7.3.58a6a0c9chore: skip v7.3.4 release8c18556fix: backport #22572, reject windows alternate paths (#22574)f20d64bfix(deps): backport #22571, reject UNC paths for launch-editor-middleware (#2...ca31424release: v7.3.35ab51c0fix: avoid destructure lowering for newer safari (#22346)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.