Skip to content

chore(deps): bump vitest to ^4.1.0 (CVE-2026-47429)#82

Merged
mandarini merged 1 commit into
mainfrom
chore/bump-vitest-4.1-cve-2026-47429
Jun 16, 2026
Merged

chore(deps): bump vitest to ^4.1.0 (CVE-2026-47429)#82
mandarini merged 1 commit into
mainfrom
chore/bump-vitest-4.1-cve-2026-47429

Conversation

@mandarini

@mandarini mandarini commented Jun 16, 2026

Copy link
Copy Markdown
Collaborator

Bumps vitest from ^4.0.18 to ^4.1.0 (resolves to 4.1.8 in the lockfile) to patch CVE-2026-47429 and https://github.com/supabase/server/security/dependabot/35, a critical-severity arbitrary file read / RCE in the Vitest UI server. No config or test changes are required: the new allowWrite / allowExec defaults are correct for this repo, and vitest.config.ts does not expose api.host. Verified locally with pnpm test (185 tests pass), pnpm typecheck, pnpm lint, and pnpm build.

@mandarini mandarini self-assigned this Jun 16, 2026
@pkg-pr-new

pkg-pr-new Bot commented Jun 16, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@supabase/server@82

commit: 9b0aa0e

@mandarini mandarini marked this pull request as ready for review June 16, 2026 12:09
@mandarini mandarini requested review from a team as code owners June 16, 2026 12:09
@mandarini mandarini merged commit 5634bb7 into main Jun 16, 2026
7 checks passed
@mandarini mandarini deleted the chore/bump-vitest-4.1-cve-2026-47429 branch June 16, 2026 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants