Skip to content

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented Jun 17, 2025

This PR contains the following updates:

Package Type Update Change
vite (source) dependencies minor 6.2.0 -> 6.3.6

By merging this PR, the issue #2 will be automatically resolved and closed:

Severity CVSS Score Vulnerability
Medium Medium 6.5 CVE-2025-32395
Medium Medium 5.3 CVE-2025-30208
Medium Medium 5.3 CVE-2025-31125
Medium Medium 5.3 CVE-2025-31486
Medium Medium 5.3 CVE-2025-46565
Medium Medium 5.3 CVE-2025-58751
Medium Medium 5.3 CVE-2025-58752

Release Notes

vitejs/vite (vite)

v6.3.6

Compare Source

Please refer to CHANGELOG.md for details.

v6.3.5

Compare Source

Vite 7 is out!

Today, we're excited to announce the release of the next Vite major:

⚠ BREAKING CHANGES
  • ssr: don't access Object variable in ssr transformed code (#​19996)
  • remove experimental.skipSsrTransform option (#​20038)
  • remove HotBroadcaster (#​19988)
  • css: always use sass compiler API (#​19978)
  • bump build.target and name it baseline-widely-available (#​20007)
  • bump required node version to 20.19+, 22.12+ and remove cjs build (#​20032)
  • css: remove sass legacy API support (#​19977)
  • remove deprecated HotBroadcaster related types (#​19987)
  • remove deprecated no-op type only properties (#​19985)
  • remove node 18 support (#​19972)
  • remove deprecated hook-level enforce/transform from transformIndexHtml hook (#​19349)
  • remove deprecated splitVendorChunkPlugin (#​19255)
Features
Bug Fixes
Performance Improvements
Documentation
Miscellaneous Chores
Code Refactoring
Tests
Continuous Integration
Beta Changelogs
7.0.0-beta.2 (2025-06-17)

See 7.0.0-beta.2 changelog

7.0.0-beta.1 (2025-06-10)

See 7.0.0-beta.1 changelog

7.0.0-beta.0 (2025-06-02)

See 7.0.0-beta.0 changelog

v6.3.4

Compare Source

Bug Fixes
  • check static serve file inside sirv (#​19965) (c22c43d)
  • optimizer: return plain object when using require to import externals in optimized dependencies (#​19940) (efc5eab)
Code Refactoring

v6.3.3

Compare Source

Bug Fixes
  • assets: ensure ?no-inline is not included in the asset url in the production environment (#​19496) (16a73c0)
  • css: resolve relative imports in sass properly on Windows (#​19920) (ffab442)
  • deps: update all non-major dependencies (#​19899) (a4b500e)
  • ignore malformed uris in tranform middleware (#​19853) (e4d5201)
  • ssr: fix execution order of re-export (#​19841) (ed29dee)
  • ssr: fix live binding of default export declaration and hoist exports getter (#​19842) (80a91ff)
Performance Improvements
  • skip sourcemap generation for renderChunk hook of import-analysis-build plugin (#​19921) (55cfd04)
Tests
  • ssr: test ssrTransform re-export deps and test stacktrace with first line (#​19629) (9399cda)

v6.3.2

Compare Source

Features
Bug Fixes

v6.3.1

Compare Source

Bug Fixes

v6.3.0

Compare Source

Bug Fixes

v6.2.7

Compare Source

Please refer to CHANGELOG.md for details.

v6.2.6

Compare Source

Please refer to CHANGELOG.md for details.

v6.2.5

Compare Source

Please refer to CHANGELOG.md for details.

v6.2.4

Compare Source

Please refer to CHANGELOG.md for details.

v6.2.3

Compare Source

Please refer to CHANGELOG.md for details.

v6.2.2

Compare Source

Features
Bug Fixes
Miscellaneous Chores
  • extend commit hash correctly when ambigious with a non-commit object (#​19600) (89a6287)

v6.2.1

Compare Source

Features
  • add *?url&no-inline type and warning for .json?inline / .json?no-inline (#​19566) (c0d3667)
Bug Fixes
  • css: stabilize css module hashes with lightningcss in dev mode (#​19481) (92125b4)
  • deps: update all non-major dependencies (#​19555) (f612e0f)
  • reporter: fix incorrect bundle size calculation with non-ASCII characters (#​19561) (437c0ed)
  • sourcemap: combine sourcemaps with multiple sources without matched source (#​18971) (e3f6ae1)
  • ssr: named export should overwrite export all (#​19534) (2fd2fc1)
Performance Improvements
Miscellaneous Chores
Code Refactoring
Tests

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jun 17, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from 3bef8ae to 7f042b9 Compare September 9, 2025 12:34
@mend-for-github-com mend-for-github-com bot changed the title Update dependency vite to v6.2.7 Update dependency vite to v6.3.6 Sep 9, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from 7f042b9 to 8b83d37 Compare September 15, 2025 12:20
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from 8b83d37 to 93408c6 Compare September 19, 2025 19:18
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from 93408c6 to ec61eeb Compare September 20, 2025 19:47
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from ec61eeb to a9e03a2 Compare September 23, 2025 23:01
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from a9e03a2 to 29e63bc Compare September 25, 2025 08:07
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from 29e63bc to c746eec Compare September 29, 2025 06:38
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from c746eec to bfd9cfa Compare October 3, 2025 06:09
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/vite-6.x-lockfile branch from bfd9cfa to 8ebc18f Compare October 18, 2025 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant