Skip to content

Update dependencies#252

Open
pomek wants to merge 2 commits into
masterfrom
ci/4359
Open

Update dependencies#252
pomek wants to merge 2 commits into
masterfrom
ci/4359

Conversation

@pomek
Copy link
Copy Markdown
Member

@pomek pomek commented Apr 9, 2026

🚀 Summary

Update dependencies to address security advisories. Bumped vite to 8.0.5 (patched: server.fs.deny bypass, arbitrary file read via WebSocket, path traversal in optimized deps). Updated serialize-javascript@^6 override floor from 7.0.3 to 7.0.5 (patched: CPU exhaustion DoS). Refreshed pnpm-lock.yaml — updated CKEditor dev packages to 55.4.x, ESLint to 9.39.4, and other transitive dependencies now resolve to patched versions naturally.


📌 Related issues

  • See ckeditor/ckeditor5-internal#4359

💡 Additional information

The vite entry in minimumReleaseAgeExclude and the 'vite': '8.0.5' workspace override are temporary: vite 8.0.8 (released 2026-04-09) has fresh transitive deps blocked by the 3-day release age gate. Both can be removed after 2026-04-12.

Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 483c76e. Configure here.

Comment thread pnpm-workspace.yaml Outdated
@jr-cobweb
Copy link
Copy Markdown

also here for the serialize-javascript fix

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants