Skip to content

Raise Vitest and happy-dom past their security advisories - #11

Merged
imanimanyara merged 1 commit into
mainfrom
fix/vitest-happy-dom-security
Oct 5, 2026
Merged

imanimanyara merged 1 commit into
mainfrom
fix/vitest-happy-dom-security

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

The rest of what Dependabot reports on tabar's dev dependencies; the esbuild bump merged as #10.

Package Advisory Severity Raised to
vitest below 3.2.6: the UI server can read and run arbitrary files critical ^3.2.6 (+ @vitest/coverage-v8)
happy-dom below 20: VM context escape to code execution critical ^20.8.9
happy-dom below 20.8.9: credentialed fetch sends page-origin cookies high ^20.8.9

Locally, on Vitest 3.2.7 and happy-dom 20.14.5: build, 147 of 147 tests, lint and typecheck pass, and Vite now shares the patched esbuild 0.28.2 instead of carrying 0.21.

Caveat: Vite 7, which Vitest 3 resolves to, needs Node 20.19+, and happy-dom 20 needs Node 20+, so the test (18) leg may no longer be able to run the suite. Node 18 has been end-of-life since April 2025. The library's own runtime floor (engines.node >=18) is unchanged.

Dependabot reports Vitest below 3.2.6 (UI server reads and runs arbitrary files, critical) and happy-dom below 20 (VM context escape, critical) and below 20.8.9 (credentialed fetch sends page-origin cookies, high). Both are dev dependencies. All 147 tests pass unchanged on Vitest 3.2.7 and happy-dom 20.14.5, and Vite now shares the patched esbuild 0.28.2.
Copilot AI balanced review requested due to automatic review settings October 5, 2026 14:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit 581a3c9 into main Oct 5, 2026
6 checks passed
@imanimanyara
imanimanyara deleted the fix/vitest-happy-dom-security branch October 5, 2026 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants