Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,10 @@ All notable changes to this project are documented here. The format is based on
- **esbuild `^0.23.0` → `^0.28.1`** (dev dependency, the bundler). Every release below 0.28.1 is
covered by an esbuild advisory, and `^0.23` stops below 0.24, so Dependabot's security update could
not reach the fix and failed on every run. The build, the 147 tests, lint and typecheck pass on 0.28.2.
Vite 5, inside Vitest 2, still bundles its own esbuild 0.21; that needs the Vitest upgrade.
- **Vitest `^2` → `^3.2.6` and happy-dom `^15` → `^20.8.9`** (dev dependencies). Vitest below 3.2.6 lets its UI
server read and run arbitrary files; happy-dom below 20 allows a VM-context escape to code execution, and below
20.8.9 sends page-origin cookies on credentialed fetches. All 147 tests pass unchanged, and Vitest 3's Vite now
shares the patched esbuild instead of carrying 0.21.

### Added
- **Publish to npm or GitHub Packages.** `release.yml` takes a `workflow_dispatch` with `tag` and
Expand Down
6 changes: 3 additions & 3 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -109,16 +109,16 @@
"@eslint/js": "^9.9.0",
"@playwright/test": "~1.61.0",
"@testing-library/react": "^16.3.2",
"@vitest/coverage-v8": "^2.1.9",
"@vitest/coverage-v8": "^3.2.6",
"@webpixels/css": "^3.0.5",
"esbuild": "^0.28.1",
"eslint": "^9.9.0",
"happy-dom": "^15.0.0",
"happy-dom": "^20.8.9",
"react": "^19.2.7",
"react-dom": "^19.2.7",
"sass": "^1.101.0",
"typescript": "^5.5.0",
"vitest": "^2.0.5"
"vitest": "^3.2.6"
},
"publishConfig": {
"access": "public",
Expand Down
Loading