Files
Æmotion StudioandClaude Opus 4.8 353e8868ac fix(security): Bump vitest to ^4.1.0 to patch GHSA-5xrq-8626-4rwp
Upgrade vitest and @vitest/coverage-v8 from ^1.2.2 (resolved 1.6.1) to
^4.1.0 (resolved 4.1.8) to address CVE-2026-47429, a critical (CVSS 9.8)
arbitrary file read/write/execute vulnerability in the Vitest UI server
affecting versions < 4.1.0. Dev-only dependency.

The regenerated lockfile resolves vite@8 (vitest 4 requires vite >= 6).
Verified the major version bump: all 85 tests pass, tsc --noEmit is clean,
and the v8 coverage report generates successfully.

Bump package versions: pyproject 1.3.3 -> 1.3.4, web 1.0.2 -> 1.0.3, and
document the fix in the changelog.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 14:39:33 -07:00

3 lines
29 B
YAML