Upgrade vitest and @vitest/coverage-v8 from ^1.2.2 (resolved 1.6.1) to ^4.1.0 (resolved 4.1.8) to address CVE-2026-47429, a critical (CVSS 9.8) arbitrary file read/write/execute vulnerability in the Vitest UI server affecting versions < 4.1.0. Dev-only dependency. The regenerated lockfile resolves vite@8 (vitest 4 requires vite >= 6). Verified the major version bump: all 85 tests pass, tsc --noEmit is clean, and the v8 coverage report generates successfully. Bump package versions: pyproject 1.3.3 -> 1.3.4, web 1.0.2 -> 1.0.3, and document the fix in the changelog. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3 lines
29 B
YAML
3 lines
29 B
YAML
allowBuilds:
|
|
esbuild: true
|