Skip to content

Update vulnerable frontend dependencies - #26

Merged
fengting124 merged 2 commits into
mainfrom
fix/frontend-dependency-security
Jul 11, 2026
Merged

Update vulnerable frontend dependencies#26
fengting124 merged 2 commits into
mainfrom
fix/frontend-dependency-security

Conversation

@fengting124

Copy link
Copy Markdown
Owner

What

  • refresh the lockfile within existing package ranges
  • update Vite 8.0.14 to 8.1.4 and Babel 7.29.0 to 7.29.7
  • record advisory remediation and verification evidence

Why

The current lockfile contains one high and one low advisory, including Windows-specific Vite development-server issues relevant to this repository's primary local environment.

Verification

  • clean npm ci passed
  • npm audit --audit-level=low: zero vulnerabilities
  • frontend: 8 tests passed
  • ESLint passed
  • Vite 8.1.4 production build passed
  • no application source or UI styling changed

@fengting124
fengting124 merged commit 108e610 into main Jul 11, 2026
4 checks passed
@fengting124
fengting124 deleted the fix/frontend-dependency-security branch July 11, 2026 00:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant