Skip to content

SECVULN-45976 vitest upgrade to 4.1.0#109

Merged
nasareeny merged 2 commits into
mainfrom
SECVULN-45976
Jun 22, 2026
Merged

SECVULN-45976 vitest upgrade to 4.1.0#109
nasareeny merged 2 commits into
mainfrom
SECVULN-45976

Conversation

@nasareeny

@nasareeny nasareeny commented Jun 22, 2026

Copy link
Copy Markdown
Collaborator

Summary

This PR remediates GHSA-5xrq-8626-4rwp by upgrading Vitest dependencies to a non-vulnerable release.

Advisory: GHSA-5xrq-8626-4rwp

https://hashicorp.atlassian.net/browse/SECVULN-45976

Changes

  1. Upgraded vitest in package.json from ^2.1.8 to ^4.1.0 (resolved to 4.1.9 in lockfile).

  2. Upgraded @vitest/coverage-v8 in package.json from ^2.1.8 to ^4.1.0 (resolved to 4.1.9 in lockfile).

  3. Updated dependency resolution in package-lock.json

Validation

Verified installed versions:
vitest@4.1.9
vitest/coverage-v8@4.1.9]

Ran test suite successfully:
npm test
1 test file passed, 5 tests passed

@nasareeny nasareeny requested a review from a team as a code owner June 22, 2026 05:28
@nasareeny nasareeny merged commit 834e3c5 into main Jun 22, 2026
6 checks passed
@nasareeny nasareeny deleted the SECVULN-45976 branch June 22, 2026 05:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants