Skip to content

Conversation

@BYK
Copy link
Member

@BYK BYK commented Jan 6, 2026

This PR updates vite from ^5.4.19 to ^5.4.21 to fix a security vulnerability where server.fs.deny could be bypassed via a backslash in the URL on Windows. This ensures that files denied by server.fs.deny are properly protected.

This commit updates the vite dependency to version 5.4.21. This includes updates to related packages such as @tailwindcss/vite, @vitejs/plugin-react, vite-plugin-dts, vite-plugin-svgr, and vitest.

Co-authored-by: burak.kaya <[email protected]>
@cursor
Copy link

cursor bot commented Jan 6, 2026

Cursor Agent can help with this pull request. Just @cursor in comments and I'll start working on changes in this branch.
Learn more about Cursor Agents

@vercel
Copy link

vercel bot commented Jan 6, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
spotlightjs Ready Ready Preview, Comment Jan 6, 2026 1:53pm

@BYK BYK deployed to Preview January 6, 2026 13:53 — with GitHub Actions Active
@BYK BYK marked this pull request as ready for review January 6, 2026 13:56
@BYK BYK enabled auto-merge (squash) January 6, 2026 13:56
@BYK BYK merged commit b1d4b74 into main Jan 6, 2026
20 checks passed
@BYK BYK deleted the cursor/vite-windows-deny-bypass-662b branch January 6, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants