Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

faissaloux
Copy link
Contributor

These are the two CVEs affeting vite
GHSA-g4jq-h2w9-997c
GHSA-jqfw-vq24-v9c3

Affected versions

>=7.0.0,<=7.0.6

@GrahamCampbell
Copy link
Member

This doesn't really "fix" anything, because both the old and new version constraints will install the latest 2.x version.

@AhmedAlaa4611
Copy link
Contributor

This doesn't really "fix" anything, because both the old and new version constraints will install the latest 2.x version.

I think many users remain at older versions due to lock files, so explicit bump is safer and avoids silently continuing to install a vulnerable dependency.

@GrahamCampbell
Copy link
Member

Sure, but no existing users with their existing lock files will get getting this change.

@taylorotwell taylorotwell merged commit eebb39c into laravel:12.x Sep 10, 2025
6 checks passed
@faissaloux faissaloux deleted the security/update-vite branch September 10, 2025 00:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants