Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

nerdy-tech-com-gitub
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade rollup from 4.22.4 to 4.49.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 77 versions ahead of your current version.

  • The recommended version was released 24 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
57 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
57 Proof of Concept
Release notes
Package name: rollup
  • 4.49.0 - 2025-08-27

    4.49.0

    2025-08-27

    Features

    • Allow config plugins to resolve imports first before deciding whether to treat them as external (#6038)

    Pull Requests

    • #6038: feat: Run external check in cli/run/loadConfigFile.ts as last in order to allow handling of e.g. workspace package imports in TS monorepos correctly (@ stazz, @ TrickyPi)
    • #6082: Improve build pipeline performance (@ lukastaegert)
  • 4.48.1 - 2025-08-25

    4.48.1

    2025-08-25

    Bug Fixes

    • Correctly ignore white-space in JSX strings around line-breaks (#6051)

    Pull Requests

  • 4.48.0 - 2025-08-23

    4.48.0

    2025-08-23

    Features

    • If configured, also keep unparseable import attributes of external dynamic imports in the output(#6071)

    Bug Fixes

    • Ensure variables referenced in non-removed import attributes are included (#6071)

    Pull Requests

  • 4.48.0-0 - 2025-08-22

    4.48.0-0

  • 4.47.1 - 2025-08-21

    4.47.1

    2025-08-21

    Bug Fixes

    • Revert build process changes to investigate issues (#6077)

    Pull Requests

  • 4.47.0 - 2025-08-21

    4.47.0

    2025-08-21

    Features

    • Aggressively reduce WASM build size (#6053)

    Bug Fixes

    • Fix illegal instruction error on Android ARM platforms (#6072)
    • Allow to pass explicit undefined for optional fields in Rollup types (#6061)

    Pull Requests

  • 4.46.4 - 2025-08-20

    4.46.4

    2025-08-20

    Bug Fixes

    • Do not omit synthetic namespaces when only accessed via in operator (#6052)

    Pull Requests

  • 4.46.3 - 2025-08-18

    4.46.3

    2025-08-18

    Bug Fixes

    • Resolve illegal instruction error on arm64 architectures (#6055)
    • Resolve sourcemap generation performance regression (#6057)

    Pull Requests

  • 4.46.2 - 2025-07-29

    4.46.2

    2025-07-29

    Bug Fixes

    • Fix in-operator handling for external namespace and when the left side cannot be analyzed (#6041)

    Pull Requests

  • 4.46.1 - 2025-07-28

    4.46.1

    2025-07-28

    Bug Fixes

    • Do not fail when using the in operator on external namespaces (#6036)

    Pull Requests

    • #6036: disables optimization for external namespace when using the in operator (@ TrickyPi)
  • 4.46.0 - 2025-07-27
  • 4.45.3 - 2025-07-26
  • 4.45.1 - 2025-07-15
  • 4.45.0 - 2025-07-12
  • 4.44.2 - 2025-07-04
  • 4.44.1 - 2025-06-26
  • 4.44.0 - 2025-06-19
  • 4.43.0 - 2025-06-11
  • 4.42.0 - 2025-06-06
  • 4.41.2 - 2025-06-06
  • 4.41.1 - 2025-05-24
  • 4.41.0 - 2025-05-18
  • 4.40.2 - 2025-05-06
  • 4.40.1 - 2025-04-28
  • 4.40.0 - 2025-04-12
  • 4.39.0 - 2025-04-02
  • 4.38.0 - 2025-03-29
  • 4.37.0 - 2025-03-23
  • 4.36.0 - 2025-03-17
  • 4.35.0 - 2025-03-08
  • 4.34.9 - 2025-03-01
  • 4.34.8 - 2025-02-17
  • 4.34.7 - 2025-02-14
  • 4.34.6 - 2025-02-07
  • 4.34.5 - 2025-02-07
  • 4.34.4 - 2025-02-05
  • 4.34.3 - 2025-02-05
  • 4.34.2 - 2025-02-04
  • 4.34.1 - 2025-02-03
  • 4.34.0 - 2025-02-01
  • 4.33.0 - 2025-02-01
  • 4.33.0-0 - 2025-01-28
  • 4.32.1 - 2025-01-28
  • 4.32.0 - 2025-01-24
  • 4.31.0 - 2025-01-19
  • 4.31.0-0 - 2025-01-14
  • 4.30.1 - 2025-01-07
  • 4.30.0 - 2025-01-06
  • 4.30.0-1 - 2024-12-30
  • 4.30.0-0 - 2024-12-21
  • 4.29.2 - 2025-01-05
  • 4.29.1 - 2024-12-21
  • 4.29.0 - 2024-12-20
  • 4.29.0-2 - 2024-12-20
  • 4.29.0-1 - 2024-12-19
  • 4.29.0-0 - 2024-12-16
  • 4.28.1 - 2024-12-06
  • 4.28.0 - 2024-11-30
  • 4.27.4 - 2024-11-23
  • 4.27.3 - 2024-11-18
  • 4.27.2 - 2024-11-15
  • 4.27.1 - 2024-11-15
  • 4.27.1-1 - 2024-11-15
  • 4.27.1-0 - 2024-11-15
  • 4.27.0 - 2024-11-15
  • 4.27.0-1 - 2024-11-14
  • 4.27.0-0 - 2024-11-13
  • 4.26.0 - 2024-11-13
  • 4.25.0 - 2024-11-09
  • 4.25.0-0 - 2024-10-29
  • 4.24.4 - 2024-11-04
  • 4.24.3 - 2024-10-29
  • 4.24.2 - 2024-10-27
  • 4.24.1 - 2024-10-27
  • 4.24.0 - 2024-10-02
  • 4.23.0 - 2024-10-01
  • 4.22.5 - 2024-09-27
  • 4.22.4 - 2024-09-21
from rollup GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade rollup from 4.22.4 to 4.49.0.

See this package in npm:
rollup

See this project in Snyk:
https://app.snyk.io/org/nerds-github/project/cff36355-d877-492a-a8fd-40687822fe66?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants