Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade vite from 3.1.6 to 4.5.6 #153

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

naiba4
Copy link
Owner

@naiba4 naiba4 commented Jan 22, 2025

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • apps/playground-sveltekit/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Origin Validation Error
SNYK-JS-VITE-8648411
  738  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Copy link

changeset-bot bot commented Jan 22, 2025

⚠️ No Changeset found

Latest commit: 6665351

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Copy link

New, updated, and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@cloudflare/workers-types@3.16.0 None 0 65 kB threepointone
npm/@esbuild/android-arm@0.15.10 🔁 npm/@esbuild/android-arm@0.24.2 None 0 10.6 MB evanw
npm/@esbuild/linux-loong64@0.15.10 🔁 npm/@esbuild/linux-loong64@0.24.2 None 0 8.45 MB evanw
npm/@eslint/eslintrc@1.3.1 filesystem, unsafe Transitive: eval +3 1.59 MB eslintbot
npm/@humanwhocodes/config-array@0.10.4 None 0 49.1 kB nzakas
npm/@humanwhocodes/gitignore-to-minimatch@1.0.2 None 0 18.8 kB nzakas
npm/@humanwhocodes/object-schema@1.2.1 None 0 49.4 kB nzakas
npm/@iarna/toml@2.2.5 eval 0 99 kB iarna
npm/@jridgewell/resolve-uri@3.1.0 None 0 55.2 kB jridgewell
npm/@jridgewell/sourcemap-codec@1.4.14 None 0 40 kB jridgewell
npm/@jridgewell/trace-mapping@0.3.15 None 0 151 kB jridgewell
npm/@mapbox/node-pre-gyp@1.0.10 🔁 npm/@mapbox/node-pre-gyp@2.0.0-rc.0 None 0 167 kB mapbox-npm-08
npm/@panva/hkdf@1.0.1 None 0 12.2 kB panva
npm/@polka/url@1.0.0-next.21 🔁 npm/@polka/url@1.0.0-next.28 None 0 5.53 kB lukeed
npm/@rollup/plugin-commonjs@22.0.2 🔁 npm/@rollup/plugin-commonjs@28.0.2 None 0 466 kB shellscape
npm/@rollup/plugin-json@4.1.0 🔁 npm/@rollup/plugin-json@6.1.0 None +1 63.3 kB shellscape
npm/@rollup/plugin-node-resolve@14.1.0 🔁 npm/@rollup/plugin-node-resolve@15.3.1 filesystem Transitive: environment +1 233 kB shellscape
npm/@sveltejs/adapter-auto@1.0.0-next.80 None 0 5.04 kB svelte-admin
npm/@sveltejs/adapter-cloudflare@1.0.0-next.38 filesystem 0 12.8 kB svelte-admin
npm/@sveltejs/adapter-netlify@1.0.0-next.78 environment, filesystem 0 1.51 MB svelte-admin
npm/@sveltejs/adapter-node@1.0.0-next.96 filesystem 0 784 kB svelte-admin
npm/@sveltejs/adapter-vercel@1.0.0-next.77 filesystem 0 14.6 kB svelte-admin
npm/@sveltejs/kit@1.0.0-next.511 environment, eval, filesystem +1 833 kB svelte-admin
npm/@sveltejs/vite-plugin-svelte@1.0.9 environment, eval, filesystem, unsafe +3 1.01 MB svelte-admin
npm/@types/cookie@0.5.1 None 0 9.76 kB types
npm/@types/estree@0.0.39 None 0 17.8 kB types
npm/@types/json-schema@7.0.9 None 0 32.2 kB types
npm/@types/node@17.0.19 🔁 npm/@types/node@22.10.7 None 0 1.68 MB types
npm/@types/pug@2.0.6 None 0 9.86 kB types
npm/@types/resolve@1.17.1 🔁 npm/@types/resolve@1.20.2 None 0 7.69 kB types
npm/@types/sass@1.43.1 None 0 13.1 kB types
npm/@typescript-eslint/eslint-plugin@5.36.1 None 0 2.31 MB jameshenry
npm/@typescript-eslint/parser@5.36.1 None 0 30.3 kB jameshenry
npm/@typescript-eslint/scope-manager@5.36.1 None 0 574 kB jameshenry
npm/@typescript-eslint/type-utils@5.36.1 None 0 86.2 kB jameshenry
npm/@typescript-eslint/types@5.36.1 None 0 214 kB jameshenry
npm/@typescript-eslint/typescript-estree@5.36.1 environment, filesystem 0 523 kB jameshenry
npm/@typescript-eslint/utils@5.36.1 None 0 477 kB jameshenry
npm/@typescript-eslint/visitor-keys@5.36.1 None 0 17.6 kB jameshenry
npm/@vercel/nft@0.22.1 🔁 npm/@vercel/nft@0.27.10 environment, eval, unsafe 0 168 kB styfle
npm/abbrev@1.1.1 🔁 npm/abbrev@3.0.0 None 0 4.78 kB isaacs
npm/acorn@8.8.0 None 0 466 kB marijn
npm/agent-base@6.0.2 🔁 npm/agent-base@7.1.3 None 0 34.6 kB tootallnate
npm/anymatch@3.1.2 🔁 npm/anymatch@3.1.3 None +1 18.8 kB paulmillr
npm/aproba@2.0.0 None 0 8.05 kB iarna
npm/are-we-there-yet@2.0.0 None 0 14.1 kB gar
npm/binary-extensions@2.2.0 🔁 npm/binary-extensions@2.3.0 None 0 5.36 kB sindresorhus
npm/braces@3.0.2 None 0 49.2 kB doowb
npm/buffer-crc32@0.2.13 🔁 npm/buffer-crc32@1.0.0 None 0 7.95 kB brianloveswords
npm/chokidar@3.5.3 🔁 npm/chokidar@3.6.0 None 0 90.1 kB paulmillr
npm/color-support@1.1.3 None 0 9.23 kB isaacs
npm/console-control-strings@1.1.0 None 0 12.7 kB iarna
npm/cookie@0.5.0 None 0 23.1 kB dougwilson
npm/cross-spawn@7.0.3 environment, filesystem, shell 0 21.2 kB satazor
npm/debug@4.3.4 🔁 npm/debug@2.6.9 None 0 42.4 kB qix
npm/deepmerge@4.2.2 🔁 npm/deepmerge@4.3.1 None 0 30.1 kB tehshrike
npm/delegates@1.0.0 None 0 7.46 kB tjholowaychuk
npm/detect-indent@6.1.0 None 0 9.68 kB sindresorhus
npm/detect-libc@2.0.1 🔁 npm/detect-libc@1.0.3 None 0 19.9 kB lovell
npm/devalue@4.0.0 None 0 22.8 kB rich_harris
npm/es6-promise@3.3.1 eval 0 173 kB stefanpenner
npm/esbuild-android-64@0.15.10 None 0 10.6 MB evanw
npm/esbuild-android-arm64@0.15.10 None 0 8.85 MB evanw
npm/esbuild-darwin-64@0.15.10 None 0 9.03 MB evanw
npm/esbuild-darwin-arm64@0.15.10 None 0 8.67 MB evanw
npm/esbuild-freebsd-64@0.15.10 None 0 8.57 MB evanw
npm/esbuild-freebsd-arm64@0.15.10 None 0 8 MB evanw
npm/esbuild-linux-32@0.15.10 None 0 8.14 MB evanw
npm/esbuild-linux-64@0.15.10 None 0 8.57 MB evanw
npm/esbuild-linux-arm@0.15.10 None 0 8.19 MB evanw
npm/esbuild-linux-arm64@0.15.10 None 0 8 MB evanw
npm/esbuild-linux-mips64le@0.15.10 None 0 9.31 MB evanw
npm/esbuild-linux-ppc64le@0.15.10 None 0 8.13 MB evanw
npm/esbuild-linux-riscv64@0.15.10 None 0 8.19 MB evanw
npm/esbuild-linux-s390x@0.15.10 None 0 8.85 MB evanw
npm/esbuild-netbsd-64@0.15.10 None 0 8.54 MB evanw
npm/esbuild-openbsd-64@0.15.10 None 0 8.57 MB evanw
npm/esbuild-sunos-64@0.15.10 None 0 8.55 MB evanw
npm/esbuild-windows-32@0.15.10 None 0 8.38 MB evanw
npm/esbuild-windows-64@0.15.10 None 0 8.71 MB evanw
npm/esbuild-windows-arm64@0.15.10 None 0 8.1 MB evanw
npm/esbuild@0.15.10 environment, filesystem, network, shell 0 121 kB evanw
npm/eslint-config-prettier@8.5.0 None 0 18.2 kB lydell
npm/eslint-plugin-svelte3@4.0.0 None 0 41.3 kB conduitry
npm/eslint-scope@5.1.1 None 0 78.4 kB eslintbot
npm/eslint-utils@3.0.0 None +1 383 kB mysticatea
npm/eslint-visitor-keys@3.3.0 None 0 31.1 kB eslintbot
npm/eslint@8.23.0 filesystem +3 2.99 MB eslintbot
npm/espree@9.4.0 None 0 76.3 kB eslintbot
npm/esquery@1.4.0 None 0 986 kB michaelficarra
npm/estraverse@4.3.0 None 0 36.3 kB michaelficarra
npm/fast-glob@3.2.11 filesystem +1 97.7 kB mrmlnc
npm/fastq@1.13.0 None 0 38.2 kB matteo.collina
npm/fill-range@7.0.1 None 0 16.4 kB jonschlinkert
npm/flat-cache@3.0.4 filesystem 0 30 kB royriojas
npm/flatted@3.2.5 None 0 78.7 kB webreflection
npm/fsevents@2.3.2 🔁 npm/fsevents@2.3.3 None 0 156 kB pipobscure
npm/function-bind@1.1.1 None 0 25.2 kB ljharb
npm/functional-red-black-tree@1.0.1 None 0 43.5 kB mikolalysenko
npm/gauge@3.0.2 None 0 48.5 kB gar
npm/glob@7.2.0 🔁 npm/glob@10.4.5, npm/glob@7.2.3 None 0 54.7 kB isaacs
npm/globals@13.17.0 None 0 46.3 kB sindresorhus
npm/globalyzer@0.1.0 None 0 11.4 kB terkelg
npm/globrex@0.1.2 None 0 14.2 kB terkelg
npm/graceful-fs@4.2.10 environment, filesystem 0 32.5 kB isaacs
npm/grapheme-splitter@1.0.4 None 0 237 kB orling
npm/has-unicode@2.0.1 environment 0 3.44 kB iarna
npm/has@1.0.3 None 0 2.77 kB ljharb
npm/https-proxy-agent@5.0.1 🔁 npm/https-proxy-agent@7.0.6 None 0 26 kB tootallnate
npm/ignore@5.2.0 None 0 48.9 kB kael
npm/is-builtin-module@3.2.0 None 0 3.83 kB sindresorhus
npm/is-core-module@2.10.0 None 0 27.3 kB ljharb
npm/jose@4.9.3 network 0 551 kB panva
npm/kleur@4.1.4 🔁 npm/kleur@3.0.3 None 0 20.2 kB lukeed
npm/magic-string@0.25.7 None 0 364 kB rich_harris
npm/make-dir@3.1.0 filesystem +1 77.1 kB sindresorhus
npm/micromatch@4.0.5 None 0 55.9 kB jonschlinkert
npm/minimist@1.2.6 None 0 33.2 kB substack
npm/minipass@3.3.4 🔁 npm/minipass@3.3.6, npm/minipass@5.0.0, npm/minipass@7.1.2 None 0 47.8 kB isaacs
npm/mri@1.2.0 None 0 13.3 kB lukeed
npm/mrmime@1.0.1 🔁 npm/mrmime@2.0.0 None 0 31 kB lukeed
npm/ms@2.1.2 None 0 6.84 kB styfle
npm/next-auth@4.10.3 environment, network +1 362 kB balazsorban
npm/node-gyp-build@4.5.0 🔁 npm/node-gyp-build@4.8.4 None 0 12.9 kB vweevers
npm/nopt@5.0.0 🔁 npm/nopt@8.1.0 environment 0 25.8 kB isaacs
npm/npmlog@5.0.1 None 0 16.6 kB gar
npm/object-assign@4.1.1 None 0 5.49 kB sindresorhus
npm/oidc-token-hash@5.0.1 🔁 npm/oidc-token-hash@5.0.3 None 0 8.52 kB panva
npm/openid-client@5.1.3 network, unsafe 0 133 kB panva
npm/optionator@0.9.1 None +1 71.3 kB gkz
npm/picocolors@1.0.0 environment 0 5.66 kB alexeyraspopov
npm/preact-render-to-string@5.1.20 None 0 254 kB jdecroock
npm/preact@10.6.6 None 0 904 kB marvinhagemeister
npm/prettier-plugin-svelte@2.7.0 environment 0 232 kB conduitry
npm/prettier@2.7.1 environment, filesystem, unsafe 0 15.8 MB prettier-bot
npm/punycode@2.1.1 🔁 npm/punycode@2.3.1 None 0 32.4 kB mathias
npm/readable-stream@3.6.0 🔁 npm/readable-stream@2.3.8, npm/readable-stream@4.7.0 None 0 122 kB matteo.collina
npm/regenerator-runtime@0.13.9 None 0 27.4 kB benjamn
npm/regexparam@2.0.1 None 0 15.9 kB lukeed
npm/rollup-pluginutils@2.8.2 None +1 256 kB guybedford
npm/rollup@2.79.1 🔁 npm/rollup@4.31.0 environment, filesystem, unsafe 0 6.7 MB lukastaegert
npm/sade@1.8.1 None 0 31.5 kB lukeed
npm/sander@0.5.1 filesystem +2 218 kB rich_harris
npm/semver@7.3.8 None 0 88.2 kB gar
npm/set-blocking@2.0.0 None 0 4.22 kB bcoe
npm/set-cookie-parser@2.5.1 None 0 15 kB nfriedly
npm/sirv@2.0.2 filesystem 0 29.9 kB lukeed
npm/sorcery@0.10.0 None 0 147 kB rich_harris
npm/sourcemap-codec@1.4.8 None 0 31.8 kB rich_harris
npm/svelte-check@2.9.0 None 0 4.3 MB svelte-language-tools-deploy
npm/svelte-hmr@0.15.0 None 0 78.2 kB rixo
npm/svelte-preprocess@4.10.3 environment, filesystem 0 147 kB kaisermann
npm/svelte@3.49.0 None 0 7.25 MB conduitry
npm/tar@6.1.11 🔁 npm/tar@7.4.3 None 0 161 kB isaacs
npm/tiny-glob@0.2.9 filesystem 0 12.1 kB terkelg
npm/totalist@3.0.0 🔁 npm/totalist@3.0.1 None 0 7.39 kB lukeed
npm/tslib@1.14.1 None 0 34 kB typescript-bot
npm/tsutils@3.21.0 None 0 382 kB ajaff
npm/type-fest@0.20.2 🔁 npm/type-fest@0.21.3, npm/type-fest@0.6.0, npm/type-fest@0.8.1 None 0 111 kB sindresorhus
npm/typescript@4.5.5 None 0 64 MB typescript-bot
npm/undici@5.11.0 environment, network, unsafe 0 900 kB ronag
npm/uri-js@4.4.1 None 0 470 kB garycourt
npm/util-deprecate@1.0.2 None 0 5.48 kB tootallnate
npm/vite@4.5.9 Transitive: environment, filesystem, network, shell +28 214 MB antfu, patak, soda, ...2 more
npm/which@2.0.2 environment 0 9.97 kB isaacs
npm/wide-align@1.1.5 None 0 4.47 kB iarna
npm/word-wrap@1.2.3 None 0 10.6 kB jonschlinkert
npm/worktop@0.8.0-next.14 None 0 86.7 kB lukeed
npm/yocto-queue@0.1.0 None 0 6.03 kB sindresorhus

View full report↗︎

Copy link

Report is too large to display inline.
View full report↗︎

Next steps

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/which@2.0.2
  • @SocketSecurity ignore npm/functional-red-black-tree@1.0.1
  • @SocketSecurity ignore npm/ms@2.1.2
  • @SocketSecurity ignore npm/estraverse@4.3.0
  • @SocketSecurity ignore npm/cross-spawn@7.0.3
  • @SocketSecurity ignore npm/make-dir@3.1.0
  • @SocketSecurity ignore npm/braces@3.0.2
  • @SocketSecurity ignore npm/util-deprecate@1.0.2
  • @SocketSecurity ignore npm/object-assign@4.1.1
  • @SocketSecurity ignore npm/y18n@5.0.8
  • @SocketSecurity ignore npm/yargs-parser@21.1.1
  • @SocketSecurity ignore npm/console-control-strings@1.1.0
  • @SocketSecurity ignore npm/set-blocking@2.0.0
  • @SocketSecurity ignore npm/delegates@1.0.0
  • @SocketSecurity ignore npm/has-unicode@2.0.1
  • @SocketSecurity ignore npm/picocolors@1.0.0
  • @SocketSecurity ignore npm/aproba@2.0.0
  • @SocketSecurity ignore npm/are-we-there-yet@2.0.0
  • @SocketSecurity ignore npm/color-support@1.1.3
  • @SocketSecurity ignore npm/cookie@0.5.0
  • @SocketSecurity ignore npm/gauge@3.0.2
  • @SocketSecurity ignore npm/grapheme-splitter@1.0.4
  • @SocketSecurity ignore npm/npmlog@5.0.1
  • @SocketSecurity ignore npm/sade@1.8.1
  • @SocketSecurity ignore npm/semver@6.3.0
  • @SocketSecurity ignore npm/cookie@0.4.2
  • @SocketSecurity ignore npm/semver@7.3.8
  • @SocketSecurity ignore npm/sourcemap-codec@1.4.8
  • @SocketSecurity ignore npm/prettier@2.7.1
  • @SocketSecurity ignore npm/@iarna/toml@2.2.5
  • @SocketSecurity ignore npm/undici@5.11.0
  • @SocketSecurity ignore npm/es6-promise@3.3.1
  • @SocketSecurity ignore npm/globalyzer@0.1.0
  • @SocketSecurity ignore npm/globrex@0.1.2
  • @SocketSecurity ignore npm/sander@0.5.1
  • @SocketSecurity ignore npm/sirv@2.0.2
  • @SocketSecurity ignore npm/tiny-glob@0.2.9
  • @SocketSecurity ignore npm/@typescript-eslint/typescript-estree@5.36.1
  • @SocketSecurity ignore npm/@typescript-eslint/utils@5.36.1
  • @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@5.36.1
  • @SocketSecurity ignore npm/eslint-plugin-svelte3@4.0.0
  • @SocketSecurity ignore npm/next-auth@4.10.3
  • @SocketSecurity ignore npm/@sveltejs/adapter-node@1.0.0-next.96
  • @SocketSecurity ignore npm/@sveltejs/vite-plugin-svelte@1.0.9
  • @SocketSecurity ignore npm/@sveltejs/adapter-netlify@1.0.0-next.78
  • @SocketSecurity ignore npm/prettier-plugin-svelte@2.7.0
  • @SocketSecurity ignore npm/preact-render-to-string@5.1.20
  • @SocketSecurity ignore npm/svelte-preprocess@4.10.3
  • @SocketSecurity ignore npm/jose@4.9.3
  • @SocketSecurity ignore npm/@sveltejs/kit@1.0.0-next.511

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants