Skip to content

fix(web): patch rollup path traversal (GHSA, #17)#75

Merged
maskedsyntax merged 1 commit intomainfrom
fix/rollup-path-traversal
Apr 6, 2026
Merged

fix(web): patch rollup path traversal (GHSA, #17)#75
maskedsyntax merged 1 commit intomainfrom
fix/rollup-path-traversal

Conversation

@maskedsyntax
Copy link
Copy Markdown
Member

Adds an npm overrides entry pinning rollup to ^4.59.0 (resolved to 4.60.1), patching the Arbitrary File Write via Path Traversal vulnerability pulled in transitively through vite@6.4.1. Fixes Dependabot alert #17.

@vercel
Copy link
Copy Markdown

vercel bot commented Apr 6, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hashprep Ready Ready Preview, Comment Apr 6, 2026 9:38am

@maskedsyntax maskedsyntax merged commit 48aa9f0 into main Apr 6, 2026
6 checks passed
@maskedsyntax maskedsyntax deleted the fix/rollup-path-traversal branch April 6, 2026 10:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant