Skip to content

fix: update vitest to resolve CVE-2026-84373 - #51

Closed
independabot-soc2[bot] wants to merge 2 commits into
mainfrom
independabot/vitest-CVE-2026-84373
Closed

independabot-soc2[bot] wants to merge 2 commits into
mainfrom
independabot/vitest-CVE-2026-84373

Conversation

@independabot-soc2

Copy link
Copy Markdown
Contributor

Hi, this is independabot — not Lili! You can ask her if you have questions, but she had no hand in generating this PR other than setting up the independabot schedule.

Please merge this PR yourself, if you approve.

BEFORE YOU MERGE

Instructions for resolving the vuln — test to make sure that nothing is broken, check compatibility, etc.

  • Dependency: vitest (devDependency) updated ^4.1.7 → ^4.1.11
  • Advisory: GHSA-82fw-gwwq-j7x9 (CVE-2026-84373)
  • Dependabot alert: https://github.com/warpdotdev/oz-agent-action/security/dependabot/47
  • Dependabot couldn't auto-fix this one (update_not_possible: "other dependencies require a version incompatible with this update"); npm install vitest@4.1.11 resolved cleanly here and pulled all @vitest/* subpackages to 4.1.11 too.
  • Verification: npm audit no longer reports this advisory, npm run lint clean, npm test 27/27 pass, npm run build succeeds with no dist/index.js diff (vitest is dev-only).

Highlight the risky code / where the dependency was used

Dev-only dependency (test runner). No production/runtime code paths affected.

Special instructions for this PR

None.

AFTER YOU MERGE

None.

Co-Authored-By: Warp agent@warp.dev

Co-Authored-By: Oz <oz-agent@warp.dev>
@independabot-soc2
independabot-soc2 Bot requested review from captainsafia and tnederlof and removed request for tnederlof September 11, 2026 13:57
@warp-agent-staging

Copy link
Copy Markdown
Contributor

This PR was generated with Warp.

Comment @warp-staging-factory on this PR to send it follow-up work.

View run View conversation View origin

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants