Fixes arbitrary file write via path traversal in rollup <4.59.0 (GHSA-mw96-cpmx-2vgc). Transitive dev dependency via vite in web/. Supersedes #1883 (Dependabot could not rebase/recreate due to removed dependabot.yml entry). Co-authored-by: xj <gh-xj@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| dist | ||
| src | ||
| .gitignore | ||
| index.html | ||
| netlify.toml | ||
| package-lock.json | ||
| package.json | ||
| package.nix | ||
| tsconfig.app.json | ||
| tsconfig.json | ||
| tsconfig.node.json | ||
| vite.config.ts | ||