Skip to content

chore(deps): bump vitest to 4 + pin vite 6#47

Merged
sarahxsanders merged 1 commit into
mainfrom
posthog-code/fix-dev-security-bumps
Jun 9, 2026
Merged

chore(deps): bump vitest to 4 + pin vite 6#47
sarahxsanders merged 1 commit into
mainfrom
posthog-code/fix-dev-security-bumps

Conversation

@sarahxsanders

Copy link
Copy Markdown
Collaborator

fix security alerts, these are all development scoped

…ity alerts

Resolves the 4 open Dependabot alerts (2 critical vitest, 1 vite, 1 esbuild),
all development-scope. vitest 4 requires vite >=6, but vite is only a peer
dep so pnpm kept the vulnerable vite 5 / esbuild 0.24 in the tree. Adding
vite ^6.4.2 explicitly lets the tree resolve vite 6.4.3 + esbuild 0.25.12.

TypeScript stays at 5 (the major 5->6 jump Dependabot bundled in is unrelated
to the alerts and handled separately). All 516 tests pass; build is green.

Generated-By: PostHog Code
Task-Id: 6e197a79-aa12-4ffd-87ac-98f581de1218
@sarahxsanders sarahxsanders merged commit 1153430 into main Jun 9, 2026
11 checks passed
@sarahxsanders sarahxsanders deleted the posthog-code/fix-dev-security-bumps branch June 9, 2026 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants