Security
- Bump
vitefrom 8.0.1 to 8.0.5 -- fixes path traversal in optimized deps.maphandling,server.fs.denybypass with queries, and arbitrary file read via dev server WebSocket - Bump
github.com/go-jose/go-jose/v3from 3.0.4 to 3.0.5 -- fixes panic in JWE decryption - Bump
github.com/go-jose/go-jose/v4from 4.1.3 to 4.1.4 -- fixes panic in JWE decryption - Bump
picomatchfrom 4.0.3 to 4.0.4 -- fixes method injection in POSIX character classes - Fix
brace-expansionandyamlmoderate vulnerabilities via npm audit fix
Changed
- Bump
typescriptfrom 5.9.3 to 6.0.2 - Bump
sveltefrom 5.54.0 to 5.55.1 - Bump
eslintfrom 10.0.3 to 10.1.0 - Bump
eslint-plugin-sveltefrom 3.15.2 to 3.16.0 - Bump
jsdomfrom 29.0.0 to 29.0.1 - Bump
svelte-checkfrom 4.4.5 to 4.4.6 - Bump
markedfrom 17.0.4 to 17.0.5 - Bump
@inlang/paraglide-jsfrom 2.15.0 to 2.15.1 - Bump
@vitest/coverage-v8from 4.1.0 to 4.1.2 - Bump
typescript-eslintfrom 8.57.1 to 8.58.0 - Bump
actions/setup-gofrom 6.3.0 to 6.4.0 - Bump
github/codeql-actionfrom 4.33.0 to 4.35.1 - Bump
codecov/codecov-actionfrom 5.5.2 to 6.0.0 - Bump
SonarSource/sonarqube-scan-actionfrom 7.0.0 to 7.1.0