mirror of
https://github.com/pbakaus/impeccable.git
synced 2026-09-17 08:36:25 +03:00
Bump astro test fixture to ^7.1.0 to clear dependabot XSS alerts
The astro-vite7 live-e2e fixture pinned astro ^6.0.0, which resolves into the vulnerable range of three dependabot advisories: GHSA-4g3v-8h47-v7g6 (reflected XSS via View Transition animation properties, medium), GHSA-f48w-9m4c-m7f5 (XSS via spread attribute names in renderHTMLElement, medium), and GHSA-7pw4-f3q4-r2p2 (XSS via transition:* directive values, low). All three are patched by 7.1.0. Dev-only test fixture; the vulnerable code paths (View Transitions, transition directives, spread attributes) are not exercised by this static, non-hydrated page, so real exposure is nil. Bumped anyway as the cheap, correct fix. Also corrected the now-stale fixture label to "Astro 7 + Vite 7". Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
9dade04bbf
commit
9f5bbed8b8
@@ -9,6 +9,6 @@
|
||||
"preview": "astro preview"
|
||||
},
|
||||
"devDependencies": {
|
||||
"astro": "^6.0.0"
|
||||
"astro": "^7.1.0"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"name": "Astro 6 + Vite 7",
|
||||
"name": "Astro 7 + Vite 7",
|
||||
"config": {
|
||||
"files": ["src/layouts/Layout.astro"],
|
||||
"insertBefore": "</body>",
|
||||
|
||||
Reference in New Issue
Block a user