Skip to content

Conversation

@mitsuki31
Copy link
Owner

Overview

This update clears out a security advisory tied to an outdated esbuild release. The vulnerable range had an issue that allowed unintended cross-origin request behavior under certain conditions, which is best removed from the toolchain altogether.

Changes Made

  • Updated esbuild to version 0.27.1, addressing a moderate-severity advisory.
  • Removed the vulnerable range (<=0.24.2) previously flagged by npm audit.

Impact

The build system no longer depends on a version of esbuild with known security issues. No functional changes occur in the output; this strictly improves the safety of the tooling.

Summary

This tidies up a lingering security advisory by lifting esbuild to a safe version, keeping the build chain clean and predictable.

This change address security advisory with moderate severity.

NPM Audit Report
-----

esbuild  <=0.24.2
Severity: moderate
esbuild enables any website to send any requests to the development
server and read the response -
GHSA-67mh-4wv8-2f99
@mitsuki31 mitsuki31 self-assigned this Dec 11, 2025
@mitsuki31 mitsuki31 added patch Patch changes (e.g., hotfix bugs and issues) bugfix Bug or issue fixes labels Dec 11, 2025
@mitsuki31 mitsuki31 merged commit 4491cf6 into master Dec 11, 2025
4 checks passed
@mitsuki31 mitsuki31 deleted the chore/bump-esbuild-security-fix branch December 11, 2025 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Bug or issue fixes patch Patch changes (e.g., hotfix bugs and issues)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants