Skip to content

fix: bump rollup to 4.59.0 (CVE path traversal)#96

Merged
cristipufu merged 1 commit intomainfrom
fix/rollup-vulnerability
Mar 2, 2026
Merged

fix: bump rollup to 4.59.0 (CVE path traversal)#96
cristipufu merged 1 commit intomainfrom
fix/rollup-vulnerability

Conversation

@cristipufu
Copy link
Member

Summary

  • Bump rollup from 4.57.1 to 4.59.0 to fix arbitrary file write via path traversal vulnerability (Dependabot high severity alert)

Test plan

  • npm run build in frontend dir still succeeds

🤖 Generated with Claude Code

This comment was marked as outdated.

@cristipufu cristipufu force-pushed the fix/rollup-vulnerability branch from 1ba0b5f to 02201bb Compare March 2, 2026 06:41
Resolves GitHub Dependabot alert for arbitrary file write via path
traversal in rollup >= 4.0.0, < 4.59.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cristipufu cristipufu force-pushed the fix/rollup-vulnerability branch from 02201bb to cfa3081 Compare March 2, 2026 06:44
@cristipufu cristipufu merged commit c0c3624 into main Mar 2, 2026
11 checks passed
@cristipufu cristipufu deleted the fix/rollup-vulnerability branch March 2, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants