fix: upgrade vite to 6.4.3 to fix launch-editor command injection and fs.deny bypass vulnerabilities

- Fixes Dependabot alert #7 (GHSA-c27g-q93r-2cwf): launch-editor command injection via crafted request on Windows, patched in vite >= 5.4.9
- Fixes Dependabot alert #8 (GHSA-fx2h-pf6j-xcff): server.fs.deny bypass on Windows alternate paths, patched in vite >= 6.4.3
- Upgraded @vitejs/plugin-vue to ^5.2.4 for vite 6 compatibility
- Upgraded vue-tsc to ^2.2.12 for vite 6 compatibility
This commit is contained in:
2026-07-22 16:22:01 +08:00
parent 75e1177b70
commit a974dd03cb
2 changed files with 743 additions and 210 deletions
+740 -207
View File
File diff suppressed because it is too large Load Diff