Skip to content

fix: address vite and lodash dependabot alerts#368

Merged
thymikee merged 2 commits intomainfrom
codex/fix-dependabot-vite-lodash-es
Apr 8, 2026
Merged

fix: address vite and lodash dependabot alerts#368
thymikee merged 2 commits intomainfrom
codex/fix-dependabot-vite-lodash-es

Conversation

@thymikee
Copy link
Copy Markdown
Contributor

@thymikee thymikee commented Apr 7, 2026

Summary

  • bump Vite to 8.0.7 to cover the open Vite advisories
  • bump @microsoft/api-extractor so the root toolchain resolves lodash 4.18.1 without an override
  • update the docs stack to @callstack/rspress-preset 0.6.1, @callstack/rspress-theme 0.6.1, and @rspress/core 2.0.8
  • keep a temporary pnpm override for lodash-es because the published @rspress/core/@rspress/shared packages still declare lodash-es ^4.17.23

The lodash-es override should be removed once the upstream Rspress dependency chain publishes a release that no longer requires it. The theme release from callstack/rspress-theme#121 is included here, but it is not sufficient on its own to remove the override.

Validation

  • pnpm check:tooling
  • pnpm --dir website build

@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 7, 2026

PR Preview Action v1.8.1

QR code for preview link

🚀 View preview at
https://callstackincubator.github.io/agent-device/pr-preview/pr-368/

Built to branch gh-pages at 2026-04-07 19:11 UTC.
Preview will be ready when the GitHub Pages deployment is complete.

@thymikee thymikee merged commit c666680 into main Apr 8, 2026
16 checks passed
@thymikee thymikee deleted the codex/fix-dependabot-vite-lodash-es branch April 8, 2026 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant