Skip to content

Conversation

@nerdy-tech-com-gitub
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade @vitejs/plugin-react from 3.1.0 to 5.0.4.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 31 versions ahead of your current version.

  • The recommended version was released a month ago.

⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELHELPERS-9397697
140 Proof of Concept
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
140 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ES5EXT-6095076
140 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
140 Proof of Concept
high severity Access Control Bypass
SNYK-JS-VITE-6182924
140 Proof of Concept
high severity Incorrect Authorization
SNYK-JS-VITE-9512410
140 Mature
high severity Incorrect Authorization
SNYK-JS-VITE-9653016
140 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
140 No Known Exploit
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
140 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-ROLLUP-8073097
140 Proof of Concept
medium severity Improper Access Control
SNYK-JS-VITE-6531286
140 Proof of Concept
medium severity Information Exposure
SNYK-JS-VITE-8023174
140 Proof of Concept
medium severity Origin Validation Error
SNYK-JS-VITE-8648411
140 Proof of Concept
medium severity Access Control Bypass
SNYK-JS-VITE-9576207
140 Proof of Concept
medium severity Information Exposure
SNYK-JS-VITE-9685035
140 Proof of Concept
medium severity Directory Traversal
SNYK-JS-VITE-9919777
140 Proof of Concept
low severity Cross-site Scripting (XSS)
SNYK-JS-VITE-8022916
140 Proof of Concept
Release notes
Package name: @vitejs/plugin-react
  • 5.0.4 - 2025-09-27

    Perf: use native refresh wrapper plugin in rolldown-vite (#881)

  • 5.0.3 - 2025-09-17
  • 5.0.2 - 2025-08-28
  • 5.0.1 - 2025-08-19
  • 5.0.0 - 2025-08-07
  • 5.0.0-beta.0 - 2025-07-28
  • 4.7.0 - 2025-07-18
  • 4.6.0 - 2025-06-23
  • 4.5.2 - 2025-06-10
  • 4.5.1 - 2025-06-03
  • 4.5.0 - 2025-05-23
  • 4.4.1 - 2025-04-19
  • 4.4.0 - 2025-04-15
  • 4.4.0-beta.2 - 2025-04-15
  • 4.4.0-beta.1 - 2025-04-09
  • 4.3.4 - 2024-11-26
  • 4.3.3 - 2024-10-19
  • 4.3.2 - 2024-09-29
  • 4.3.1 - 2024-06-10
  • 4.3.0 - 2024-05-22
  • 4.2.1 - 2023-12-04
  • 4.2.0 - 2023-11-16

    Add @ vitejs/plugin-react-swc/preamble virtual module for SSR HMR (#890)

    SSR applications can now initialize HMR runtime by importing @ vitejs/plugin-react-swc/preamble at the top of their client entry instead of manually calling transformIndexHtml. This simplifies SSR setup for applications that don't use the transformIndexHtml API.

    Use SWC when useAtYourOwnRisk_mutateSwcOptions is provided (#951)

    Previously, this plugin did not use SWC if plugins were not provided even if useAtYourOwnRisk_mutateSwcOptions was provided. This is now fixed.

  • 4.1.1 - 2023-11-02
  • 4.1.0 - 2023-09-24

    Set SWC cacheRoot options

    This is set to {viteCacheDir}/swc and override the default of .swc.

    Perf: simplify refresh wrapper generation (#835)

  • 4.0.4 - 2023-07-31
  • 4.0.3 - 2023-07-10
  • 4.0.2 - 2023-07-06
  • 4.0.1 - 2023-06-19
  • 4.0.0 - 2023-04-20
  • 4.0.0-beta.1 - 2023-04-17
  • 4.0.0-beta.0 - 2023-04-05
  • 3.1.0 - 2023-02-02
from @vitejs/plugin-react GitHub release notes

Important

  • Warning: This PR contains a major version upgrade, and may be a breaking change.
  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade @vitejs/plugin-react from 3.1.0 to 5.0.4. See this package in npm: @vitejs/plugin-react See this project in Snyk: https://app.snyk.io/org/nerds-github/project/ce23e2e3-936d-4fab-b367-2b488f20b092?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants