Sourced from vite's releases.
v4.5.6
This version contains a breaking change due to security fixes. See https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6 for more details.
Please refer to CHANGELOG.md for details.
v4.5.5
Please refer to CHANGELOG.md for details.
v4.5.4
Please refer to CHANGELOG.md for details.
Sourced from vite's changelog.
4.5.6 (2025-01-20)
- fix!: check host header to prevent DNS rebinding attacks and introduce
server.allowedHosts
(ef1049d)- fix!: default
server.cors: false
to disallow fetching from untrusted origins (07b36d5)- fix: verify token for HMR WebSocket connection (c065a77)
4.5.5 (2024-09-16)
4.5.4 (2024-09-16)
9e460f5
release: v4.5.6ef1049d
fix!: check host header to prevent DNS rebinding attacks and introduce
`serve...c065a77
fix: verify token for HMR WebSocket connection07b36d5
fix!: default server.cors: false
to disallow fetching from
untrusted originsf1d8845
release: v4.5.52466c08
release: v4.5.4e812716
fix: avoid DOM Clobbering gadget in
getRelativeUrlFromDocument
(#18115)b901438
fix: backport #18112,
fs raw query