Skip to content

patch: override h3 due to vulnerable version in vinxi#249

Closed
madaxen86 wants to merge 1 commit intosolidjs:mainfrom
madaxen86:patch-override-h3
Closed

patch: override h3 due to vulnerable version in vinxi#249
madaxen86 wants to merge 1 commit intosolidjs:mainfrom
madaxen86:patch-override-h3

Conversation

@madaxen86
Copy link

override the h3 version in package.json

Users face high vulnerability after creating a new solid-start project with the cli.

Reason: h3 vulnerability - GHSA-mp2g-9vg9-f4cg

  • Vinxi pinned the h3 version to the vulnerable 1.5.3
  • Fix is available from 1.5.5

This PR adds an override to all start templates package.json files.

@madaxen86
Copy link
Author

@davedbase please review

@madaxen86 madaxen86 closed this Feb 16, 2026
@madaxen86
Copy link
Author

Vinxi merged a PR with a fixed version of h3.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant