Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(@angular/build): update vite to version 6.0.11 #29471

Merged
merged 1 commit into from
Jan 24, 2025

Conversation

clydin
Copy link
Member

@clydin clydin commented Jan 24, 2025

Version update from 6.0.7 to address advisory GHSA-vg6x-rcgg-rjx6

Vite version 6.0.9+, which is now used by the Angular CLI with the application/browser-esbuild builders, contains a potentially breaking change for some development setups. Examples of such setups include those that use reverse proxies or custom host names during development. The change within a patch release was made by Vite to address a security vulnerability. For projects that directly access the development server via localhost, no changes should be needed. However, some development setups may now need to adjust the allowedHosts development server option. This option can include an array of host names that are allowed to communicate with the development server. The option sets the corresponding Vite option within the Angular CLI. For more information on the option and its specific behavior, please see the Vite documentation located here:
https://vite.dev/config/server-options.html#server-allowedhosts

The following is an example of the configuration option allowing example.com:

"serve": {
      "builder": "@angular-devkit/build-angular:dev-server",
      "options": {
        "allowedHosts": ["example.com"]
      },

@clydin clydin added the target: patch This PR is targeted for the next patch release label Jan 24, 2025
@clydin clydin force-pushed the vite-allowed-hosts-19.1.x branch from 42180fa to c130c77 Compare January 24, 2025 09:44
@clydin clydin added the action: review The PR is still awaiting reviews from at least one requested reviewer label Jan 24, 2025
@clydin clydin requested review from dgp1130 and alan-agius4 January 24, 2025 14:06
Copy link
Collaborator

@alan-agius4 alan-agius4 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just a couple of nits.

Version update from 6.0.7 to address advisory GHSA-vg6x-rcgg-rjx6

Vite version 6.0.9+, which is now used by the Angular CLI with the `application`/`browser-esbuild`
builders, contains a potentially breaking change for some development setups. Examples of such
setups include those that use reverse proxies or custom host names during development.
The change within a patch release was made by Vite to address a security vulnerability.
For projects that directly access the development server via `localhost`, no changes should
be needed. However, some development setups may now need to adjust the
`allowedHosts` development server option. This option can include an array
of host names that are allowed to communicate with the development server. The option
sets the corresponding Vite option within the Angular CLI.
For more information on the option and its specific behavior, please see the Vite
documentation located here:
https://vite.dev/config/server-options.html#server-allowedhosts

The following is an example of the configuration option allowing `example.com`:
```
"serve": {
      "builder": "@angular-devkit/build-angular:dev-server",
      "options": {
        "allowedHosts": ["example.com"]
      },
```
@clydin clydin force-pushed the vite-allowed-hosts-19.1.x branch from c130c77 to f500423 Compare January 24, 2025 14:31
@clydin clydin removed the request for review from dgp1130 January 24, 2025 14:31
@clydin clydin added action: merge The PR is ready for merge by the caretaker and removed action: review The PR is still awaiting reviews from at least one requested reviewer labels Jan 24, 2025
@clydin clydin merged commit 6880199 into angular:19.1.x Jan 24, 2025
30 of 31 checks passed
@clydin clydin deleted the vite-allowed-hosts-19.1.x branch January 24, 2025 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
action: merge The PR is ready for merge by the caretaker area: @angular/build target: patch This PR is targeted for the next patch release
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants