Skip to content

Commit ae82dd2

Browse files
ralyodioclaude
andcommitted
fix(security): upgrade vitest to v3 to patch esbuild CVE; use hello@ sender
- Bump vitest ^2.1.0 → ^3.2.0 everywhere (root, apps/web, shared-types) vitest 3 pulls vite 6 which ships esbuild >=0.25 — fixes the GHSA-67mh-4wv8-2f99 vulnerabilities that were failing npm audit CI - Change default EMAIL_FROM to hello@pairux.com Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 0198fce commit ae82dd2

5 files changed

Lines changed: 311 additions & 29 deletions

File tree

apps/web/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,6 @@
5353
"sharp": "^0.34.5",
5454
"tailwindcss": "^4.0.0",
5555
"typescript": "^5.7.0",
56-
"vitest": "^2.1.0"
56+
"vitest": "^3.2.0"
5757
}
5858
}

apps/web/src/app/actions/email.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ export async function sendBulkEmail(input: {
4848
const resendApiKey = process.env.RESEND_API_KEY;
4949
if (!resendApiKey) return { ok: false, error: 'RESEND_API_KEY is not configured.' };
5050

51-
const defaultFrom = process.env.EMAIL_FROM ?? 'PairUX <noreply@pairux.com>';
51+
const defaultFrom = process.env.EMAIL_FROM ?? 'PairUX <hello@pairux.com>';
5252

5353
// Fetch all user emails via the admin auth API (service role bypasses RLS).
5454
const svc = serviceClient();

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@
5858
"@eslint/js": "^9.17.0",
5959
"@next/eslint-plugin-next": "^15.1.0",
6060
"@types/node": "^22.10.0",
61-
"@vitest/coverage-v8": "^2.1.0",
61+
"@vitest/coverage-v8": "^3.2.0",
6262
"eslint": "^9.17.0",
6363
"eslint-config-prettier": "^9.1.0",
6464
"eslint-plugin-react": "^7.37.0",
@@ -68,7 +68,7 @@
6868
"turbo": "^2.3.0",
6969
"typescript": "^5.7.0",
7070
"typescript-eslint": "^8.18.0",
71-
"vitest": "^2.1.0"
71+
"vitest": "^3.2.0"
7272
},
7373
"repository": {
7474
"type": "git",

packages/shared-types/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,6 @@
3636
},
3737
"devDependencies": {
3838
"typescript": "^5.7.0",
39-
"vitest": "^2.1.0"
39+
"vitest": "^3.2.0"
4040
}
4141
}

0 commit comments

Comments
 (0)