We've published a Browser Mode security advisory.
CDP-capable providers like Playwright Chromium with the browser API exposed to the network allowed attackers to run code on the host.
Update vitest/browser to 5.0.0-beta.4, 4.1.8, or 3.2.6.
Vite+ users: Upgrade to 0.1.24
π¨ We are publishing Vitest 4.1.6 and Vitest 5.0.0-beta.3 to resolve recent vulnerabilities:
- `--api` and `--ui` exposed arbitrary files to the network
- `--api` allowed arbitrary execution
- `?otelCarrier` XSS
More information on our GitHub security page
Vitest 4.1 is out! π
β Vite 8 support from day 1
π·οΈ Test tags to organize, filter & apply shared options
πͺ New hooks for easier tracing, transactions and AsyncLocalStorage
π Async leak detection
π€ Agent reporter to reduce token usage
And much more!
In the next version of Claude Code..
We're introducing two new Skills: /simplify and /batch. I have been using both daily, and am excited to share them with everyone.
Combined, these kills automate much of the work it used to take to (1) shepherd a pull request to production