fix!: Rollup build XSS vulnerability (CVE-2024-43788) #759
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR removes Rollup from dependencies, using the exported types from Vite.
This is breaking since we need Vite
4.2.0+
to re-use exported Rollup types included in this PR vitejs/vite#12316 (included in Vite4.2.0-beta.2 (2023-03-13)
).This PR doesn't solve CVE-2024-43788 since
workbox-build
and Vite have the same problem as pointed in the linked issue, the consumer should useoverrides
,resolutions
orpnpm.overrides
to override Rollup version.Once Vite and
workbox-build
fix the vulnerability the PWA plugin should be ready.Linked Issues
closes #758
Additional Context
This PR may or may not work when overriding Rollup 4.22.4:
workbox-build
Tip
The author of this PR can publish a preview release by commenting
/publish
below.