diff --git a/.tool-versions b/.tool-versions new file mode 100644 index 00000000000000..e8fc3f8ea0e28e --- /dev/null +++ b/.tool-versions @@ -0,0 +1 @@ +nodejs 20.18.1 diff --git a/packages/vite/CHANGELOG.md b/packages/vite/CHANGELOG.md index ccee6ae6416689..f1f228fd260058 100644 --- a/packages/vite/CHANGELOG.md +++ b/packages/vite/CHANGELOG.md @@ -1,3 +1,11 @@ +## 4.5.6 (2025-01-20) + +* fix!: check host header to prevent DNS rebinding attacks and introduce `server.allowedHosts` ([ef1049d](https://github.com/vitejs/vite/commit/ef1049d)) +* fix!: default `server.cors: false` to disallow fetching from untrusted origins ([07b36d5](https://github.com/vitejs/vite/commit/07b36d5)) +* fix: verify token for HMR WebSocket connection ([c065a77](https://github.com/vitejs/vite/commit/c065a77)) + + + ## 4.5.5 (2024-09-16) diff --git a/packages/vite/package.json b/packages/vite/package.json index 25fd90cc100bb8..06935207cd4e9d 100644 --- a/packages/vite/package.json +++ b/packages/vite/package.json @@ -1,6 +1,6 @@ { "name": "vite", - "version": "4.5.5", + "version": "4.5.6", "type": "module", "license": "MIT", "author": "Evan You",