Sourced from vite's releases.
v5.4.14
Please refer to CHANGELOG.md for details.
v5.4.13
Please refer to CHANGELOG.md for details.
v5.4.12
This version contains a breaking change due to security fixes. See https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6 for more details.
Please refer to CHANGELOG.md for details.
Sourced from vite's changelog.
5.4.14 (2025-01-21)
- fix:
preview.allowedHosts
with specific values was not respected (#19246) (9df6e6b), closes #19246- fix: allow CORS from loopback addresses by default (#19249) (7d1699c), closes #19249
5.4.13 (2025-01-20)
5.4.12 (2025-01-20)
e7eb3c5
release: v5.4.147d1699c
fix: allow CORS from loopback addresses by default (#19249)9df6e6b
fix: preview.allowedHosts
with specific values was not
respected (#19246)a1824c5
release: v5.4.135946215
fix: try parse server.origin
URL (#19241)f428aa9
release: v5.4.129da4abc
fix!: check host header to prevent DNS rebinding attacks and introduce
`serve...b71a5c8
fix: verify token for HMR WebSocket connectiondfea38f
fix!: default server.cors: false
to disallow fetching from
untrusted originsecd2375
chore: add deps update changelog