Skip to content

fix: bump modern.js to v2.68.0 to fix esbuild vulnerability#3880

Merged
2heal1 merged 2 commits intomodule-federation:mainfrom
Julien-Marcou:fix-modernjs-security-issue
Jul 15, 2025
Merged

fix: bump modern.js to v2.68.0 to fix esbuild vulnerability#3880
2heal1 merged 2 commits intomodule-federation:mainfrom
Julien-Marcou:fix-modernjs-security-issue

Conversation

@Julien-Marcou
Copy link
Copy Markdown
Contributor

Description

Bump modern.js to fix esbuild vulnerability

Related Issue

Closes #3719

Types of changes

  • Docs change / refactoring / dependency upgrade
  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)

Checklist

  • I have added tests to cover my changes.
  • All new and existing tests passed.
  • I have updated the documentation.

@changeset-bot
Copy link
Copy Markdown

changeset-bot bot commented Jul 3, 2025

🦋 Changeset detected

Latest commit: 95e1076

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 33 packages
Name Type
create-module-federation Patch
@module-federation/devtools Patch
@module-federation/modern-js Patch
@module-federation/modernjsapp Patch
@module-federation/cli Patch
@module-federation/enhanced Patch
@module-federation/nextjs-mf Patch
@module-federation/node Patch
@module-federation/rsbuild-plugin Patch
@module-federation/rspress-plugin Patch
@module-federation/storybook-addon Patch
remote5 Patch
website-new Patch
@module-federation/runtime Patch
@module-federation/rspack Patch
@module-federation/webpack-bundler-runtime Patch
@module-federation/sdk Patch
@module-federation/runtime-tools Patch
@module-federation/managers Patch
@module-federation/manifest Patch
@module-federation/dts-plugin Patch
@module-federation/third-party-dts-extractor Patch
@module-federation/bridge-react Patch
@module-federation/bridge-vue3 Patch
@module-federation/bridge-shared Patch
@module-federation/bridge-react-webpack-plugin Patch
@module-federation/retry-plugin Patch
@module-federation/data-prefetch Patch
@module-federation/error-codes Patch
@module-federation/inject-external-runtime-core-plugin Patch
@module-federation/runtime-core Patch
@module-federation/esbuild Patch
@module-federation/utilities Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@netlify
Copy link
Copy Markdown

netlify bot commented Jul 3, 2025

Deploy Preview for module-federation-docs ready!

Name Link
🔨 Latest commit 95e1076
🔍 Latest deploy log https://app.netlify.com/projects/module-federation-docs/deploys/6875f2ad2817120008b252b8
😎 Deploy Preview https://deploy-preview-3880--module-federation-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@cjz9032
Copy link
Copy Markdown

cjz9032 commented Jul 4, 2025

Curious why Dependabot is not introduced to the upgrading process.

@Julien-Marcou
Copy link
Copy Markdown
Contributor Author

Hello @2heal1 @ScriptedAlchemy,

I can see you are actively maintaining this repo, so I was wondering if you could review my PR so we could move forward with it

@2heal1 2heal1 merged commit e0ceca6 into module-federation:main Jul 15, 2025
6 checks passed
@Julien-Marcou Julien-Marcou deleted the fix-modernjs-security-issue branch July 15, 2025 08:33
@2heal1 2heal1 mentioned this pull request Jul 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vulnerable esbuild version (<=0.24.2) introduced via @modern-js/node-bundle-require

3 participants