Bump rollup from 3.20.2 to 3.30.0 by dependabot[bot] · Pull Request #12206 · chartjs/Chart.js
Bumps rollup from 3.20.2 to 3.30.0.
Release notes
Sourced from rollup's releases.
v3.30.0
3.30.0
2026-02-22
Features
- Throw when the generated bundle contains paths that would leave the output directory (#6276)
Pull Requests
- #6276: Validate bundle stays within output dir (
@lukastaegert)v3.29.5
3.29.5
2024-09-21
Bug Fixes
- Fix a vulnerability in generated code that affects IIFE, UMD and CJS bundles when run in a browser context (#5671)
Pull Requests
- #5671: Fix DOM Clobbering CVE (
@lukastaegert)
Changelog
Sourced from rollup's changelog.
3.30.0
2026-02-22
Features
- Throw when the generated bundle contains paths that would leave the output directory (#6276)
Pull Requests
- #6276: Validate bundle stays within output dir (
@lukastaegert)3.29.5
2024-09-21
Bug Fixes
- Resolve CVE-2024-43788
3.29.4
2023-09-28
Bug Fixes
- Fix static analysis when an exported function uses callbacks (#5158)
Pull Requests
- #5158: Deoptimize all parameters when losing track of a function (
@lukastaegert)3.29.3
2023-09-24
Bug Fixes
- Fix a bug where code was wrongly tree-shaken after mutating function parameters (#5153)
Pull Requests
- #5145: docs: improve the docs repl appearance in the light mode (
@TrickyPi)- #5148: chore(deps): update dependency
@vue/eslint-config-typescriptto v12 (@renovate[bot])- #5149: chore(deps): lock file maintenance minor/patch updates (
@renovate[bot])- #5153: Fully deoptimize first level path when deoptimizing nested parameter paths (
@lukastaegert)3.29.2
2023-09-15
... (truncated)
Commits
d91d5e13.30.09677409Update release script for backportsc8cf1f9Validate bundle stays within output dir (#6276)dfd233d3.29.52ef77c0Fix DOM Clobbering CVEa6448b93.29.44e92d60Deoptimize all parameters when losing track of a function (#5158)801ffd13.29.3353e462Fully deoptimize first level path when deoptimizing nested parameter paths (#...a1a89e7chore(deps): update dependency@vue/eslint-config-typescriptto v12 (#5148)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.