[Fix] Upgrade Vue to 3.5.0 to resolve peer dependency conflict #4318
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What is the purpose of the pull request
CRITICAL: This PR unblocks distribution of CVE-2025-53960 security fix to Docker users.
The v2.1.7 release contains a fix for CVE-2025-53960 (CVSS 5.9 MEDIUM - JWT HMAC key weakness allowing account takeover), but Docker images were never published due to build failures.
The docker-push workflow has been failing consistently since September 11, 2025, preventing security updates from reaching users who deploy via Docker.
Example failures:
Error from build logs:
Brief change log
vuefrom^3.3.4to^3.5.0@vue/runtime-corefrom^3.2.41to^3.5.0@vue/sharedfrom^3.2.41to^3.5.0@vue/compiler-sfcfrom^3.2.41to^3.5.0Verifying this change
This change is already covered by existing tests:
The fix has been verified on fork with successful CI runs.
Does this pull request potentially affect one of the following parts
Documentation