Skip to content

build(deps-dev): upgrade vitest to v5 - #410

Merged
MarshallOfSound merged 1 commit into
mainfrom
vitest-5
Sep 23, 2026
Merged

MarshallOfSound merged 1 commit into
mainfrom
vitest-5

Conversation

@claude

@claude claude Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Requested by David Sanders · Slack thread

This bumps vitest and @vitest/coverage-v8 to ^5.0.1. That also fixes the existing peer mismatch between coverage-v8 4.1.2 and vitest 4.1.11. Vitest 5 lists vite as a required peer instead of a dependency, so I added vite as a devDependency at ^8.0.16, the version already in the lockfile. No test or config changes were needed. Lint, build and build:docs pass locally. 86 tests pass, the same as main. The 5 tests that fetch from github.com (FetchDownloader.network.spec.ts and one downloadArtifact() test in index.spec.ts) couldn't reach GitHub from my environment on either branch. I checked separately that Vitest 5 still serializes HTTPError in the format their inline snapshot expects.

🤖 Generated with Claude Code

https://claude.ai/code/session_01N2vvE5XzurMvQfsX7Vz7bF


Generated by Claude Code

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N2vvE5XzurMvQfsX7Vz7bF
@claude
claude Bot requested a review from a team as a code owner September 23, 2026 21:34
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​vitest/​coverage-v8@​4.1.2 ⏵ 5.0.19910079 +198 -1100
Updatedvitest@​4.1.11 ⏵ 5.0.198 +110079 +198100
Addedvite@​8.0.16991008296100

View full report

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, straightforward dependency bump.

What was reviewed: package.json devDependency changes (vitest and @ vitest/coverage-v8 to ^5.0.1, new vite ^8.0.16) and the corresponding yarn.lock regeneration. Confirmed the lockfile entries resolve to matching versions (5.0.1 / 8.0.16) with consistent peer dependency declarations. No application source under src/ or test/ is touched, and no security-sensitive surface is involved.

Extended reasoning...

This is a devDependency-only version bump (vitest/@ vitest/coverage-v8 to ^5.0.1, plus new explicit vite ^8.0.16 devDependency) with a regenerated yarn.lock; no source or test files changed. Verified the lockfile entries for vitest, @ vitest/coverage-v8, and vite resolve consistently at the stated versions with matching peer dependency metadata. The bug hunter reported no findings, the change is small and mechanical, and it touches no auth/crypto/permissions code, so this qualifies for approval without requiring human review.

@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) September 23, 2026 23:13
@MarshallOfSound
MarshallOfSound merged commit 0dbfc3a into main Sep 23, 2026
11 checks passed
@MarshallOfSound
MarshallOfSound deleted the vitest-5 branch September 23, 2026 23:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants