Skip to content

chore(deps): update vitest monorepo to v5 - #8320

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-vitest-monorepo
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-vitest-monorepo

Conversation

@renovate

@renovate renovate Bot commented Jun 18, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@vitest/coverage-v8 (source) ^4.1.11 → ^5.0.0 age confidence
vitest (source) ^4.1.11 → ^5.0.0 age confidence

Release Notes

vitest-dev/vitest (@​vitest/coverage-v8)

v5.0.3

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v5.0.2

Compare Source

   🐞 Bug Fixes
    View changes on GitHub

v5.0.1

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v5.0.0

Compare Source

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes
   🚀 Features
   🐞 Bug Fixes

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner June 18, 2026 23:07
@renovate renovate Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jun 18, 2026
kodiakhq[bot]
kodiakhq Bot previously approved these changes Jun 18, 2026
@renovate renovate Bot changed the title chore(deps): update vitest monorepo to v4 chore(deps): update vitest monorepo (major) Jun 22, 2026
@renovate renovate Bot changed the title chore(deps): update vitest monorepo (major) chore(deps): update dependency @vitest/coverage-v8 to v4 Jun 25, 2026
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 423ab5b to 7dab8a9 Compare July 9, 2026 07:40
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 2 times, most recently from 8e22bdb to 8b4825a Compare July 20, 2026 15:51
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 8b4825a to 72d1cb5 Compare July 24, 2026 14:46
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 72d1cb5 to 93a7b84 Compare July 27, 2026 17:34
@renovate renovate Bot changed the title chore(deps): update dependency @vitest/coverage-v8 to v4 chore(deps): update vitest monorepo to v4 Jul 27, 2026
kodiakhq[bot]
kodiakhq Bot previously approved these changes Jul 27, 2026
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 93a7b84 to a277bed Compare July 30, 2026 15:23
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 2 times, most recently from 01e4699 to 859a0e7 Compare August 14, 2026 23:25
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 2 times, most recently from 0d2b6ec to b569c66 Compare August 26, 2026 12:08
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 4 times, most recently from 7e77604 to 2ad747a Compare September 3, 2026 15:51
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 2ad747a to 0c16cc8 Compare September 6, 2026 15:07
@renovate renovate Bot changed the title chore(deps): update vitest monorepo to v4 chore(deps): update vitest monorepo to v5 Sep 6, 2026
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 2 times, most recently from 60ec148 to 55e947c Compare September 8, 2026 21:48
@renovate renovate Bot changed the title chore(deps): update vitest monorepo to v5 chore(deps): update dependency @vitest/coverage-v8 to v5 Sep 8, 2026
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 2 times, most recently from 6277388 to b5e3cff Compare September 10, 2026 15:19
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 84fb3784-0e3d-442f-94eb-51f2582d6ed6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 2 times, most recently from dd35e1a to bf39ac1 Compare September 18, 2026 22:57
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 3 times, most recently from 8143e8b to 9037c44 Compare October 1, 2026 07:41
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch 2 times, most recently from a7216cc to 9a21d22 Compare October 5, 2026 16:03
sarahetter added a commit that referenced this pull request Oct 6, 2026
Opened by Netliloop run [#392](https://netliloop.netlify.app/#/runs/392)
(security-scan), asked in
[Slack](https://slack.com/archives/C095D1JL480/p1791299459766719?thread_ts=1791298825.895999&cid=C095D1JL480)

### Why

- `vitest@3.2.7` carries
[GHSA-82fw-gwwq-j7x9](GHSA-82fw-gwwq-j7x9)
(`@vitest/mocker` path traversal, patched in 4.1.11). Renovate's
[#8289](#8289) and
[#8320](#8320) target it but their
lockfiles no longer resolve against `main` (`npm ci` fails on every
rebase), and Dependabot's
[#8570](#8570) jumps to vitest 5 and
fails typecheck, lint and 12 unit tests.
- `oxfmt@0.61.0` pins `tinypool@2.1.0`, which carries the critical
[GHSA-85c8-ppgw-ccpr](GHSA-85c8-ppgw-ccpr);
the only way past it is an oxfmt version that pins `tinypool >= 2.1.2`.
- `npm audit` on `main` lists `vitest`, `@vitest/mocker`,
`@vitest/coverage-v8` and `tinypool`; on this branch none of them
appear.

### What changed

- `vitest` and `@vitest/coverage-v8` go to `^4.1.11`, the first patched
release (vitest 5 is a week old).
- `oxfmt` goes to `0.72.0`, which pins `tinypool@2.2.0`; running it
reformats two files under `src/commands/logs/sources/`.
- vitest 4 removed `poolOptions`, so `threads.singleThread: true`
becomes `maxWorkers: 1` in both configs: still one worker thread, one
file at a time. This is not a byte-for-byte port. The migration guide's
equivalent adds `isolate: false`, but in vitest 4 that shares module
mocks across files and fails 38 unit tests here, so file isolation stays
on and the comment in each config says why. Each file now gets a fresh
worker; the Windows-hang TODO beside the pin still applies and CI's
Windows jobs on this PR are the check.
- Transitively, vitest now carries its own nested Vite 8.3.3 (rolldown)
instead of the top-level Vite 7.3.5, so test-file transforms change
engine.
- Coverage reports change shape (vitest 4 drops `coverage.all` and uses
AST remapping), so the Codecov numbers on this PR will move; that is the
tooling, not a regression.
- vitest 4 constructs mocks called with `new`, so the `NetlifyAPI` and
`LocalState` mock implementations in three test files become `function`
expressions instead of arrow functions.
- `toThrowError` is marked `@deprecated` ("Alias for `expect.toThrow`")
in `@vitest/expect` 4 and so flagged by
`@typescript-eslint/no-deprecated`; 38 call sites in `tests/` switch to
`toThrow` with the same arguments.
- Supersedes #8289, #8320 and #8570, which can be closed when this
merges.

### How we verified

- `npm ci --dry-run`: the committed lockfile is in sync with
`package.json` (Renovate's #8289 and #8320 fail exactly here).
- `npm run build`, `npm run typecheck`, `npm run lint`, `npm run
format:check`: all exit 0.
- `CI=true npm run test:unit -- --coverage`: 80 files, 667 tests passed,
the same counts as `CI=true npm run test:unit` on `main`. With the
migration guide's `isolate: false` the same command fails 38 tests in 9
files (leaked module mocks), which is why isolation stays on.
- `CI=true npx vitest run --retry=3 --coverage
tests/integration/commands/env/env.test.ts
tests/integration/commands/dev/dev-forms-and-redirects.test.ts`: 2
files, 32 tests passed, so `--retry`, `--coverage` and the integration
harness work on vitest 4
- `CI=true npm run test:integration -- --shard=1/4` here: 24 failures in
6 files, and the same 6 files fail with the same 24 tests on `main`
under vitest 3 (this machine has a linked Netlify site and no git
identity, which `build`, `clone` and `link` tests depend on); the full
set is CI's 8 green shards.
- `npx vitest list --config vitest.e2e.config.ts`: the e2e config loads
and lists 5 tests.
- `CI=true npx vitest run --config vitest.e2e.config.ts -t "npm →"` runs
through verdaccio publish, `npm install`, `netlify --help` and `netlify
link` on vitest 4 and fails at the `netlify unlink` assertion (`expected
... to contain 'Run netlify link to link it'`). The identical run on
`main` with vitest 3 fails at the same line: this machine has a globally
linked Netlify site (`main` received `Unlinked from netliloop`) and,
once unlinked, the CLI running under `npx` phrases the hint as `Run npx
netlify link` (the branch received that). The failure is the
environment, not the upgrade; the e2e suite is unverified here.
- `npm audit --json`: on `main` it lists `vitest` (critical, range
0.0.95 - 4.1.10), `@vitest/mocker`, `@vitest/coverage-v8` and `tinypool
<=2.1.1`; on this branch none of the four appear and `npm ls tinypool`
shows only `oxfmt@0.72.0 → tinypool@2.2.0`. 39 advisories remain,
unchanged from `main`; the two critical ones are `proxy-addr`
(Dependabot's #8567 fixes it) and `shell-quote`.

### What is left to test

- The full integration suite, the e2e suite, and unit/integration on
macOS and Windows (where the single-thread pin matters most) could not
run here; on this PR CI ran them and all 34 checks are green (unit on
ubuntu/macOS/Windows, 8 integration shards, e2e, lint, format,
typecheck, verify-docs, package-size).

### Risk

`low`: development tooling only; nothing in `dist/` or the published
package changes except the two reformatted files, whose formatting-only
diff is in the branch. No Linear issue: a self-contained dependency fix
the CLI team can merge from this description.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Netliloop <netliloop@netlify.com>
Co-authored-by: Sarah Etter <sarah.etter@netlify.com>
@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 9a21d22 to 8833c1d Compare October 6, 2026 16:56
@renovate renovate Bot changed the title chore(deps): update dependency @vitest/coverage-v8 to v5 chore(deps): update vitest monorepo to v5 Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

📊 Benchmark results

Comparing with 96c9a93

  • Dependency count: 1,014 (no change)
  • Package size: 372 MB ⬆️ 0.00% increase vs. 96c9a93
  • Number of ts-expect-error directives: 331 (no change)

@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/netlify-cli@8320

commit: 8833c1d

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants