Repository navigation
chore(deps): update vitest monorepo to v5 - #8320
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
from
July 9, 2026 07:40
423ab5b to
7dab8a9
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
2 times, most recently
from
July 20, 2026 15:51
8e22bdb to
8b4825a
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
from
July 24, 2026 14:46
8b4825a to
72d1cb5
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
from
July 27, 2026 17:34
72d1cb5 to
93a7b84
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
from
July 30, 2026 15:23
93a7b84 to
a277bed
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
2 times, most recently
from
August 14, 2026 23:25
01e4699 to
859a0e7
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
2 times, most recently
from
August 26, 2026 12:08
0d2b6ec to
b569c66
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
4 times, most recently
from
September 3, 2026 15:51
7e77604 to
2ad747a
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
from
September 6, 2026 15:07
2ad747a to
0c16cc8
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
2 times, most recently
from
September 8, 2026 21:48
60ec148 to
55e947c
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
2 times, most recently
from
September 10, 2026 15:19
6277388 to
b5e3cff
Compare
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
2 times, most recently
from
September 18, 2026 22:57
dd35e1a to
bf39ac1
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
3 times, most recently
from
October 1, 2026 07:41
8143e8b to
9037c44
Compare
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
2 times, most recently
from
October 5, 2026 16:03
a7216cc to
9a21d22
Compare
sarahetter
added a commit
that referenced
this pull request
Oct 6, 2026
Opened by Netliloop run [#392](https://netliloop.netlify.app/#/runs/392) (security-scan), asked in [Slack](https://slack.com/archives/C095D1JL480/p1791299459766719?thread_ts=1791298825.895999&cid=C095D1JL480) ### Why - `vitest@3.2.7` carries [GHSA-82fw-gwwq-j7x9](GHSA-82fw-gwwq-j7x9) (`@vitest/mocker` path traversal, patched in 4.1.11). Renovate's [#8289](#8289) and [#8320](#8320) target it but their lockfiles no longer resolve against `main` (`npm ci` fails on every rebase), and Dependabot's [#8570](#8570) jumps to vitest 5 and fails typecheck, lint and 12 unit tests. - `oxfmt@0.61.0` pins `tinypool@2.1.0`, which carries the critical [GHSA-85c8-ppgw-ccpr](GHSA-85c8-ppgw-ccpr); the only way past it is an oxfmt version that pins `tinypool >= 2.1.2`. - `npm audit` on `main` lists `vitest`, `@vitest/mocker`, `@vitest/coverage-v8` and `tinypool`; on this branch none of them appear. ### What changed - `vitest` and `@vitest/coverage-v8` go to `^4.1.11`, the first patched release (vitest 5 is a week old). - `oxfmt` goes to `0.72.0`, which pins `tinypool@2.2.0`; running it reformats two files under `src/commands/logs/sources/`. - vitest 4 removed `poolOptions`, so `threads.singleThread: true` becomes `maxWorkers: 1` in both configs: still one worker thread, one file at a time. This is not a byte-for-byte port. The migration guide's equivalent adds `isolate: false`, but in vitest 4 that shares module mocks across files and fails 38 unit tests here, so file isolation stays on and the comment in each config says why. Each file now gets a fresh worker; the Windows-hang TODO beside the pin still applies and CI's Windows jobs on this PR are the check. - Transitively, vitest now carries its own nested Vite 8.3.3 (rolldown) instead of the top-level Vite 7.3.5, so test-file transforms change engine. - Coverage reports change shape (vitest 4 drops `coverage.all` and uses AST remapping), so the Codecov numbers on this PR will move; that is the tooling, not a regression. - vitest 4 constructs mocks called with `new`, so the `NetlifyAPI` and `LocalState` mock implementations in three test files become `function` expressions instead of arrow functions. - `toThrowError` is marked `@deprecated` ("Alias for `expect.toThrow`") in `@vitest/expect` 4 and so flagged by `@typescript-eslint/no-deprecated`; 38 call sites in `tests/` switch to `toThrow` with the same arguments. - Supersedes #8289, #8320 and #8570, which can be closed when this merges. ### How we verified - `npm ci --dry-run`: the committed lockfile is in sync with `package.json` (Renovate's #8289 and #8320 fail exactly here). - `npm run build`, `npm run typecheck`, `npm run lint`, `npm run format:check`: all exit 0. - `CI=true npm run test:unit -- --coverage`: 80 files, 667 tests passed, the same counts as `CI=true npm run test:unit` on `main`. With the migration guide's `isolate: false` the same command fails 38 tests in 9 files (leaked module mocks), which is why isolation stays on. - `CI=true npx vitest run --retry=3 --coverage tests/integration/commands/env/env.test.ts tests/integration/commands/dev/dev-forms-and-redirects.test.ts`: 2 files, 32 tests passed, so `--retry`, `--coverage` and the integration harness work on vitest 4 - `CI=true npm run test:integration -- --shard=1/4` here: 24 failures in 6 files, and the same 6 files fail with the same 24 tests on `main` under vitest 3 (this machine has a linked Netlify site and no git identity, which `build`, `clone` and `link` tests depend on); the full set is CI's 8 green shards. - `npx vitest list --config vitest.e2e.config.ts`: the e2e config loads and lists 5 tests. - `CI=true npx vitest run --config vitest.e2e.config.ts -t "npm →"` runs through verdaccio publish, `npm install`, `netlify --help` and `netlify link` on vitest 4 and fails at the `netlify unlink` assertion (`expected ... to contain 'Run netlify link to link it'`). The identical run on `main` with vitest 3 fails at the same line: this machine has a globally linked Netlify site (`main` received `Unlinked from netliloop`) and, once unlinked, the CLI running under `npx` phrases the hint as `Run npx netlify link` (the branch received that). The failure is the environment, not the upgrade; the e2e suite is unverified here. - `npm audit --json`: on `main` it lists `vitest` (critical, range 0.0.95 - 4.1.10), `@vitest/mocker`, `@vitest/coverage-v8` and `tinypool <=2.1.1`; on this branch none of the four appear and `npm ls tinypool` shows only `oxfmt@0.72.0 → tinypool@2.2.0`. 39 advisories remain, unchanged from `main`; the two critical ones are `proxy-addr` (Dependabot's #8567 fixes it) and `shell-quote`. ### What is left to test - The full integration suite, the e2e suite, and unit/integration on macOS and Windows (where the single-thread pin matters most) could not run here; on this PR CI ran them and all 34 checks are green (unit on ubuntu/macOS/Windows, 8 integration shards, e2e, lint, format, typecheck, verify-docs, package-size). ### Risk `low`: development tooling only; nothing in `dist/` or the published package changes except the two reformatted files, whose formatting-only diff is in the branch. No Linear issue: a self-contained dependency fix the CLI team can merge from this description. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Netliloop <netliloop@netlify.com> Co-authored-by: Sarah Etter <sarah.etter@netlify.com>
renovate
Bot
force-pushed
the
renovate/major-vitest-monorepo
branch
from
October 6, 2026 16:56
9a21d22 to
8833c1d
Compare
commit: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.1.11→^5.0.0^4.1.11→^5.0.0Release Notes
vitest-dev/vitest (@vitest/coverage-v8)
v5.0.3Compare Source
🐞 Bug Fixes
result.statusbetweenrepeatsruns - by @hi-ogawa, Hiroshi Ogawa and Codex (GPT-6) in #11218 (5dbeb)test.failsexpectedly failed - by @hi-ogawa, Hiroshi Ogawa and Codex (GPT-6) in #11219 (b2458)listenuntil tests start running - by @sheremet-va in #11366 (7d8ed)toMatchScreenshotuses wrong reference on retried tests - by @macarie in #11393 (c22ab)why-is-node-runningto3.2.1to avoid users running intoERR_PNPM_TRUST_DOWNGRADE- by @AriPerkkio in #11403 (f6c9a)expect.extendasymmetric matchers - by @hi-ogawa, Hiroshi Ogawa and Claude in #11401 (3e794)groupOrderis set - by @mtorp in #11392 (50312)View changes on GitHub
v5.0.2Compare Source
🐞 Bug Fixes
processin case global is overwritten - by @AriPerkkio in #11343 (0b792)process.stdiohandles - by @AriPerkkio in #11333 (0fd6b)toMatchObjectwith asymmetric matchers - by @ShreeBohara, Claude Opus 5, @hi-ogawa, Hiroshi Ogawa and Codex (GPT-5) in #11100 (42523)RequestwithBlobbody on jsdom 28+ - by @harshit-d3v in #11295 (d1c3e)agentto respect--silent- by @Raj4478 and @AriPerkkio in #11271 (5b95e)createReportcalls - by @7rulnik in #11278 (e8e55)hanging-processto use ESM entrypoint - by @AriPerkkio in #11316 (4e91e)Set.prototype.add- by @fengmk2 in #11299 (a0a93)View changes on GitHub
v5.0.1Compare Source
🚀 Features
🐞 Bug Fixes
extends- by @sheremet-va in #11034 (23dda)deps.optimizer.webis used - by @im10furry in #11214 (2ce29)config.define- by @sheremet-va in #11198 (972e2)toMatchAriaSnapshot- by @sheremet-va in #11208 (c119b)queueMicrotaskandnextTickintoNotFake- by @kingmakeruix, kingmakeruix, Hiroshi Ogawa, Codex and @hi-ogawa in #11261 (a47d7)deepMergeto handle prototype - by @hi-ogawa, Hiroshi Ogawa and Codex in #11215 (4944c)View changes on GitHub
v5.0.0Compare Source
Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.
🚨 Breaking Changes
loupe.inspectwith pretty-format - by @hi-ogawa, Claude Opus 5 (1M context) and OpenAI Codex in #9609 (3f802)test.for/eachtitle$variable (take 2) - by @hi-ogawa in #10170 (04d37)attachmentsDirfrom.vitest-attachements/to.vitest/attachments/- by @MdSadiqMd in #10186 (1ba73)sequentialtest/suite options in favor ofconcurrent- by @hi-ogawa and OpenAI Codex in #10198 (9229f)expectpackage - by @sheremet-va in #10221 (ad162)expect.pollwhen function didn't resolve in time - by @hi-ogawa and OpenAI Codex in #10233 (4df04)toHaveTextContentis strict, addtoMatchTextContentas alternative - by @sheremet-va in #10473 (18f30)@vitest/runnerpackage, do not publish it anymore - by @sheremet-va in #10511 (6d6e4)concurrencyId/workerIdon TestModule's diagnostics, make id 1-based - by @sheremet-va in #10516 (bdd98)screenshotDirectoryconfig tobrowser.expect.toMatchScreenshot- by @macarie in #10592 (a60de)@sinonjs/fake-timersand support mockingTemporal- by @hi-ogawa, Hiroshi Ogawa and OpenCode (gpt-5.6-sol) in #10654 (f8b15)>as separator in-t, calculateonlyonce - by @sheremet-va in #10686 (a0b20)locators.exactby default - by @sheremet-va in #10430 (e2032)sessionIdfor orchestrator html request - by @hi-ogawa, Hiroshi Ogawa and OpenAI Codex in #10522 (79b7d)attachmentsDir- by @macarie in #10917 (3b5bb)include/excludeglobs too eager - by @AriPerkkio in #9818 (edacb)thresholds.perFileto accept an object - by @vladlenskiy and @AriPerkkio in #10190 (13b78)toThrow("")behavior by reverting #6710 - by @hi-ogawa in #9643 and #6710 (6c3e4)blobreporter and--merge-reportsdefault to.vitest/blob/- by @AriPerkkio in #10232 (d22b0).vitestby default - by @hi-ogawa, Hiroshi Ogawa, OpenCode (gpt-5.6-sol) and @AriPerkkio in #10621 (58577).vitest- by @hi-ogawa and Hiroshi Ogawa in #10620 (29c36)🚀 Features
createReportand.vitestreport directory convention - by @AriPerkkio in #9993 (72a6d)configDefaults.reporters- by @hi-ogawa and Claude Opus 5 (1M context) in #10219 (083f6)logger.formatError- by @hi-ogawa and OpenAI Codex in #10268 (2c5f3)injectCjsGlobalsoption - by @sheremet-va in #10709 (82671)for/eachtitle placeholders - by @k-yle in #10773 (15e0a)ToMatchScreenshotResolvePath- by @macarie and @sheremet-va in #10138 (16654)kindinpage.mark- by @AriPerkkio in #10302 (053e8)context.markfor custom command tracing - by @AriPerkkio in #10329 (aa514)--repeatsCLI option - by @todor-a in #10504 (ee48b)node:child_processandnode:worker_threadscontexts - by @AriPerkkio in #9976 (9baa5)thresholds.autoUpdateto receive previous threshold as argument - by @wouterkroes in #10495 (04f81)@vitest/istanbuljspackages - by @AriPerkkio in #11053 (5f6a5)vi.when()- by @macarie in #10174 (3900e)require(esm)in vm pools - by @sheremet-va in #10829 (01298)🐞 Bug Fixes
sequence.concurrent: truewith top-leveltest(..., { concurrent: false })+ depreactesequentialtest API and options - by @hi-ogawa, OpenAI Codex and @sheremet-va in #10194 (9387f)tagsoptions should overwrite inherited suite options + inherit suite options intaskAPI - by @hi-ogawa and OpenAI Codex in #10216 (457db)attachmentsDirroot only config - by @hi-ogawa and OpenAI Codex in #10334 (fab1b)__esModule- by @hi-ogawa in #10363 (2b135)vi.defineHelpercallsite for async error stack - by @macayu17 and @hi-ogawa in #10415 (ac697)disableConsoleInterceptin browser mode - by @Copilot, Hiroshi Ogawa, @hi-ogawa and OpenAI Codex in #10391 (66110)onUserConsoleLog- by @Copilot, Hiroshi Ogawa, @hi-ogawa and @sheremet-va in #10308 (62756)importOriginalwith optimizer and query import - by @davidxharris, David Harris, @hi-ogawa, Hiroshi Ogawa and OpenAI Codex in #10469 (6a3bb)setImmediateawait in detect-async-leak - by @hi-ogawa and Hiroshi Ogawa in #10608 (dd62b)sequenceconfig - by @hi-ogawa, Hiroshi Ogawa and OpenCode (gpt-5.6-sol) in #10659 (40cdc)includeTaskLocationis enabled - by @sheremet-va in #10681 (bd9cc)off- by @sheremet-va in #10741 (d758b)ci.yml- by @hirehamir in #10759 (2127f)vitest --typecheckfrom reporting a false success when thetscprocess crashes - by @hitenkalda and Hiten Kalda in #10705 (a1b05)process.exitdisabled in workers - by @sheremet-va in #10963 (5e69a)recordArtifactlocation withvi.defineHelper- by @hi-ogawa, Hiroshi Ogawa and OpenCode (gpt-5.6-sol) in #11047 (c2186)oxc.targetif user provides a custom array - by @sheremet-va in #11095 (848d7)extends: true- by @sheremet-va in #11120 (584cf)Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.