Repository navigation
build(deps): bump tinypool, @vitest/coverage-v8, vitest and oxfmt - #8570
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
commit: |
Bumps [tinypool](https://github.com/tinylibs/tinypool) to 2.2.0 and updates ancestor dependencies [tinypool](https://github.com/tinylibs/tinypool), [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8), [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) and [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt). These dependencies need to be updated together. Updates `tinypool` from 1.1.1 to 2.2.0 - [Release notes](https://github.com/tinylibs/tinypool/releases) - [Commits](tinylibs/tinypool@v1.1.1...v2.2.0) Updates `@vitest/coverage-v8` from 3.2.7 to 5.0.3 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8) Updates `vitest` from 3.2.7 to 5.0.3 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest) Updates `oxfmt` from 0.61.0 to 0.72.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.72.0/npm/oxfmt) --- updated-dependencies: - dependency-name: "@vitest/coverage-v8" dependency-version: 5.0.3 dependency-type: direct:development - dependency-name: oxfmt dependency-version: 0.72.0 dependency-type: direct:development - dependency-name: tinypool dependency-version: 2.2.0 dependency-type: indirect - dependency-name: vitest dependency-version: 5.0.3 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/multi-e26da46fb2
branch
from
October 6, 2026 16:23
d0860f6 to
0ef00b8
Compare
sarahetter
added a commit
that referenced
this pull request
Oct 6, 2026
Opened by Netliloop run [#392](https://netliloop.netlify.app/#/runs/392) (security-scan), asked in [Slack](https://slack.com/archives/C095D1JL480/p1791299459766719?thread_ts=1791298825.895999&cid=C095D1JL480) ### Why - `vitest@3.2.7` carries [GHSA-82fw-gwwq-j7x9](GHSA-82fw-gwwq-j7x9) (`@vitest/mocker` path traversal, patched in 4.1.11). Renovate's [#8289](#8289) and [#8320](#8320) target it but their lockfiles no longer resolve against `main` (`npm ci` fails on every rebase), and Dependabot's [#8570](#8570) jumps to vitest 5 and fails typecheck, lint and 12 unit tests. - `oxfmt@0.61.0` pins `tinypool@2.1.0`, which carries the critical [GHSA-85c8-ppgw-ccpr](GHSA-85c8-ppgw-ccpr); the only way past it is an oxfmt version that pins `tinypool >= 2.1.2`. - `npm audit` on `main` lists `vitest`, `@vitest/mocker`, `@vitest/coverage-v8` and `tinypool`; on this branch none of them appear. ### What changed - `vitest` and `@vitest/coverage-v8` go to `^4.1.11`, the first patched release (vitest 5 is a week old). - `oxfmt` goes to `0.72.0`, which pins `tinypool@2.2.0`; running it reformats two files under `src/commands/logs/sources/`. - vitest 4 removed `poolOptions`, so `threads.singleThread: true` becomes `maxWorkers: 1` in both configs: still one worker thread, one file at a time. This is not a byte-for-byte port. The migration guide's equivalent adds `isolate: false`, but in vitest 4 that shares module mocks across files and fails 38 unit tests here, so file isolation stays on and the comment in each config says why. Each file now gets a fresh worker; the Windows-hang TODO beside the pin still applies and CI's Windows jobs on this PR are the check. - Transitively, vitest now carries its own nested Vite 8.3.3 (rolldown) instead of the top-level Vite 7.3.5, so test-file transforms change engine. - Coverage reports change shape (vitest 4 drops `coverage.all` and uses AST remapping), so the Codecov numbers on this PR will move; that is the tooling, not a regression. - vitest 4 constructs mocks called with `new`, so the `NetlifyAPI` and `LocalState` mock implementations in three test files become `function` expressions instead of arrow functions. - `toThrowError` is marked `@deprecated` ("Alias for `expect.toThrow`") in `@vitest/expect` 4 and so flagged by `@typescript-eslint/no-deprecated`; 38 call sites in `tests/` switch to `toThrow` with the same arguments. - Supersedes #8289, #8320 and #8570, which can be closed when this merges. ### How we verified - `npm ci --dry-run`: the committed lockfile is in sync with `package.json` (Renovate's #8289 and #8320 fail exactly here). - `npm run build`, `npm run typecheck`, `npm run lint`, `npm run format:check`: all exit 0. - `CI=true npm run test:unit -- --coverage`: 80 files, 667 tests passed, the same counts as `CI=true npm run test:unit` on `main`. With the migration guide's `isolate: false` the same command fails 38 tests in 9 files (leaked module mocks), which is why isolation stays on. - `CI=true npx vitest run --retry=3 --coverage tests/integration/commands/env/env.test.ts tests/integration/commands/dev/dev-forms-and-redirects.test.ts`: 2 files, 32 tests passed, so `--retry`, `--coverage` and the integration harness work on vitest 4 - `CI=true npm run test:integration -- --shard=1/4` here: 24 failures in 6 files, and the same 6 files fail with the same 24 tests on `main` under vitest 3 (this machine has a linked Netlify site and no git identity, which `build`, `clone` and `link` tests depend on); the full set is CI's 8 green shards. - `npx vitest list --config vitest.e2e.config.ts`: the e2e config loads and lists 5 tests. - `CI=true npx vitest run --config vitest.e2e.config.ts -t "npm →"` runs through verdaccio publish, `npm install`, `netlify --help` and `netlify link` on vitest 4 and fails at the `netlify unlink` assertion (`expected ... to contain 'Run netlify link to link it'`). The identical run on `main` with vitest 3 fails at the same line: this machine has a globally linked Netlify site (`main` received `Unlinked from netliloop`) and, once unlinked, the CLI running under `npx` phrases the hint as `Run npx netlify link` (the branch received that). The failure is the environment, not the upgrade; the e2e suite is unverified here. - `npm audit --json`: on `main` it lists `vitest` (critical, range 0.0.95 - 4.1.10), `@vitest/mocker`, `@vitest/coverage-v8` and `tinypool <=2.1.1`; on this branch none of the four appear and `npm ls tinypool` shows only `oxfmt@0.72.0 → tinypool@2.2.0`. 39 advisories remain, unchanged from `main`; the two critical ones are `proxy-addr` (Dependabot's #8567 fixes it) and `shell-quote`. ### What is left to test - The full integration suite, the e2e suite, and unit/integration on macOS and Windows (where the single-thread pin matters most) could not run here; on this PR CI ran them and all 34 checks are green (unit on ubuntu/macOS/Windows, 8 integration shards, e2e, lint, format, typecheck, verify-docs, package-size). ### Risk `low`: development tooling only; nothing in `dist/` or the published package changes except the two reformatted files, whose formatting-only diff is in the branch. No Linear issue: a self-contained dependency fix the CLI team can merge from this description. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Netliloop <netliloop@netlify.com> Co-authored-by: Sarah Etter <sarah.etter@netlify.com>
Contributor
|
Superseded by #8573 (vitest ^4.1.11, oxfmt 0.72.0 → tinypool 2.2.0), which has merged. |
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps tinypool to 2.2.0 and updates ancestor dependencies tinypool, @vitest/coverage-v8, vitest and oxfmt. These dependencies need to be updated together.
Updates
tinypoolfrom 1.1.1 to 2.2.0Release notes
Sourced from tinypool's releases.
Commits
2ed30642.2.0dd30cedfeat: accept a URL instance as filename (#141)a067b09fix: remove CJS references (#140)5e183822.1.2f41411afix: guard worker filename from proto pollution (#135)4b5229a2.1.124df4e7fix: guard worker options from proto pollution (#134)abc247f2.1.039481b8feat(child_process): supportserializationoption (#128)4f70c17chore: include node typesMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for tinypool since your current version.
Updates
@vitest/coverage-v8from 3.2.7 to 5.0.3Release notes
Sourced from @vitest/coverage-v8's releases.
... (truncated)
Commits
33cadeachore: release v5.0.3 (#11409)a029e76chore: migrate to oxc (#11367)428e2e5chore: release v5.0.2 (#11357)03630a5chore: release v5.0.1 (#11275)f441c6fchore: release v5.0.0 (#11130)c4473e4fix(coverage): prevent crash on/@fs/prepended virtual files (#11119)897f51fchore: release v5.0.0-rc.4 (#11107)7db80dcchore: release v5.0.0-rc.3 (#11089)5f6a5e8feat(coverage): switch to@vitest/istanbuljspackages (#11053)c6174a6fix(coverage): v8 to ignore Vite SSR's generated import bindings (#11023)Updates
vitestfrom 3.2.7 to 5.0.3Release notes
Sourced from vitest's releases.
... (truncated)
Commits
33cadeachore: release v5.0.3 (#11409)346d389fix(vm): don't reuse scripts across vite environments (#11395)f6c9a49fix(deps): pinwhy-is-node-runningto3.2.1to avoid users running into `...062c75dchore: fix standalone docs build, update exports maps (#11394)caf2887fix(vm): do not optimize deps from index.html (fix #11329) (#11360)50312ebfix(pool): preserve unique pool ids whengroupOrderis set (#11392)7c36748fix(browser): ignore page crash while cancelling (#11386)92ba7fcfix: scope cache key generators to projects (fix #11281) (#11301)38f9885fix(cache): revalidate imports of cached modules (#11381)b24585ffix: don't retry whentest.failsexpectedly failed (#11219)Updates
oxfmtfrom 0.61.0 to 0.72.0Release notes
Sourced from oxfmt's releases.
... (truncated)
Commits
2bd08ebrelease(apps): oxlint v1.87.0 && oxfmt v0.72.0 (#27341)2ae2939release(apps): oxlint v1.86.0 && oxfmt v0.71.0 (#27132)f158bffchore(deps): update npm packages (#26865)288d8ccrelease(apps): oxlint v1.85.0 && oxfmt v0.70.0 (#26903)f02a64arelease(apps): oxlint v1.84.0 && oxfmt v0.69.0 (#26874)7bf68f7release(apps): oxlint v1.83.0 && oxfmt v0.68.0 (#26631)b4da00brelease(apps): oxlint v1.82.0 && oxfmt v0.67.0 (#26384)9a612d5chore(deps): update npm packages (#26178)0b4e2e6release(apps): oxlint v1.81.0 && oxfmt v0.66.0 (#26199)5ff57f8fix(formatter/sort-imports): handle custom side effect groups (#26217)