Skip to content

build(deps): bump tinypool, @vitest/coverage-v8, vitest and oxfmt - #8570

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-e26da46fb2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-e26da46fb2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps tinypool to 2.2.0 and updates ancestor dependencies tinypool, @vitest/coverage-v8, vitest and oxfmt. These dependencies need to be updated together.

Updates tinypool from 1.1.1 to 2.2.0

Release notes

Sourced from tinypool's releases.

v2.2.0

What's Changed

New Contributors

Full Changelog: tinylibs/tinypool@v2.1.2...v2.2.0

v2.1.2

Contains security fix for GHSA-85c8-ppgw-ccpr.

What's Changed

Full Changelog: tinylibs/tinypool@v2.1.1...v2.1.2

v2.1.1

Contains security fix for GHSA-5gmw-xhrv-c9v3.

What's Changed

Full Changelog: tinylibs/tinypool@v2.1.0...v2.1.1

v2.1.0

What's Changed

New Contributors

Full Changelog: tinylibs/tinypool@v2.0.0...v2.1.0

v2.0.0

What's Changed

Full Changelog: tinylibs/tinypool@v1.1.1...v2.0.0

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for tinypool since your current version.


Updates @vitest/coverage-v8 from 3.2.7 to 5.0.3

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Updates vitest from 3.2.7 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Updates oxfmt from 0.61.0 to 0.72.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.72.0

💥 BREAKING CHANGES

  • e2c68b1 oxfmt: [BREAKING] Format parser:markdown files by oxc_formatter_markdown (#27256) (leaysgur)

🚀 Features

  • b538e3c formatter_css: Parse embedded CSS as a block's contents (#27284) (leaysgur)

🐛 Bug Fixes

  • 71e400b formatter_markdown: Fixed remaining issues found by fuzz (#27334) (leaysgur)
  • 7d0e54d formatter_markdown: Preserve line breaks around Chinese/Japanese characters in all proseWrap (#27331) (leaysgur)
  • e9ae2d8 formatter_css: Fix layouts found in mdn-content repo (css-in-md) (#27326) (leaysgur)
  • df85b4c oxfmt: Keep blank lines after a line break in Prettier Doc to IR (#27325) (leaysgur)
  • 7f65b75 formatter: Format assignment target property as assignment-like (#27289) (leaysgur)
  • 6c08f2a formatter_css: Apply the url() import exception to a lone comma group (#27288) (leaysgur)
  • 1967302 formatter_css: Hug a spaced ident ( only at the at-rule prelude head (#27283) (leaysgur)
  • 2445064 formatter_markdown: Keep a preserved line break before a delimiter row that opens no table (#27278) (leaysgur)
  • dd72fbf formatter_markdown: Keep container columns as spaces under useTabs (#27277) (leaysgur)
  • 1686018 oxfmt: Make one state conditionalGroup fit up to first hardline (#27275) (leaysgur)
  • fd4ddce formatter_json: Flatten block comment only array|object (#27274) (leaysgur)
  • 267557c formatter,oxfmt: Embed only original JSDoc plugin supported languages (#27241) (leaysgur)
  • 2606c60 oxfmt: Do not re-include a file below an excluded directory with a negated pattern (#27237) (Nicolas Le Cam)
  • c2de02b formatter: Decide embedded template layout from AST, not source shape (#27218) (leaysgur)
  • c9e1224 formatter: Handle quoteProps: consistent for patterns and computed keys (#27216) (leaysgur)
  • 36e14df formatter: Keep comments between callee and its opener on the callee side (#27172) (leaysgur)
  • 6da7657 oxfmt: Render diagnostics with source in Stdin mode (#27130) (leaysgur)
  • e9b2ec5 oxfmt/lsp: Reload .prettierignore on watched file change (#27129) (leaysgur)
  • 30eb463 oxfmt: Check global ignores before resolving nested config in Stdin mode (#27128) (leaysgur)

⚡ Performance

  • 72f42a3 formatter_markdown: Pre-allocate the IR buffer (#27333) (leaysgur)
  • cea47e3 formatter_core: Avoid exponential will_break check on nested interned (#27211) (leaysgur)
  • 0aba566 oxfmt: Do not resolve root js config from nested context (#27147) (leaysgur)

📚 Documentation

  • 51506c6 formatter_css: Record divergences found in mdn-content (css-in-md) (#27327) (leaysgur)
  • 656b81c formatter_markdown: Record unclosed fences closing at a directive's closer (#27279) (leaysgur)
  • 66545bf formatter_markdown: Record setext heading wrap divergence (#27221) (leaysgur)
  • af4b269 oxfmt: Document why format() API does not take cwd (#27131) (leaysgur)

oxfmt v0.71.0

🚀 Features

  • e0b1f9f oxfmt: Bump bundled Prettier version to 3.9.9 (#27002) (leaysgur)
  • 342527d oxfmt: Bump bundled Prettier version to 3.9.8 (#26999) (leaysgur)

... (truncated)

Commits

@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 08:57
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 6, 2026
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 756c4780-88ae-44da-a8be-270478f3549f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

📊 Benchmark results

Comparing with 26d16cd

  • Dependency count: 1,014 ⬇️ 0.30% decrease vs. 26d16cd
  • Package size: 373 MB ⬇️ 1.83% decrease vs. 26d16cd
  • Number of ts-expect-error directives: 331 (no change)

@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/netlify-cli@8570

commit: 0ef00b8

Bumps [tinypool](https://github.com/tinylibs/tinypool) to 2.2.0 and updates ancestor dependencies [tinypool](https://github.com/tinylibs/tinypool), [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8), [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) and [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt). These dependencies need to be updated together.


Updates `tinypool` from 1.1.1 to 2.2.0
- [Release notes](https://github.com/tinylibs/tinypool/releases)
- [Commits](tinylibs/tinypool@v1.1.1...v2.2.0)

Updates `@vitest/coverage-v8` from 3.2.7 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `vitest` from 3.2.7 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `oxfmt` from 0.61.0 to 0.72.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.72.0/npm/oxfmt)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
- dependency-name: oxfmt
  dependency-version: 0.72.0
  dependency-type: direct:development
- dependency-name: tinypool
  dependency-version: 2.2.0
  dependency-type: indirect
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-e26da46fb2 branch from d0860f6 to 0ef00b8 Compare October 6, 2026 16:23
sarahetter added a commit that referenced this pull request Oct 6, 2026
Opened by Netliloop run [#392](https://netliloop.netlify.app/#/runs/392)
(security-scan), asked in
[Slack](https://slack.com/archives/C095D1JL480/p1791299459766719?thread_ts=1791298825.895999&cid=C095D1JL480)

### Why

- `vitest@3.2.7` carries
[GHSA-82fw-gwwq-j7x9](GHSA-82fw-gwwq-j7x9)
(`@vitest/mocker` path traversal, patched in 4.1.11). Renovate's
[#8289](#8289) and
[#8320](#8320) target it but their
lockfiles no longer resolve against `main` (`npm ci` fails on every
rebase), and Dependabot's
[#8570](#8570) jumps to vitest 5 and
fails typecheck, lint and 12 unit tests.
- `oxfmt@0.61.0` pins `tinypool@2.1.0`, which carries the critical
[GHSA-85c8-ppgw-ccpr](GHSA-85c8-ppgw-ccpr);
the only way past it is an oxfmt version that pins `tinypool >= 2.1.2`.
- `npm audit` on `main` lists `vitest`, `@vitest/mocker`,
`@vitest/coverage-v8` and `tinypool`; on this branch none of them
appear.

### What changed

- `vitest` and `@vitest/coverage-v8` go to `^4.1.11`, the first patched
release (vitest 5 is a week old).
- `oxfmt` goes to `0.72.0`, which pins `tinypool@2.2.0`; running it
reformats two files under `src/commands/logs/sources/`.
- vitest 4 removed `poolOptions`, so `threads.singleThread: true`
becomes `maxWorkers: 1` in both configs: still one worker thread, one
file at a time. This is not a byte-for-byte port. The migration guide's
equivalent adds `isolate: false`, but in vitest 4 that shares module
mocks across files and fails 38 unit tests here, so file isolation stays
on and the comment in each config says why. Each file now gets a fresh
worker; the Windows-hang TODO beside the pin still applies and CI's
Windows jobs on this PR are the check.
- Transitively, vitest now carries its own nested Vite 8.3.3 (rolldown)
instead of the top-level Vite 7.3.5, so test-file transforms change
engine.
- Coverage reports change shape (vitest 4 drops `coverage.all` and uses
AST remapping), so the Codecov numbers on this PR will move; that is the
tooling, not a regression.
- vitest 4 constructs mocks called with `new`, so the `NetlifyAPI` and
`LocalState` mock implementations in three test files become `function`
expressions instead of arrow functions.
- `toThrowError` is marked `@deprecated` ("Alias for `expect.toThrow`")
in `@vitest/expect` 4 and so flagged by
`@typescript-eslint/no-deprecated`; 38 call sites in `tests/` switch to
`toThrow` with the same arguments.
- Supersedes #8289, #8320 and #8570, which can be closed when this
merges.

### How we verified

- `npm ci --dry-run`: the committed lockfile is in sync with
`package.json` (Renovate's #8289 and #8320 fail exactly here).
- `npm run build`, `npm run typecheck`, `npm run lint`, `npm run
format:check`: all exit 0.
- `CI=true npm run test:unit -- --coverage`: 80 files, 667 tests passed,
the same counts as `CI=true npm run test:unit` on `main`. With the
migration guide's `isolate: false` the same command fails 38 tests in 9
files (leaked module mocks), which is why isolation stays on.
- `CI=true npx vitest run --retry=3 --coverage
tests/integration/commands/env/env.test.ts
tests/integration/commands/dev/dev-forms-and-redirects.test.ts`: 2
files, 32 tests passed, so `--retry`, `--coverage` and the integration
harness work on vitest 4
- `CI=true npm run test:integration -- --shard=1/4` here: 24 failures in
6 files, and the same 6 files fail with the same 24 tests on `main`
under vitest 3 (this machine has a linked Netlify site and no git
identity, which `build`, `clone` and `link` tests depend on); the full
set is CI's 8 green shards.
- `npx vitest list --config vitest.e2e.config.ts`: the e2e config loads
and lists 5 tests.
- `CI=true npx vitest run --config vitest.e2e.config.ts -t "npm →"` runs
through verdaccio publish, `npm install`, `netlify --help` and `netlify
link` on vitest 4 and fails at the `netlify unlink` assertion (`expected
... to contain 'Run netlify link to link it'`). The identical run on
`main` with vitest 3 fails at the same line: this machine has a globally
linked Netlify site (`main` received `Unlinked from netliloop`) and,
once unlinked, the CLI running under `npx` phrases the hint as `Run npx
netlify link` (the branch received that). The failure is the
environment, not the upgrade; the e2e suite is unverified here.
- `npm audit --json`: on `main` it lists `vitest` (critical, range
0.0.95 - 4.1.10), `@vitest/mocker`, `@vitest/coverage-v8` and `tinypool
<=2.1.1`; on this branch none of the four appear and `npm ls tinypool`
shows only `oxfmt@0.72.0 → tinypool@2.2.0`. 39 advisories remain,
unchanged from `main`; the two critical ones are `proxy-addr`
(Dependabot's #8567 fixes it) and `shell-quote`.

### What is left to test

- The full integration suite, the e2e suite, and unit/integration on
macOS and Windows (where the single-thread pin matters most) could not
run here; on this PR CI ran them and all 34 checks are green (unit on
ubuntu/macOS/Windows, 8 integration shards, e2e, lint, format,
typecheck, verify-docs, package-size).

### Risk

`low`: development tooling only; nothing in `dist/` or the published
package changes except the two reformatted files, whose formatting-only
diff is in the branch. No Linear issue: a self-contained dependency fix
the CLI team can merge from this description.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Netliloop <netliloop@netlify.com>
Co-authored-by: Sarah Etter <sarah.etter@netlify.com>
@sarahetter

Copy link
Copy Markdown
Contributor

Superseded by #8573 (vitest ^4.1.11, oxfmt 0.72.0 → tinypool 2.2.0), which has merged.

@sarahetter sarahetter closed this Oct 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-e26da46fb2 branch October 6, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant