Skip to content

chore(deps): update vitest to v4 and oxfmt to 0.72.0 [security] - #8573

Merged
sarahetter merged 2 commits into
mainfrom
netliloop/392/vitest-security-update
Oct 6, 2026
Merged

sarahetter merged 2 commits into
mainfrom
netliloop/392/vitest-security-update

Conversation

@netlify-coding

@netlify-coding netlify-coding Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Opened by Netliloop run #392 (security-scan), asked in Slack

Why

  • vitest@3.2.7 carries GHSA-82fw-gwwq-j7x9 (@vitest/mocker path traversal, patched in 4.1.11). Renovate's #8289 and #8320 target it but their lockfiles no longer resolve against main (npm ci fails on every rebase), and Dependabot's #8570 jumps to vitest 5 and fails typecheck, lint and 12 unit tests.
  • oxfmt@0.61.0 pins tinypool@2.1.0, which carries the critical GHSA-85c8-ppgw-ccpr; the only way past it is an oxfmt version that pins tinypool >= 2.1.2.
  • npm audit on main lists vitest, @vitest/mocker, @vitest/coverage-v8 and tinypool; on this branch none of them appear.

What changed

  • vitest and @vitest/coverage-v8 go to ^4.1.11, the first patched release (vitest 5 is a week old).
  • oxfmt goes to 0.72.0, which pins tinypool@2.2.0; running it reformats two files under src/commands/logs/sources/.
  • vitest 4 removed poolOptions, so threads.singleThread: true becomes maxWorkers: 1 in both configs: still one worker thread, one file at a time. This is not a byte-for-byte port. The migration guide's equivalent adds isolate: false, but in vitest 4 that shares module mocks across files and fails 38 unit tests here, so file isolation stays on and the comment in each config says why. Each file now gets a fresh worker; the Windows-hang TODO beside the pin still applies and CI's Windows jobs on this PR are the check.
  • Transitively, vitest now carries its own nested Vite 8.3.3 (rolldown) instead of the top-level Vite 7.3.5, so test-file transforms change engine.
  • Coverage reports change shape (vitest 4 drops coverage.all and uses AST remapping), so the Codecov numbers on this PR will move; that is the tooling, not a regression.
  • vitest 4 constructs mocks called with new, so the NetlifyAPI and LocalState mock implementations in three test files become function expressions instead of arrow functions.
  • toThrowError is marked @deprecated ("Alias for expect.toThrow") in @vitest/expect 4 and so flagged by @typescript-eslint/no-deprecated; 38 call sites in tests/ switch to toThrow with the same arguments.
  • Supersedes chore(deps): update dependency vitest to v4 [security] #8289, chore(deps): update vitest monorepo to v5 #8320 and build(deps): bump tinypool, @vitest/coverage-v8, vitest and oxfmt #8570, which can be closed when this merges.

How we verified

  • npm ci --dry-run: the committed lockfile is in sync with package.json (Renovate's chore(deps): update dependency vitest to v4 [security] #8289 and chore(deps): update vitest monorepo to v5 #8320 fail exactly here).
  • npm run build, npm run typecheck, npm run lint, npm run format:check: all exit 0.
  • CI=true npm run test:unit -- --coverage: 80 files, 667 tests passed, the same counts as CI=true npm run test:unit on main. With the migration guide's isolate: false the same command fails 38 tests in 9 files (leaked module mocks), which is why isolation stays on.
  • CI=true npx vitest run --retry=3 --coverage tests/integration/commands/env/env.test.ts tests/integration/commands/dev/dev-forms-and-redirects.test.ts: 2 files, 32 tests passed, so --retry, --coverage and the integration harness work on vitest 4
  • CI=true npm run test:integration -- --shard=1/4 here: 24 failures in 6 files, and the same 6 files fail with the same 24 tests on main under vitest 3 (this machine has a linked Netlify site and no git identity, which build, clone and link tests depend on); the full set is CI's 8 green shards.
  • npx vitest list --config vitest.e2e.config.ts: the e2e config loads and lists 5 tests.
  • CI=true npx vitest run --config vitest.e2e.config.ts -t "npm →" runs through verdaccio publish, npm install, netlify --help and netlify link on vitest 4 and fails at the netlify unlink assertion (expected ... to contain 'Run netlify link to link it'). The identical run on main with vitest 3 fails at the same line: this machine has a globally linked Netlify site (main received Unlinked from netliloop) and, once unlinked, the CLI running under npx phrases the hint as Run npx netlify link (the branch received that). The failure is the environment, not the upgrade; the e2e suite is unverified here.
  • npm audit --json: on main it lists vitest (critical, range 0.0.95 - 4.1.10), @vitest/mocker, @vitest/coverage-v8 and tinypool <=2.1.1; on this branch none of the four appear and npm ls tinypool shows only oxfmt@0.72.0 → tinypool@2.2.0. 39 advisories remain, unchanged from main; the two critical ones are proxy-addr (Dependabot's build(deps): bump proxy-addr from 2.0.7 to 2.0.8 #8567 fixes it) and shell-quote.

What is left to test

  • The full integration suite, the e2e suite, and unit/integration on macOS and Windows (where the single-thread pin matters most) could not run here; on this PR CI ran them and all 34 checks are green (unit on ubuntu/macOS/Windows, 8 integration shards, e2e, lint, format, typecheck, verify-docs, package-size).

Risk

low: development tooling only; nothing in dist/ or the published package changes except the two reformatted files, whose formatting-only diff is in the branch. No Linear issue: a self-contained dependency fix the CLI team can merge from this description.

🤖 Generated with Claude Code

vitest 4.1.11 clears GHSA-82fw-gwwq-j7x9 (@vitest/mocker path traversal) and
oxfmt 0.72.0 moves tinypool past GHSA-85c8-ppgw-ccpr. poolOptions is gone in
vitest 4, so singleThread becomes maxWorkers: 1; vi.fn() now honours new, so
constructor mocks need function implementations; toThrowError is deprecated
in favour of its alias toThrow.
@netlify-coding
netlify-coding Bot requested a review from a team as a code owner October 6, 2026 15:40
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Team
  • Run ID: 5a06f714-e73a-4145-8566-a12fa2666e18
📥 Commits

Reviewing files that changed from the base of the PR and between 111d78e and d1c48cd.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • package.json
  • tests/integration/commands/dev/dev-forms-and-redirects.test.ts
 ______________________________________________________
< Your merge request walked so code reviews could run. >
 ------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Team
  • Run ID: 04ff1909-86ab-4c15-b6e3-30ae6d68e977
📥 Commits

Reviewing files that changed from the base of the PR and between 40d389e and 111d78e.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (23)
  • package.json
  • src/commands/logs/sources/edge-functions.ts
  • src/commands/logs/sources/functions.ts
  • tests/integration/commands/blobs/blobs.test.ts
  • tests/integration/commands/deploy/deploy.test.ts
  • tests/integration/commands/dev/dev-forms-and-redirects.test.ts
  • tests/integration/commands/dev/dev-miscellaneous.test.ts
  • tests/integration/commands/dev/dev.zisi.test.ts
  • tests/integration/commands/env/env-set.test.ts
  • tests/integration/commands/functions-create/functions-create.test.ts
  • tests/integration/commands/sites/sites.test.ts
  • tests/integration/telemetry.test.ts
  • tests/unit/commands/api/api.test.ts
  • tests/unit/commands/clone/clone.test.ts
  • tests/unit/commands/login/login-check.test.ts
  • tests/unit/commands/login/login-request.test.ts
  • tests/unit/lib/exec-fetcher.test.ts
  • tests/unit/utils/deploy/util.test.ts
  • tests/unit/utils/headers.test.ts
  • tests/unit/utils/live-tunnel.test.ts
  • tests/unit/utils/read-repo-url.test.ts
  • vitest.config.ts
  • vitest.e2e.config.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 2 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour. Your free on-demand review promotion remains active until October 9, 2026 at 6:00 PM UTC.


📝 Summary

Summary by CodeRabbit

  • Chores

    • Updated testing and formatting tools.
  • Tests

    • Updated test configuration and assertions to remain compatible with the current testing tools. Tested behaviors and expected results are unchanged.

Walkthrough

The pull request updates Vitest and its coverage package to version range ^4.1.11, updates oxfmt, and adjusts both Vitest configurations. Tests replace toThrowError assertions with toThrow and change three mock implementations to regular functions. Historical edge-function and function log mappings are reformatted without changes to their behavior.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: ndhoule

Merge Risk: ⚪ Minimal · up to 111d7

The committed dependency update resolves the named vulnerable packages, and no actionable merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the Vitest and oxfmt dependency updates and identifies the security context.
Description check ✅ Passed The description explains the dependency updates, related Vitest changes, security rationale, and reported verification results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

📊 Benchmark results

Comparing with 26d16cd

  • Dependency count: 1,014 ⬇️ 0.30% decrease vs. 26d16cd
  • Package size: 373 MB ⬇️ 1.83% decrease vs. 26d16cd
  • Number of ts-expect-error directives: 331 (no change)

@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/netlify-cli@8573

commit: d1c48cd

@sarahetter sarahetter left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed: lockfile + vitest 4 migration (function-style mocks, toThrowError→toThrow, poolOptions→maxWorkers), oxfmt formatting-only src changes. Fixes GHSA-82fw-gwwq-j7x9 and GHSA-85c8-ppgw-ccpr.

@sarahetter
sarahetter enabled auto-merge (squash) October 6, 2026 16:20
@sarahetter
sarahetter merged commit e5d6c36 into main Oct 6, 2026
36 of 37 checks passed
@sarahetter
sarahetter deleted the netliloop/392/vitest-security-update branch October 6, 2026 16:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant