Repository navigation
chore(deps): update vitest to v4 and oxfmt to 0.72.0 [security] - #8573
Conversation
vitest 4.1.11 clears GHSA-82fw-gwwq-j7x9 (@vitest/mocker path traversal) and oxfmt 0.72.0 moves tinypool past GHSA-85c8-ppgw-ccpr. poolOptions is gone in vitest 4, so singleThread becomes maxWorkers: 1; vi.fn() now honours new, so constructor mocks need function implementations; toThrowError is deprecated in favour of its alias toThrow.
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (23)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. 2 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour. Your free on-demand review promotion remains active until October 9, 2026 at 6:00 PM UTC. 📝 SummarySummary by CodeRabbit
WalkthroughThe pull request updates Vitest and its coverage package to version range Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The committed dependency update resolves the named vulnerable packages, and no actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
commit: |
sarahetter
left a comment
There was a problem hiding this comment.
Reviewed: lockfile + vitest 4 migration (function-style mocks, toThrowError→toThrow, poolOptions→maxWorkers), oxfmt formatting-only src changes. Fixes GHSA-82fw-gwwq-j7x9 and GHSA-85c8-ppgw-ccpr.
Opened by Netliloop run #392 (security-scan), asked in Slack
Why
vitest@3.2.7carries GHSA-82fw-gwwq-j7x9 (@vitest/mockerpath traversal, patched in 4.1.11). Renovate's #8289 and #8320 target it but their lockfiles no longer resolve againstmain(npm cifails on every rebase), and Dependabot's #8570 jumps to vitest 5 and fails typecheck, lint and 12 unit tests.oxfmt@0.61.0pinstinypool@2.1.0, which carries the critical GHSA-85c8-ppgw-ccpr; the only way past it is an oxfmt version that pinstinypool >= 2.1.2.npm auditonmainlistsvitest,@vitest/mocker,@vitest/coverage-v8andtinypool; on this branch none of them appear.What changed
vitestand@vitest/coverage-v8go to^4.1.11, the first patched release (vitest 5 is a week old).oxfmtgoes to0.72.0, which pinstinypool@2.2.0; running it reformats two files undersrc/commands/logs/sources/.poolOptions, sothreads.singleThread: truebecomesmaxWorkers: 1in both configs: still one worker thread, one file at a time. This is not a byte-for-byte port. The migration guide's equivalent addsisolate: false, but in vitest 4 that shares module mocks across files and fails 38 unit tests here, so file isolation stays on and the comment in each config says why. Each file now gets a fresh worker; the Windows-hang TODO beside the pin still applies and CI's Windows jobs on this PR are the check.coverage.alland uses AST remapping), so the Codecov numbers on this PR will move; that is the tooling, not a regression.new, so theNetlifyAPIandLocalStatemock implementations in three test files becomefunctionexpressions instead of arrow functions.toThrowErroris marked@deprecated("Alias forexpect.toThrow") in@vitest/expect4 and so flagged by@typescript-eslint/no-deprecated; 38 call sites intests/switch totoThrowwith the same arguments.How we verified
npm ci --dry-run: the committed lockfile is in sync withpackage.json(Renovate's chore(deps): update dependency vitest to v4 [security] #8289 and chore(deps): update vitest monorepo to v5 #8320 fail exactly here).npm run build,npm run typecheck,npm run lint,npm run format:check: all exit 0.CI=true npm run test:unit -- --coverage: 80 files, 667 tests passed, the same counts asCI=true npm run test:unitonmain. With the migration guide'sisolate: falsethe same command fails 38 tests in 9 files (leaked module mocks), which is why isolation stays on.CI=true npx vitest run --retry=3 --coverage tests/integration/commands/env/env.test.ts tests/integration/commands/dev/dev-forms-and-redirects.test.ts: 2 files, 32 tests passed, so--retry,--coverageand the integration harness work on vitest 4CI=true npm run test:integration -- --shard=1/4here: 24 failures in 6 files, and the same 6 files fail with the same 24 tests onmainunder vitest 3 (this machine has a linked Netlify site and no git identity, whichbuild,cloneandlinktests depend on); the full set is CI's 8 green shards.npx vitest list --config vitest.e2e.config.ts: the e2e config loads and lists 5 tests.CI=true npx vitest run --config vitest.e2e.config.ts -t "npm →"runs through verdaccio publish,npm install,netlify --helpandnetlify linkon vitest 4 and fails at thenetlify unlinkassertion (expected ... to contain 'Run netlify link to link it'). The identical run onmainwith vitest 3 fails at the same line: this machine has a globally linked Netlify site (mainreceivedUnlinked from netliloop) and, once unlinked, the CLI running undernpxphrases the hint asRun npx netlify link(the branch received that). The failure is the environment, not the upgrade; the e2e suite is unverified here.npm audit --json: onmainit listsvitest(critical, range 0.0.95 - 4.1.10),@vitest/mocker,@vitest/coverage-v8andtinypool <=2.1.1; on this branch none of the four appear andnpm ls tinypoolshows onlyoxfmt@0.72.0 → tinypool@2.2.0. 39 advisories remain, unchanged frommain; the two critical ones areproxy-addr(Dependabot's build(deps): bump proxy-addr from 2.0.7 to 2.0.8 #8567 fixes it) andshell-quote.What is left to test
Risk
low: development tooling only; nothing indist/or the published package changes except the two reformatted files, whose formatting-only diff is in the branch. No Linear issue: a self-contained dependency fix the CLI team can merge from this description.🤖 Generated with Claude Code