Skip to content

Upgrade vitest and @vitest/coverage-v8 to 5, group vitest in Dependabot - #55

Merged
michalporeba merged 1 commit into
mainfrom
deps/vitest-5
Sep 27, 2026
Merged

michalporeba merged 1 commit into
mainfrom
deps/vitest-5

Conversation

@michalporeba

Copy link
Copy Markdown
Owner

Replaces #50, #51 and #54, which each failed npm ci with ERESOLVE because @vitest/coverage-v8 pins vitest as an exact peer and Dependabot bumped only one side.

Changes

  • vitest ^4.1.4 → ^5.0.2 and @vitest/coverage-v8 ^4.1.4 → ^5.0.2, together
  • security updates from Bump the npm_and_yarn group across 1 directory with 3 updates #54: ws → 8.22.0, brace-expansion → 5.0.12, @vitest/mocker → 5.0.2 (via vitest)
  • npm audit fix resolves esbuild to 0.27.2, below the advisory range (GHSA-g7r4-m6w7-qqqr); npm audit now reports 0 vulnerabilities (was 6 on main)
  • .github/dependabot.yml: group vitest + @vitest/* for version and security updates so they always move together

Verification (local, Node 26)

  • npm ci, npm run verify (139 tests, coverage thresholds pass), npm run build, npm run test:demo: all pass
  • npm run test:pod could not run locally (Solid containers unreachable on this machine, main fails identically), relying on CI's Pod Integration job

🤖 Generated with Claude Code

Move vitest and @vitest/coverage-v8 to 5.0.2 together; the coverage
package pins vitest as an exact peer, so bumping either alone fails
npm ci with ERESOLVE (dependabot #50, #51, #54).

Also picks up the security updates from #54 (ws, brace-expansion,
@vitest/mocker) and resolves esbuild below the affected range, leaving
npm audit clean.

Group vitest and @vitest/* in dependabot for both version and security
updates so they are always bumped together.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@michalporeba
michalporeba merged commit 79bb59b into main Sep 27, 2026
7 checks passed
@michalporeba
michalporeba deleted the deps/vitest-5 branch September 27, 2026 19:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant