Repository navigation
build(deps-dev): bump vitest from 4.1.0 to 4.1.11 - #283
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.0 to 4.1.11. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 4.1.11 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
🟡 Changes recommended
The updated lockfile includes a deprecated transitive dependency (@ungap/structured-clone@1.3.0) flagged for a potential CWE-502 and should be upgraded to >=1.3.1 (e.g., via pnpm overrides) before approval.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR updates the repo’s dev test runner tooling by bumping the vitest devDependency from 4.1.0 to 4.1.11, aligning the lockfile to the new Vitest release and its transitive dependency set.
Changes:
- Bump
vitestversion inpackage.jsonto^4.1.11. - Regenerate
pnpm-lock.yamlto reflectvitest@4.1.11and updated transitive packages.
File summaries
| File | Description |
|---|---|
| package.json | Updates the vitest devDependency version. |
| pnpm-lock.yaml | Updates the resolved Vitest version and transitive dependency graph for pnpm installs. |
Review details
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
- Files reviewed: 1/2 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| '@ungap/structured-clone@1.3.0': | ||
| resolution: {integrity: sha512-WmoN8qaIAo7WTYWbAZuG8PYEhn5fkz7dZrqTBZ7dtt//lL2Gwms1IcnQ5yHqjDfX8Ft5j4YzDM23f87zBfDe9g==} | ||
| deprecated: Potential CWE-502 - Update to 1.3.1 or higher |
|
Superseded by #284, merged as efdf3a7. That PR bumps both It also removes |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
> **Stack of 4 — merge bottom to top.** Review each layer against the one below it, not `main`. > > **→** 1. dfinity#284 — security fix: dependency advisories, `bun.lock` removal > 2. dfinity#285 — contributor setup docs > 3. dfinity#286 — `consumer_install` job, retires `e2e_test_bun` > 4. dfinity#288 — consumer install guidance > > Repo installs are pnpm-only: `pnpm.overrides`, `minimumReleaseAge` and `onlyBuiltDependencies` are pnpm-only fields, so a second installer resolves a graph that bypasses them. Bun remains a supported **consumer** runtime, covered by `consumer_install (bun)` from layer 3. > > Scoped to the security fix and the install-path change it forces. Pre-existing documentation gaps in `README.md` and `examples/README.md`, including the `pnpm run setup` step and the canister toolchain, are fixed in dfinity#285. Clears all 24 open Dependabot alerts (1 critical, 13 high, 8 moderate, 2 low). Supersedes dfinity#275 and dfinity#283. Bumps `vite` to `^7.3.5` and `vitest` to `^4.1.11`, and extends `pnpm.overrides` to cover the 21 transitive advisories. Drops the `minimumReleaseAgeExclude: [vite]` entry, annotated for removal after 2026-04-16. ## Removing `bun.lock` `pnpm.overrides`, `minimumReleaseAge` and `onlyBuiltDependencies` are pnpm-only, so `bun.lock` resolved a second dependency graph that bypassed them. Against the overrides as they stood on `main`: | `pnpm.overrides` on `main` | pnpm-lock.yaml | bun.lock | | --- | --- | --- | | `brace-expansion@>=1 <2` → `^1.1.13` | 1.1.13 | 1.1.12 | | `brace-expansion@>=2 <2.0.3` → `^2.0.3` | 2.0.3 | 2.0.2 | | `picomatch@>=2 <3` → `^2.3.2` | 2.3.2 | 2.3.1 | | `picomatch@>=4 <4.0.4` → `4.0.4` | 4.0.4 | 4.0.3 | | `yaml@>=2 <2.8.3` → `2.8.3` | 2.8.3 | 2.8.2 | This PR then raises several of those bounds to clear the open advisories, so the versions now resolved are `brace-expansion` 1.1.18 / 2.1.4, `picomatch` 2.3.2 / 4.0.4 and `yaml` 2.8.3. Dependabot cannot keep `bun.lock` current either: bun is supported for [version updates but not security updates](https://docs.github.com/en/code-security/dependabot/ecosystems-supported-by-dependabot/supported-ecosystems-and-repositories), so security PRs updated `package.json` and `pnpm-lock.yaml` only, leaving it stale and failing `bun i --frozen-lockfile`. `e2e_test_bun` now installs with pnpm and still builds and tests with bun. Contributor-facing commands move to pnpm to match, including the eight per-example READMEs. ## Verified `pnpm audit` clean · `pnpm i --frozen-lockfile` up to date · `pnpm test:pic` 65 passed · `bun run build` against the pnpm tree 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps vitest from 4.1.0 to 4.1.11.
Release notes
Sourced from vitest's releases.
... (truncated)
Commits
9bd8d46chore: release v4.1.11 (#10995)9851dbcfix(browser): trigger playwright/chromium gc on lower disk availability [back...db616d2chore: release v4.1.10 (#10718)bae52b5fix(vm): fix external module resolve error with deps optimizer query for enco...a7a61e7chore: release v4.1.9 (#10598)934b0f5fix(pool): prevent test run hang on worker crash (#10543) [backport to v4] (#...7fb2965fix(browser): wait for orchestrator readiness before resolving browser sessio...a518019fix: fiximportOriginalwith optimizer and query import [backport to v4] (#...e61f2ddchore: release v4.1.8e4067b3fix(browser): disable clientcdpAPI whenallowWrite/allowExec: false[ba...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.