Skip to content

Bump vitest from 4.1.11 to 5.0.0 - #178

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/vitest-5.0.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/vitest-5.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps vitest from 4.1.11 to 5.0.0.

Release notes

Sourced from vitest's releases.

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits
  • f441c6f chore: release v5.0.0 (#11130)
  • d46a747 fix: treat test.describe as a suite during static collection (#11128)
  • 584cf30 fix: add a warning if inline project has duplicate plugins due to unexpected ...
  • f08ce4b fix: apply queued mocks from doMock() in queue order (fixes #10706) (#11127)
  • 897f51f chore: release v5.0.0-rc.4 (#11107)
  • 1339b06 chore(deps): update all non-major dependencies (#11104)
  • 51e9494 feat!: parse files statically in vitest list by default (#11088)
  • 2122ffd fix: propagate --maxWorkers to projects (#11102)
  • dc10f5f fix(browser): report the action error when a task times out (#11101)
  • d4fe198 feat: promote clearCache out of experimental (#11086)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Dependency updates label Sep 9, 2026
@dependabot
dependabot Bot requested a review from andrewkoltsov as a code owner September 9, 2026 07:06
@dependabot dependabot Bot added the dependencies Dependency updates label Sep 9, 2026
@socket-security

socket-security Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedvitest@​4.1.11 ⏵ 5.0.098 +110079 +199100

View full report

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.11 to 5.0.0.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/vitest-5.0.0 branch from 0ecebdf to 22e7d91 Compare September 9, 2026 07:35
andrewkoltsov added a commit that referenced this pull request Sep 9, 2026
Dependabot split this into two separate PRs (#177, #178), but bumping
either package alone breaks test:coverage with "coverageFilesDirectory
is required" since vitest 5's rewritten coverage provider requires
both packages to move in lockstep.

Also pins vite as an explicit devDependency: vitest 5 requires vite
as a non-optional peer, but legacy-peer-deps=true in .npmrc means npm
never auto-installs peer deps, so it was silently dropped from the
lockfile when only one of the two packages was bumped.


Claude-Session: https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP

Co-authored-by: Claude <noreply@anthropic.com>

Copy link
Copy Markdown
Owner

Superseded by #179, which bumps vitest and @vitest/coverage-v8 together — bumping either package alone (as this PR does) breaks test:coverage with AssertionError: coverageFilesDirectory is required, since vitest 5's coverage provider requires both packages on the same major version. Closing in favor of #179 (merged).


Generated by Claude Code

@dependabot @github

dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/vitest-5.0.0 branch September 9, 2026 16:43
andrewkoltsov added a commit that referenced this pull request Sep 9, 2026
Dependabot split the vitest 5.0.0 major bump into two separate PRs
(#177, #178) because the existing npm-minor-and-patch group only
covers minor/patch updates. Bumping either package alone breaks
test:coverage, since vitest's coverage provider requires both on the
same major version (fixed together in #179).

Add a dedicated vitest group (patterns: vitest, @vitest/*) covering
all update types, so future bumps of these packages always land in
one PR — same fix already applied to codeql-action after a similar
incident.


Claude-Session: https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant