Skip to content

Bump vitest and @vitest/coverage-v8 to 5.0.0 together - #179

Merged
andrewkoltsov merged 1 commit into
masterfrom
claude/vitest-5-combined-bump
Sep 9, 2026
Merged

andrewkoltsov merged 1 commit into
masterfrom
claude/vitest-5-combined-bump

Conversation

@andrewkoltsov

Copy link
Copy Markdown
Owner

Review CONTRIBUTING.md for the branch workflow,
required local checks, and when docs or changelog updates are expected.

Summary

  • Dependabot split the vitest 5.0.0 major bump into two separate PRs (Bump @vitest/coverage-v8 from 4.1.11 to 5.0.0 #177 for @vitest/coverage-v8, Bump vitest from 4.1.11 to 5.0.0 #178 for vitest). Bumping either package alone breaks test:coverage with AssertionError: coverageFilesDirectory is required, since vitest 5's rewritten coverage provider requires both packages to be on the same major version.
  • This PR bumps vitest and @vitest/coverage-v8 to ^5.0.0 together.
  • Also pins vite as an explicit devDependency (^8.2.2). vitest 5 requires vite as a non-optional peer dependency, but this repo has legacy-peer-deps=true in .npmrc, so npm never auto-installs peer deps — vite was silently dropped from the lockfile when only one of the two vitest packages was bumped in isolation. Pinning it explicitly avoids relying on peer-dependency auto-install.

Verification

  • npm run validate (lint, format:check, build, test:coverage, pack:check) — all pass locally with 424/424 tests passing and coverage thresholds met
  • manual verification noted below if applicable

Notes

🤖 Generated with Claude Code

https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP


Generated by Claude Code

Dependabot split this into two separate PRs (#177, #178), but bumping
either package alone breaks test:coverage with "coverageFilesDirectory
is required" since vitest 5's rewritten coverage provider requires
both packages to move in lockstep.

Also pins vite as an explicit devDependency: vitest 5 requires vite
as a non-optional peer, but legacy-peer-deps=true in .npmrc means npm
never auto-installs peer deps, so it was silently dropped from the
lockfile when only one of the two packages was bumped.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​vitest/​coverage-v8@​4.1.11 ⏵ 5.0.09910079 +199 +1100
Updatedvitest@​4.1.11 ⏵ 5.0.098 +110079 +199100
Updatedvite@​8.0.16 ⏵ 8.2.29810082 +197 +1100

View full report

@andrewkoltsov
andrewkoltsov merged commit 5f5ce65 into master Sep 9, 2026
11 checks passed
@andrewkoltsov
andrewkoltsov deleted the claude/vitest-5-combined-bump branch September 9, 2026 16:43
andrewkoltsov added a commit that referenced this pull request Sep 9, 2026
Dependabot split the vitest 5.0.0 major bump into two separate PRs
(#177, #178) because the existing npm-minor-and-patch group only
covers minor/patch updates. Bumping either package alone breaks
test:coverage, since vitest's coverage provider requires both on the
same major version (fixed together in #179).

Add a dedicated vitest group (patterns: vitest, @vitest/*) covering
all update types, so future bumps of these packages always land in
one PR — same fix already applied to codeql-action after a similar
incident.


Claude-Session: https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants