Bump vitest and @vitest/coverage-v8 to 5.0.0 together - #179
Merged
Merged
Conversation
Dependabot split this into two separate PRs (#177, #178), but bumping either package alone breaks test:coverage with "coverageFilesDirectory is required" since vitest 5's rewritten coverage provider requires both packages to move in lockstep. Also pins vite as an explicit devDependency: vitest 5 requires vite as a non-optional peer, but legacy-peer-deps=true in .npmrc means npm never auto-installs peer deps, so it was silently dropped from the lockfile when only one of the two packages was bumped. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This was referenced Sep 9, 2026
andrewkoltsov
added a commit
that referenced
this pull request
Sep 9, 2026
Dependabot split the vitest 5.0.0 major bump into two separate PRs (#177, #178) because the existing npm-minor-and-patch group only covers minor/patch updates. Bumping either package alone breaks test:coverage, since vitest's coverage provider requires both on the same major version (fixed together in #179). Add a dedicated vitest group (patterns: vitest, @vitest/*) covering all update types, so future bumps of these packages always land in one PR — same fix already applied to codeql-action after a similar incident. Claude-Session: https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Review
CONTRIBUTING.mdfor the branch workflow,required local checks, and when docs or changelog updates are expected.
Summary
@vitest/coverage-v8, Bump vitest from 4.1.11 to 5.0.0 #178 forvitest). Bumping either package alone breakstest:coveragewithAssertionError: coverageFilesDirectory is required, since vitest 5's rewritten coverage provider requires both packages to be on the same major version.vitestand@vitest/coverage-v8to^5.0.0together.viteas an explicit devDependency (^8.2.2). vitest 5 requiresviteas a non-optional peer dependency, but this repo haslegacy-peer-deps=truein.npmrc, so npm never auto-installs peer deps —vitewas silently dropped from the lockfile when only one of the two vitest packages was bumped in isolation. Pinning it explicitly avoids relying on peer-dependency auto-install.Verification
npm run validate(lint, format:check, build, test:coverage, pack:check) — all pass locally with 424/424 tests passing and coverage thresholds metNotes
🤖 Generated with Claude Code
https://claude.ai/code/session_01PJyro83oZ4SGWgG8Xa7XtP
Generated by Claude Code