Skip to content

chore(deps): upgrade vite to 8.3.1 and pin bundled dev rolldown to 1.2.9 - #2034

Merged
stipsan merged 1 commit into
mainfrom
cody/vite-8-3-1-rolldown-pin-80eb
Sep 28, 2026
Merged

stipsan merged 1 commit into
mainfrom
cody/vite-8-3-1-rolldown-pin-80eb

Conversation

@stipsan

@stipsan stipsan commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Description

Ports sanity-io/sanity#15055. dev/test-studio runs sanity dev with unstable_bundledDev: true, so it has the same exposure.

Vite 8.3.1 inlines rolldown 1.2.9's browser dev runtime into bundledDevClient.mjs, but declares rolldown: ~1.2.9. rolldown 1.2.10 dropped the kind argument from registerFactory (rolldown#10915). With rolldown 1.2.10 or 1.2.11 under Vite 8.3.1, every lazy import() and HMR update in bundled dev fails with TypeError: factory.fn is not a function.

This PR moves Vite from 8.2.2 to 8.3.1 and adds 'vite@8.3.1>rolldown': '1.2.9', with the same removal condition as upstream: the next Vite release serves the runtime from the installed rolldown (vite#23568), so delete the entry when bumping past 8.3.1.

Differences from the Sanity PR:

  • Vite is only a transitive dependency here (through @sanity/cli, @sanity/cli-build, vitest and the Vite plugins), so there is no catalog entry to bump. It was moved with pnpm update vite -r.
  • This repo never got the earlier vite>rolldown: 1.2.8 / tsdown>rolldown pins from sanity#14835, so there is nothing to remove. It stayed safe only because Vite was still on 8.2.2. That wouldn't last: @sanity/cli@8.13.0, which the current sanity@next uses, requires vite ^8.3.0, and the clean regeneration in #2018 already resolves Vite 8.3.0 with rolldown 1.2.9, which is the requestLazy crash combination.
  • tsdown keeps its own rolldown 1.2.4 and @sanity/tsdown-config keeps 1.2.6, so plugin builds are unaffected. All 296 dist/ files are byte-identical to a fresh main build.

What to review

  • pnpm-workspace.yaml: the scoped override and its removal condition.
  • pnpm-lock.yaml:
    • Vite 8.2.2 becomes 8.3.1, and Vite's rolldown goes from 1.2.6 to 1.2.9. That adds rolldown 1.2.9 with its bindings, @oxc-project/types@0.150.0, and postcss@8.5.28 (required by Vite 8.3.1). Peer suffixes follow: (vite@8.2.2) becomes (vite@8.3.1), and the rolldown peers of @rolldown/plugin-babel and the Studio CLI packages go from (rolldown@1.2.6) to (rolldown@1.2.9).
    • Any overrides edit makes pnpm fully re-resolve, which also applies normalization unrelated to Vite, the same thing a Renovate or dedupe run would do. No versions are added or removed by this part:
      • The CodeMirror packages in Vision's tree (autocomplete, lint, search, theme-one-dark) move from the locked @codemirror/state 6.7.2 / @codemirror/view 6.43.10 to the locked 6.7.4 / 6.43.11. Vision itself already used those, so its tree now mixes fewer copies.
      • The now-published optional @oxlint/binding-linux-arm64-gnu@1.83.0 is added.
      • A stale catalogs.peer.react entry is dropped.
      • The optional @vitejs/devtools peer is kept only in the sanity snapshot that dev/test-studio uses, since it is the only importer that depends on @vitejs/devtools.
    • The Studio next overrides stay on their locked 6.13.3-next.7. At the time, a full re-resolution would have moved them to 6.17.0-next.106, which pulls @sanity/sdk@3.5.0 and failed trustPolicy: no-downgrade. To keep that upgrade out, I resolved through a throwaway local registry proxy that reported the locked versions as next. pnpm wrote the whole lockfile itself, with no hand edits, and it has no localhost or tarball: entries. Both a clean-clone CI=true pnpm install --frozen-lockfile and a plain pnpm install against npm accept it as-is.

The AGENTS.md note about that next-override gotcha was pushed after this PR merged, so it's in #2038.

Resolved after merge: the ERR_PNPM_TRUST_DOWNGRADE for @sanity/sdk@3.5.0 also broke pnpm dedupe on main. @sanity/sdk 3.4.0 and 3.5.0 were published by sanity-svc.npm without provenance. #2037 fixed it by allowlisting @sanity/sdk@3.5.0 and @sanity/sdk-react@3.5.0 while it bumped the Studio.

Vite 8.3.x also raised its optional @vitejs/devtools peer range to ^0.7.1, while the test studio uses 0.4.12, so pnpm now reports a peer warning. The DevTools workflow still works, because it goes through the DevTools() plugin rather than Vite's top-level devtools option. Bumping @vitejs/devtools* to 0.7 is left for a separate PR.

Testing

First I confirmed the root cause in the published tarballs (Linux x64 binding strings):

Package registerFactory shape
Vite 8.2.2 and 8.3.1 bundledDevClient.mjs registerFactory(id, kind, fn) (8.3.1 also has requestLazy)
rolldown 1.2.6 and 1.2.9 compiler registerFactory(id, kind, fn)
rolldown 1.2.10 and 1.2.11 compiler registerFactory(id, fn)

Then I ran dev/test-studio in bundled dev, authenticated, and drove it headlessly with Playwright. Each run loaded Workspace Home, edited the heading in sanity-plugin-workspace-home/src/components/WorkspaceHome.tsx, reverted the edit, and then opened the Structure tool:

Vite rolldown under Vite Result
8.3.1 1.2.9 (this PR) Renders. 23 /@vite/lazy chunks, all 200. [vite] hot updated for the edit and the revert, applied in place with no reload. Structure renders. 0 page or console errors.
8.3.1 1.2.11 (override temporarily set to the newest ~1.2.9 match) TypeError: factory.fn is not a function at ViteDevRuntime.initModule, the Studio crash screen, and nothing renders.
8.3.1 with ENABLE_VITE_DEVTOOLS=true 1.2.9 Renders, HMR works, and /__devtools/ returns 200. The only error is devframe's "rpc to be trusted" timeout, because no one approved the one-time auth prompt.
8.3.1 on main after #2037 (sanity@6.17.0-next.106) 1.2.9 Same as the first row. The pin held through #2037's re-resolution, which moved every other rolldown consumer to 1.2.11.

Removing the override alone and running pnpm update rolldown -r kept Vite's locked 1.2.9. A fresh resolution, like the regeneration in #2018, picks the newest ~1.2.9 match instead, which is why the negative control sets 1.2.11 explicitly.

bundled_dev_vite_8_3_1_rolldown_1_2_9_lazy_load_and_hmr.mp4

Pinned rolldown 1.2.9: heading hot updated in place
rolldown 1.2.11 under Vite 8.3.1: factory.fn is not a function

Other checks that passed locally:

  • pnpm format (no changes)
  • pnpm lint: 1,505 files, 0 diagnostics
  • pnpm knip
  • pnpm build: 52/52 tasks uncached, including the sanity build of test-studio and e2e-studio on Vite 8.3.1, plus an ENABLE_VITE_DEVTOOLS=true studio build that records a Rolldown session
  • pnpm test run: 224 files, 1,391 tests
  • A clean-clone CI=true pnpm install --frozen-lockfile
  • A byte-for-byte dist/ comparison against main

Notes for release

N/A. This is dev tooling only: no published package changes, so no changeset.

To show artifacts inline, enable in settings.

Open in Web Open in Cursor 

…o 1.2.9

Vite 8.3.1 inlines rolldown 1.2.9's browser dev runtime into bundledDevClient.mjs,
while its rolldown range (~1.2.9) resolves 1.2.10+. rolldown 1.2.10 dropped the kind
argument from registerFactory (rolldown#10915), so with a newer rolldown every lazy
import() and HMR update in bundled dev mode (`unstable_bundledDev` in dev/test-studio)
fails with 'factory.fn is not a function'.

Pin rolldown under vite@8.3.1 to 1.2.9, the version Vite 8.3.1 was built against.
The next Vite release serves the runtime from the installed rolldown (vite#23568),
so the scoped override stops applying once Vite is bumped past 8.3.1.

Vite is only a transitive dependency here, so it was bumped with `pnpm update vite -r`.
The Studio `next` dist-tag overrides stay on their locked 6.13.3-next.7 versions.

Co-authored-by: Cody Olsen <stipsan@users.noreply.github.com>
@changeset-bot

changeset-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 2afc4e0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@stipsan stipsan added the 🤖 bot label Sep 28, 2026 — with Cursor
@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
plugins-studio Ready Ready Preview Sep 28, 2026 1:46pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
plugins-e2e-test-studio Ignored Ignored Sep 28, 2026 1:46pm UTC

Request Review

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ E2E Tests

🟢 43 passed • 🟡 1 flaky • view full report • view run

Studio: https://plugins-e2e-test-studio-eu8jbi00j.sanity.dev

Datasets: pr-2034-chromium-36430987302, pr-2034-firefox-36430987302

@github-actions

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 33.34% 5810 / 17426
🔵 Statements 33.11% 6142 / 18545
🔵 Functions 29.43% 1535 / 5214
🔵 Branches 24.55% 3014 / 12272
File CoverageNo changed files found.
Generated in workflow #10104 for commit 2afc4e0 by the Vitest Coverage Report Action

cursor Bot pushed a commit that referenced this pull request Sep 28, 2026
The sanity@next bump brings in vite@8.3.1, whose bundled-dev client inlines
rolldown 1.2.9's runtime while its `rolldown: ~1.2.9` range resolves 1.2.11.
rolldown 1.2.10 dropped the `kind` argument from registerFactory
(rolldown/rolldown#10915), so every lazy import in the test studio's
`sanity dev` failed with `factory.fn is not a function`.

Same override as #2034.
@stipsan
stipsan marked this pull request as ready for review September 28, 2026 13:59
@stipsan
stipsan requested a review from a team as a code owner September 28, 2026 13:59
@stipsan
stipsan requested review from bjoerge and a balanced review from Copilot and removed request for a team September 28, 2026 13:59
@stipsan
stipsan merged commit 46fdfaf into main Sep 28, 2026
26 checks passed
@stipsan
stipsan deleted the cody/vite-8-3-1-rolldown-pin-80eb branch September 28, 2026 13:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The override is correctly scoped and matches the documented upstream incompatibility.

Review effort: Balanced
Findings: None

What changed in this PR

Pins Rolldown 1.2.9 under Vite 8.3.1 to preserve bundled-development lazy imports and HMR compatibility.

Changes:

  • Adds a version-scoped pnpm override.
  • Documents the incompatibility and removal condition.
File Description
pnpm-workspace.yaml Adds the scoped Rolldown compatibility override.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

cursor Bot pushed a commit that referenced this pull request Sep 28, 2026
Resolves the pnpm-lock.yaml conflict with #2034 by keeping this branch's
lockfile: it already has vite@8.3.1 with the identical `vite@8.3.1>rolldown`
pin that #2034 added, on top of the sanity@next bump, and passes
`pnpm install --frozen-lockfile` and `pnpm dedupe --check` against the
merged manifests.
stipsan added a commit that referenced this pull request Sep 28, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
### Description

Turns on the new `beta.reactActivityMode` flag from
[sanity-io/sanity#14901](sanity-io/sanity#14901)
for every workspace in `dev/test-studio`, so the plugins in this
monorepo get dogfooded with recently used tools kept mounted behind
React's `<Activity>` (effects torn down while hidden, re-created on
reveal) instead of being unmounted on tool switch.

The flag's typings ship in `sanity@6.17.0-next.106`, published by
[Release @next run
36426787139](https://github.com/sanity-io/sanity/actions/runs/36426787139)
from the PR's merge commit (`f5821c33bf`). The lockfile was still on
`6.13.3-next.7`, where the config fails type-checking with `TS2353:
'reactActivityMode' does not exist in type 'BetaFeatures'`, so this also
re-resolves the `next` overrides.

### Changes

- `dev/test-studio/sanity.config.ts`: a shared `beta` constant applied
by `createWorkspace` (placed before `...config`, so a workspace that
defines its own `beta` still opts out) and on the standalone
`cross-dataset-duplicator-target` workspace, which also registers a
tool.
- `pnpm-lock.yaml`: `sanity`, `@sanity/vision`, `@sanity/types`,
`@sanity/util`, `@sanity/schema`, `@sanity/mutator` and `groq` move in
lockstep from `6.13.3-next.7` to `6.17.0-next.106` (one copy of each).
Regenerated with `pnpm dedupe`, the same command the "Dedupe lockfile"
workflow runs, repeated until `pnpm dedupe --check` passes, so no
follow-up bot PR is needed. That also collapses duplicates the bump
would otherwise leave behind, which is why a few direct deps shift to
in-range versions already in the graph: `@codemirror/state` 6.7.6 /
`@codemirror/view` 6.43.13 / `@uiw/react-codemirror` 4.25.12
(code-input), `xstate` 5.33.2 (dashboard-widget-vercel),
`@mux/mux-player(-react)` 3.13.4 (mux-input), `@tanstack/react-virtual`
3.14.13 (workflow), `uuid` 14.0.2 (graph-view), `axios` 1.20.0
(shopify-assets). Catalogs and `package.json` specifiers are unchanged.
- `pnpm-workspace.yaml`: `sanity@6.17.0-next.106` needs `@sanity/sdk`
and `@sanity/sdk-react` `^3.5.0`, which `sanity-svc.npm` published from
`sanity-io/sdk` without provenance (since 3.4.0), tripping `trustPolicy:
no-downgrade`. `3.5.0` of both is added to `trustPolicyExclude` next to
the existing `@sanity/sdk@2.1.2 || 3.0.0-rc.1` entry. Without this,
`pnpm dedupe` on `main` (and so the Dedupe lockfile workflow) currently
fails with `ERR_PNPM_TRUST_DOWNGRADE`.

The bump also pulls in `vite@8.3.1`, whose bundled-dev client needs the
`vite@8.3.1>rolldown: 1.2.9` pin; without it every lazy chunk in `pnpm
dev` fails with `factory.fn is not a function`. That pin landed on
`main` in #2034 (this branch had added the identical override before it
merged), and the merge keeps this branch's deduped lockfile, which
already resolves `vite@8.3.1` → `rolldown@1.2.9`.

No changeset: only the private test studio and workspace tooling change;
published package ranges are untouched.

### Testing

- `pnpm format`, `pnpm lint` (type-aware), `pnpm knip`, `pnpm build` (52
tasks) and `pnpm test run` (224 files, 1391 tests) all pass locally.
- `pnpm oxlint dev/test-studio/sanity.config.ts` fails with `TS2353` on
`6.13.3-next.7` and passes on `6.17.0-next.106`.
- After merging `main`: `pnpm install --frozen-lockfile` and `pnpm
dedupe --check` both pass.
- Manual test of tool switching in the test studio: in progress; this
description will be updated with the recording.

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-e9a7834b-ed40-45c0-8168-0afdb8a313c7?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-e9a7834b-ed40-45c0-8168-0afdb8a313c7&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
stipsan added a commit that referenced this pull request Sep 28, 2026
…overrides (#2038)

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
### Description

Follow-up to [#2034](#2034).
#2034 was merged before this AGENTS.md commit was pushed, so it lands
separately.

While `pnpm-workspace.yaml` overrides `sanity`, `@sanity/mutator`,
`@sanity/schema`, `@sanity/types`, `@sanity/util`, `@sanity/vision`, and
`groq` to the `next` dist-tag, any full re-resolution moves them to the
newest `next` prerelease. That includes editing `overrides`, `pnpm
update <pkg>`, and `pnpm dedupe`. pnpm cannot reuse a locked version for
a dist-tag, so a targeted dependency change silently becomes a Studio
upgrade. The new prerelease can also trip `trustPolicy: no-downgrade`,
which is what happened with `@sanity/sdk@3.5.0` until
[#2037](#2037) allowlisted it.

The note covers the two options: call the Studio bump out in the PR, or
keep it out by resolving through a local registry proxy that serves the
locked versions as `next`. #2034's lockfile was produced the second way.
The note also warns against temporarily pinning the overrides to an
exact version. I tried that first: pnpm applies semver overrides to
`peerDependencies` ranges too, and the rewritten ranges (for example
`sanity: 6.13.3-next.7` in `@sanity/cli-build`'s peers) stay in the
lockfile.

### What to review

- `AGENTS.md`: one new paragraph under "Code Style → Dependencies",
after the Studio upgrade steps.

### Testing

Docs only. `oxfmt --check AGENTS.md` passes.

### Notes for release

N/A. Docs only, no changeset.
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-8a49abed-56bd-47f4-9e16-fbcde27d80eb?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-8a49abed-56bd-47f4-9e16-fbcde27d80eb&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>

This branch was successfully deployed

1 active deployment
Preview – plugins-studio — 2afc4e08 Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants