build(deps): bump vitest and @vitest/coverage-v8 to 5.0.3 in /web - #635
dependabot[bot] wants to merge 9 commits into
Conversation
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.11 to 5.0.1. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 5.0.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
🔥 Roast: half an upgrade, and a CI that has never once run1. It is one half of a two-part bump
So coverage-v8@4.1.11 demands vitest@4.1.11 exactly, while this PR moves vitest to 5. The tree is unsatisfiable. #636 is the mirror image (coverage-v8 → 5, vitest left at 4) and I am closing it as the stale, conflicting half; the pair must land as one PR.
2.
|
| conclusion | count |
|---|---|
action_required |
32 |
success |
7 |
skipped |
1 |
Every one of those 7 successes is CodeQL, Codacy or Vercel — third-party apps. Every CI, CI UI, Commit Lint, Security Scan, Integration Tests and Gitleaks run is parked at action_required, waiting for a workflow approval nobody gave.
The consequence is that the four gates DEPENDABOT_AUTO_MERGE_SOP.md step 4 requires — Lint, Sample Run, Quality Gate, E2E Tests (web) — have never executed, on any commit, in nine days. This PR has been sitting in the queue on the strength of a green CodeQL badge that says nothing about whether vitest 5 actually runs the suite.
Given that web/tests/ holds 20+ test files and web/vitest.config.ts configures globals, environment: "node" and a v8 coverage provider, "a major test-runner upgrade that has never been executed" is the whole risk profile of this PR.
3. What is actually fine
vitest@5.0.1engines require Node^22.12.0 || ^24.0.0 || >=26.0.0; CI pinsnode-version: '22', which resolves to latest 22.x. No problem there.- Per
DEPENDABOT_AUTO_MERGE_SOP.md,update-type: semver-majoris intentional human-review routing, not a bug. Correct that this is waiting on a person rather than auto-merging.
Verdict
Keep — but it is not mergeable as-is and it is not "blocked on review", it is unvalidated.
To land it:
- Add
@vitest/coverage-v8→^5.0.1in the same PR (this absorbs build(deps-dev): bump @vitest/coverage-v8 from 4.1.11 to 5.0.1 in /web #636). - Approve the parked workflow runs so the web suite actually executes.
- Confirm the 20+ files in
web/tests/and thetests/e2e/**exclusion still behave on vitest 5.
Worth fixing upstream too: dependabot is opening these two exactly-pinned peers as separate PRs, which guarantees both are broken. They belong in one group.
vitest and @vitest/coverage-v8 pin each other as exact peers, so bumping only one leaves the tree unsatisfiable. Both are now ^5.0.3. vitest 5 also moved vite from a runtime dependency to a non-optional peer. Without it, `npm test` failed with ERR_MODULE_NOT_FOUND from vitest/dist, so vite is now an explicit devDependency. Verified locally on Node 24: - npm ci --legacy-peer-deps -> exit 0, tree valid and deduped - npm test -> 18 files, 175 tests passed - npm run test:coverage -> exit 0 (v8 provider) Refs #635
What
Upgrades the test toolchain as one unit:
vitest:4.1.11->5.0.3@vitest/coverage-v8:4.1.11->5.0.3vite: added as adevDependency(^8.3.2)Why the extra packages
vitestand@vitest/coverage-v8pin each other as exact peers. Dependabotopened the two halves as separate PRs (#635 and #636), which left each one
unsatisfiable on its own. #636 has been closed; this PR now carries both halves.
vitest5 also movedvitefrom a runtime dependency to a non-optional peer.Without it,
npm testfails:That failure was never visible because every CI run on this branch sat at
action_requiredand never executed.Verification (Node 24)
npm ci --legacy-peer-deps-> exit 0;npm lsshows a valid, deduped treenpm test-> 18 test files, 175 tests passednpm run test:coverage-> exit 0 with the v8 provider