Skip to content

build(deps): bump vitest and @vitest/coverage-v8 to 5.0.3 in /web - #635

Open
dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/npm_and_yarn/web/vitest-5.0.1
Open

dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/npm_and_yarn/web/vitest-5.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

What

Upgrades the test toolchain as one unit:

  • vitest: 4.1.11 -> 5.0.3
  • @vitest/coverage-v8: 4.1.11 -> 5.0.3
  • vite: added as a devDependency (^8.3.2)

Why the extra packages

vitest and @vitest/coverage-v8 pin each other as exact peers. Dependabot
opened the two halves as separate PRs (#635 and #636), which left each one
unsatisfiable on its own. #636 has been closed; this PR now carries both halves.

vitest 5 also moved vite from a runtime dependency to a non-optional peer.
Without it, npm test fails:

Error [ERR_MODULE_NOT_FOUND]: Cannot find package 'vite' imported from
  web/node_modules/vitest/dist/chunks/index.DpLw24bj.js

That failure was never visible because every CI run on this branch sat at
action_required and never executed.

Verification (Node 24)

  • npm ci --legacy-peer-deps -> exit 0; npm ls shows a valid, deduped tree
  • npm test -> 18 test files, 175 tests passed
  • npm run test:coverage -> exit 0 with the v8 provider

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.11 to 5.0.1.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file frontend labels Sep 21, 2026
@vercel

vercel Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-web-doc-resolover Ready Ready Preview Oct 1, 2026 5:13pm UTC

@codacy-production

codacy-production Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity

Metric Results
Complexity 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@cline-cloud

cline-cloud Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🔥 Roast: half an upgrade, and a CI that has never once run

1. It is one half of a two-part bump

vitest goes ^4.1.11 → ^5.0.1, but @vitest/coverage-v8 is left at ^4.1.11. That package's peer dependencies are exact pins:

$ npm view @vitest/coverage-v8@4.1.11 peerDependencies
{ vitest: '4.1.11', '@vitest/browser': '4.1.11' }

So coverage-v8@4.1.11 demands vitest@4.1.11 exactly, while this PR moves vitest to 5. The tree is unsatisfiable. #636 is the mirror image (coverage-v8 → 5, vitest left at 4) and I am closing it as the stale, conflicting half; the pair must land as one PR.

web/.npmrc sets legacy-peer-deps=true, so npm install will not tell you any of this. It will succeed and be wrong.

2. BLOCKED does not mean "CI failed", it means "CI never ran"

Across 40 workflow runs on this branch:

conclusion count
action_required 32
success 7
skipped 1

Every one of those 7 successes is CodeQL, Codacy or Vercel — third-party apps. Every CI, CI UI, Commit Lint, Security Scan, Integration Tests and Gitleaks run is parked at action_required, waiting for a workflow approval nobody gave.

The consequence is that the four gates DEPENDABOT_AUTO_MERGE_SOP.md step 4 requires — Lint, Sample Run, Quality Gate, E2E Tests (web) — have never executed, on any commit, in nine days. This PR has been sitting in the queue on the strength of a green CodeQL badge that says nothing about whether vitest 5 actually runs the suite.

Given that web/tests/ holds 20+ test files and web/vitest.config.ts configures globals, environment: "node" and a v8 coverage provider, "a major test-runner upgrade that has never been executed" is the whole risk profile of this PR.

3. What is actually fine

  • vitest@5.0.1 engines require Node ^22.12.0 || ^24.0.0 || >=26.0.0; CI pins node-version: '22', which resolves to latest 22.x. No problem there.
  • Per DEPENDABOT_AUTO_MERGE_SOP.md, update-type: semver-major is intentional human-review routing, not a bug. Correct that this is waiting on a person rather than auto-merging.

Verdict

Keep — but it is not mergeable as-is and it is not "blocked on review", it is unvalidated.

To land it:

  1. Add @vitest/coverage-v8 → ^5.0.1 in the same PR (this absorbs build(deps-dev): bump @vitest/coverage-v8 from 4.1.11 to 5.0.1 in /web #636).
  2. Approve the parked workflow runs so the web suite actually executes.
  3. Confirm the 20+ files in web/tests/ and the tests/e2e/** exclusion still behave on vitest 5.

Worth fixing upstream too: dependabot is opening these two exactly-pinned peers as separate PRs, which guarantees both are broken. They belong in one group.

vitest and @vitest/coverage-v8 pin each other as exact peers, so bumping
only one leaves the tree unsatisfiable. Both are now ^5.0.3.

vitest 5 also moved vite from a runtime dependency to a non-optional
peer. Without it, `npm test` failed with ERR_MODULE_NOT_FOUND from
vitest/dist, so vite is now an explicit devDependency.

Verified locally on Node 24:
- npm ci --legacy-peer-deps -> exit 0, tree valid and deduped
- npm test -> 18 files, 175 tests passed
- npm run test:coverage -> exit 0 (v8 provider)

Refs #635
@cline-cloud cline-cloud Bot changed the title build(deps-dev): bump vitest from 4.1.11 to 5.0.1 in /web build(deps): bump vitest and @vitest/coverage-v8 to 5.0.3 in /web Oct 1, 2026

This branch was successfully deployed

1 active deployment
Preview — 8e999aab Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file frontend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants