Skip to content

build(deps-dev): bump @vitest/coverage-v8 from 4.1.11 to 5.0.1 in /web - #636

Closed
dependabot[bot] wants to merge 5 commits into
mainfrom
dependabot/npm_and_yarn/web/vitest/coverage-v8-5.0.1
Closed

dependabot[bot] wants to merge 5 commits into
mainfrom
dependabot/npm_and_yarn/web/vitest/coverage-v8-5.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Automated dependency update from dependabot.

Bumps a grouped set of packages (see commit history for the full list of version changes).

Bumps [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) from 4.1.11 to 5.0.1.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/coverage-v8)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file frontend labels Sep 21, 2026
@vercel

vercel Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-web-doc-resolover Ready Ready Preview Sep 29, 2026 12:39am UTC

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity

Metric Results
Complexity 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@cline-cloud

cline-cloud Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🔥 Roast: the wrong half of a two-part upgrade, 8 days stale, never once executed

1. It cannot resolve

@vitest/coverage-v8@5.0.1 declares exact peer pins:

$ npm view @vitest/coverage-v8@5.0.1 peerDependencies
{ vitest: '5.0.1', '@vitest/browser': '5.0.1' }

This PR bumps @vitest/coverage-v8 to ^5.0.1 and leaves vitest at ^4.1.11 in the same package.json. The resulting tree is unsatisfiable by construction: coverage-v8@5 demands vitest@5.0.1 exactly, and vitest is not moving.

You will not notice, because web/.npmrc sets legacy-peer-deps=true. The install succeeds and the tree is quietly wrong. That setting is doing exactly what it was added to do, which is hide this class of problem.

#635 is the mirror image — vitest bumped to 5, coverage-v8 left at 4. Both halves are broken alone. They need to be one PR.

2. It is stale and it conflicts

Base is 81d40b2, which predates the merged #644 npm-deps batch. Result: CONFLICTING / DIRTY since 2026-09-21 — eight days.

DEPENDABOT_AUTO_MERGE_SOP.md step 5 is explicit that a dependabot PR "must not be permanently dirty", and prescribes gh pr update-branch if it stays dirty for more than 2 hours. It has been dirty for ~190 hours. The autoupdate sweep is not doing its job, or nobody looked.

3. It has never been tested

Of 40 workflow runs on this branch:

conclusion count
action_required 32
success 7
skipped 1

Every success is CodeQL / Codacy / Vercel — none of them the repo's own gates. Every CI, CI UI, Commit Lint, Security Scan, Integration Tests and Gitleaks run is parked at action_required, waiting for an approval that never came. So Lint, Sample Run, Quality Gate and E2E Tests (web) have not executed once in eight days. The green badges on this PR are third-party apps, not validation.

Verdict

It cannot merge (conflicting), it would not work if it did (unsatisfiable peers), and it has never been run. Merging it would deliver no upgrade to the test runner while breaking the coverage tool.

Verdict: no impact — closing. The work is tracked in #635, which is based on current main; the fix is a single PR bumping vitest and @vitest/coverage-v8 to 5.0.1 together. Dependabot will regenerate this if it is still wanted.

@cline-cloud

cline-cloud Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Closing: no impact. Unsatisfiable peer pin (@vitest/coverage-v8@5.0.1 requires vitest@5.0.1 exactly, while this leaves vitest at 4.1.11), stale/conflicting base for 8 days, and 32 of 40 CI runs never executed (action_required). Superseded by #635 — the correct fix is a single combined bump of vitest + @vitest/coverage-v8 to 5.0.1. Details in the review comment above.

@cline-cloud cline-cloud Bot closed this Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/web/vitest/coverage-v8-5.0.1 branch October 1, 2026 16:13

This branch was successfully deployed

1 active deployment
Preview — ac1174fa Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file frontend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants