Skip to content

fix: pin vitest to 5.0.1 and override it to fix npm 10 install crash - #533

Merged
Tony133 merged 3 commits into
fastify:mainfrom
Puppo:fix/vitest-5-npm10
Oct 7, 2026
Merged

Tony133 merged 3 commits into
fastify:mainfrom
Puppo:fix/vitest-5-npm10

Conversation

@Puppo

@Puppo Puppo commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Motivation

A fresh npm i on main currently fails on Node 22 (npm 10):

npm error Cannot read properties of null (reading 'edgesOut')

Root cause

  • vite@8, a peer of vitest, has an optional peer @vitejs/devtools. That package requires @vitejs/devtools-vitest, which declares a peer of vitest: "*".
  • npm 10's arborist resolves that vitest@* on its own. Now that vitest 5 is latest, it picks vitest@5.x, which pulls @vitest/browser-playwright@5.x, which in turn requires vitest@5.x. That clashes with the root vitest@4.1.11.
  • Instead of reporting a peer conflict, npm 10 crashes in #loadPeerSet (build-ideal-tree.js). npm 11 (Node 24/26) handles the same tree correctly.

Nothing in this repo changed. It started when vitest 5 became latest on the registry.

Why bumping vitest alone (#531) is not enough

On Node 20, npm prefers engine-compatible versions. vitest 5 requires Node ^22.12.0 || ^24.0.0 || >=26.0.0, so there vitest@* resolves to 4.1.11. With vitest 5 at the root, that is the same conflict in reverse, and npm 10 crashes the same way.

Fix

  • Pin vitest to 5.0.1.
  • Add "overrides": { "vitest": "5.0.1" } so every vitest in the tree, including the one requested through the optional peer chain, resolves to the same version. This removes the conflict on every Node version.
  • The version is exact rather than a range so npm 10 and npm 11 install the same thing. npm 11 honours min-release-age=7 from .npmrc and npm 10 ignores it, so a ^5 range would give different versions depending on the npm version.

Note

The override has to match the vitest devDependency exactly on future bumps; otherwise npm rejects the install with an override conflict. It can be removed once Node 20 is dropped from the CI matrix. vitest 5, borp and tstyche already declare Node >= 22 in their engines.

Verification

Clean npm i --ignore-scripts + npm test on macOS:

Node npm vitest installed Install Tests
20.20.2 10.8.2 5.0.1 ok (EBADENGINE warnings) pass
22.23.3 10.9.9 5.0.1 ok pass
24.21.0 11.19.0 5.0.1 ok pass
26.5.1 11.17.0 5.0.1 ok pass

Without the override, Node 20 still crashes with the edgesOut error; 22, 24 and 26 install fine.

Supersedes #531.

Checklist

Puppo added 2 commits October 5, 2026 17:18
npm 10 (bundled with Node 20 and 22) crashes with
"Cannot read properties of null (reading 'edgesOut')" when vite's
optional peer chain (@vitejs/devtools -> @vitejs/devtools-vitest ->
vitest@*) resolves to a different vitest major than the root one.
Overriding vitest keeps a single version in the tree.

Use ^5.0.1 so npm 11 installs respect min-release-age=7.
@Puppo Puppo mentioned this pull request Oct 5, 2026
4 tasks
Comment thread package.json Outdated
@Puppo
Puppo requested a review from Eomm October 6, 2026 13:26
@Puppo Puppo changed the title fix: bump vitest to v5 and override it to fix npm 10 install crash fix: pin vitest to 5.0.1 and override it to fix npm 10 install crash Oct 6, 2026
@Tony133
Tony133 merged commit eac381a into fastify:main Oct 7, 2026
19 checks passed
@Puppo
Puppo deleted the fix/vitest-5-npm10 branch October 7, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants