Skip to content

build(deps-dev): bump vitest from 4.1.11 to 5.0.0 in the all-dependencies group - #45

Merged
stephendolan merged 2 commits into
mainfrom
dependabot/npm_and_yarn/all-dependencies-4b52c90628
Sep 29, 2026
Merged

stephendolan merged 2 commits into
mainfrom
dependabot/npm_and_yarn/all-dependencies-4b52c90628

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Verification (vitest 4.1.11 → 5.0.x)

Added commit 46ada79: regenerated bun.lock. Dependabot bumped package.json only, so bun install --frozen-lockfile failed on the PR head ("lockfile had changes, but lockfile is frozen"), and a plain bun install would have rewritten the lockfile silently. The lockfile now resolves vitest@5.0.2; the old lock was on 4.0.16.

Why the original green check didn't prove anything: CI runs bun install (not frozen) and bun test (bun's native runner, which remaps vitest imports to bun:test). CI never executes vitest, so a vitest major can't break CI either way.

Local results on 46ada79 (clean node_modules, node 24.14.1, bun 1.3.14):

Command Result
bun install --frozen-lockfile ok
bun run typecheck 0 errors
bun run lint 0 warnings, 0 errors
bun run build ok
bun run test (vitest v5.0.2) 3 files, 24/24 passed
bun test 24 pass, 0 fail

The baseline on main (vitest 4.0.16) was also 24/24 under both runners, and the same 24 tests ran under v5.

Breaking-change review: the tests only use describe/it/expect/beforeAll, with no vitest config file, mocks, test.each, sequential, expect.poll, snapshots, reporters, or browser mode. vitest 5 requires Node ≥ 22, which already matches engines.node >=22.12.0. None of the listed breaking changes affect this repo.


Bumps the all-dependencies group with 1 update: vitest.

Updates vitest from 4.1.11 to 5.0.0

Release notes

Sourced from vitest's releases.

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits
  • f441c6f chore: release v5.0.0 (#11130)
  • d46a747 fix: treat test.describe as a suite during static collection (#11128)
  • 584cf30 fix: add a warning if inline project has duplicate plugins due to unexpected ...
  • f08ce4b fix: apply queued mocks from doMock() in queue order (fixes #10706) (#11127)
  • 897f51f chore: release v5.0.0-rc.4 (#11107)
  • 1339b06 chore(deps): update all non-major dependencies (#11104)
  • 51e9494 feat!: parse files statically in vitest list by default (#11088)
  • 2122ffd fix: propagate --maxWorkers to projects (#11102)
  • dc10f5f fix(browser): report the action error when a task times out (#11101)
  • d4fe198 feat: promote clearCache out of experimental (#11086)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-dependencies group with 1 update: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `vitest` from 4.1.11 to 5.0.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
Dependabot bumps package.json but not bun.lock in this repo, so
`bun install --frozen-lockfile` fails on the PR head and a plain
`bun install` silently rewrites the lockfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@stephendolan
stephendolan merged commit df6460b into main Sep 29, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/all-dependencies-4b52c90628 branch September 29, 2026 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant