Skip to content

chore(deps-dev): bump the development-dependencies group across 1 directory with 2 updates - #136

Merged
veillette merged 1 commit into
mainfrom
dependabot/npm_and_yarn/development-dependencies-12ebeab49c
Sep 28, 2026
Merged

veillette merged 1 commit into
mainfrom
dependabot/npm_and_yarn/development-dependencies-12ebeab49c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 2 updates in the / directory: vite and vitest.

Updates vite from 8.3.0 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Commits
  • 39ddf7c release: v8.3.1 (#23573)
  • f68c0d5 fix: handle server.ws: false in mergeConfig (#23511)
  • 6f831f9 fix(server): avoid reinitializing watcher when adding file after server close...
  • 04fc30a fix(sourcemap): skip URL source roots when injecting sources content (#23519)
  • 5f89433 fix(optimizer): resolve pending discovered dep processing on close before ini...
  • 63567c7 chore(optimizer): add debug log when waiting for dep before init (#23566)
  • e8990c4 fix(deps): update all non-major dependencies (#23537)
  • af7cdf6 refactor: replace find with some (#23554)
  • 39330f4 fix(optimizer): don't skip imports whose binding starts with type (#23540)
  • 9abd99b refactor: remove duplicate configurations (#23532)
  • Additional commits viewable in compare view

Updates vitest from 5.0.1 to 5.0.2

Release notes

Sourced from vitest's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub
Commits

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@dependabot
dependabot Bot requested a review from veillette as a code owner September 28, 2026 09:17
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@oxc-project/types 0.151.0 UnknownUnknown
npm/@rolldown/binding-android-arm-eabi 1.2.11 UnknownUnknown
npm/@rolldown/binding-android-arm64 1.2.11 UnknownUnknown
npm/@rolldown/binding-darwin-arm64 1.2.11 UnknownUnknown
npm/@rolldown/binding-darwin-x64 1.2.11 UnknownUnknown
npm/@rolldown/binding-freebsd-x64 1.2.11 UnknownUnknown
npm/@rolldown/binding-linux-arm-gnueabihf 1.2.11 UnknownUnknown
npm/@rolldown/binding-linux-arm64-gnu 1.2.11 UnknownUnknown
npm/@rolldown/binding-linux-arm64-musl 1.2.11 UnknownUnknown
npm/@rolldown/binding-linux-ppc64-gnu 1.2.11 UnknownUnknown
npm/@rolldown/binding-linux-s390x-gnu 1.2.11 UnknownUnknown
npm/@rolldown/binding-linux-x64-gnu 1.2.11 UnknownUnknown
npm/@rolldown/binding-linux-x64-musl 1.2.11 UnknownUnknown
npm/@rolldown/binding-openharmony-arm64 1.2.11 UnknownUnknown
npm/@rolldown/binding-win32-arm64-msvc 1.2.11 UnknownUnknown
npm/@rolldown/binding-win32-x64-msvc 1.2.11 UnknownUnknown
npm/@vitest/mocker 5.0.2 UnknownUnknown
npm/@vitest/spy 5.0.2 UnknownUnknown
npm/magic-string 1.4.2 🟢 5.2
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 5Found 16/30 approved changesets -- score normalized to 5
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
npm/rolldown 1.2.11 UnknownUnknown
npm/vite 8.3.1 🟢 6.9
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 9 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 8Found 20/23 approved changesets -- score normalized to 8
Token-Permissions🟢 7detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts⚠️ 1binaries present in source code
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST🟢 10SAST tool is run on all commits
npm/vitest 5.0.2 UnknownUnknown
npm/why-is-node-running 3.2.2 🟢 3.8
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 1Found 4/30 approved changesets -- score normalized to 1
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • package-lock.json

…ectory with 2 updates

Bumps the development-dependencies group with 2 updates in the / directory: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `vite` from 8.3.0 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-dev): bump the development-dependencies group with 2 updates chore(deps-dev): bump the development-dependencies group across 1 directory with 2 updates Sep 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/development-dependencies-12ebeab49c branch from 6559ae1 to 2dafa47 Compare September 28, 2026 12:17

@veillette veillette left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Dev-dependency patch bumps only: vite 8.3.0 → 8.3.1 and vitest 5.0.1 → 5.0.2. Required checks are green; only package.json and package-lock.json change.

@veillette
veillette merged commit b1e2942 into main Sep 28, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/development-dependencies-12ebeab49c branch September 28, 2026 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant