Skip to content

chore(deps-dev): bump vitest from 3.2.6 to 4.1.11 - #1121

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.11
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown

Bumps vitest from 3.2.6 to 4.1.11.

Release notes

Sourced from vitest's releases.

v4.1.11

   🐞 Bug Fixes

    View changes on GitHub

v4.1.10

   🐞 Bug Fixes

    View changes on GitHub

v4.1.9

🐞 Bug Fixes

View changes on GitHub

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

... (truncated)

Commits
  • 9bd8d46 chore: release v4.1.11 (#10995)
  • 9851dbc fix(browser): trigger playwright/chromium gc on lower disk availability [back...
  • db616d2 chore: release v4.1.10 (#10718)
  • bae52b5 fix(vm): fix external module resolve error with deps optimizer query for enco...
  • a7a61e7 chore: release v4.1.9 (#10598)
  • 934b0f5 fix(pool): prevent test run hang on worker crash (#10543) [backport to v4] (#...
  • 7fb2965 fix(browser): wait for orchestrator readiness before resolving browser sessio...
  • a518019 fix: fix importOriginal with optimizer and query import [backport to v4] (#...
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Greptile Summary

This PR upgrades the repository's shared Vitest development dependency from 3.2.6 to 4.1.11 and refreshes its transitive lockfile entries.

  • Updates the Vitest package family and associated assertion, formatting, runner, snapshot, and utility dependencies.
  • Removes Vitest 3's vite-node dependency, which conflicts with an existing eval test helper that directly resolves its executable.

Confidence Score: 4/5

This PR is not safe to merge until the eval test helper is migrated away from the removed vite-node dependency.

The upgraded dependency graph no longer installs vite-node, while the eval suite synchronously resolves its executable before spawning a child process, causing that suite to fail.

Files Needing Attention: package.json, packages/evals/test/eval-durable.test.ts

Important Files Changed

Filename Overview
package.json Upgrades Vitest across a major-version boundary, exposing an incompatible direct reliance on its former vite-node dependency.
pnpm-lock.yaml Resolves Vitest 4.1.11 and its new transitive graph, notably removing vite-node.

Fix all with Greploop Fix All in Claude Code

Prompt To Fix All With AI
### Issue 1
package.json:49
**Vitest Upgrade Breaks Eval Tests**

Vitest 4 no longer installs `vite-node`, but `packages/evals/test/eval-durable.test.ts` still resolves `vite-node/vite-node.mjs` through Vitest before starting a child process. Running the `@ultrafuzz/evals` test suite will therefore fail with a module-resolution error. Update the helper to use an execution path supported by Vitest 4.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Reviews (1): Last reviewed commit: "chore(deps-dev): bump vitest from 3.2.6 ..." | Re-trigger Greptile

Greptile also left 1 inline comment on this PR.

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.6 to 4.1.11.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedvitest@​3.2.6 ⏵ 4.1.1198 +1100 +279 +199 +2100

View full report

Comment thread package.json
"typescript": "^5.8.3",
"typescript-eslint": "^8.62.1",
"vitest": "^3.2.4",
"vitest": "^4.1.11",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Vitest Upgrade Breaks Eval Tests

Vitest 4 no longer installs vite-node, but packages/evals/test/eval-durable.test.ts still resolves vite-node/vite-node.mjs through Vitest before starting a child process. Running the @ultrafuzz/evals test suite will therefore fail with a module-resolution error. Update the helper to use an execution path supported by Vitest 4.

Prompt To Fix With AI
This is a comment left during a code review.
Path: package.json
Line: 49

Comment:
**Vitest Upgrade Breaks Eval Tests**

Vitest 4 no longer installs `vite-node`, but `packages/evals/test/eval-durable.test.ts` still resolves `vite-node/vite-node.mjs` through Vitest before starting a child process. Running the `@ultrafuzz/evals` test suite will therefore fail with a module-resolution error. Update the helper to use an execution path supported by Vitest 4.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants