chore(deps-dev): bump vitest from 4.1.9 to 4.1.11 - #571
Conversation
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.9 to 4.1.11. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 4.1.11 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
seonghobae
left a comment
There was a problem hiding this comment.
Reality review found this Dependabot security delta is valid but not merge authority in its current form. Exact ee7677036311df66e66da42cf26fcb55bdd229a6 passes reviewer-ci and required Security Scan, but application CI 34307879575 fails the repository's schema-v3 lockfile change-control contract before install: .github/lockfile-change-policy.json is not rebound to current main@8108bae1128c20b92d79dacaf65c3d9e3d55b758, does not enumerate the exact changed package keys, and does not bind the before/after package-object digests. patch-validator-image also fails. This is a repair finding, not grounds to weaken or bypass the gate.
The existing security-owner lane #569/#568 additionally carries the hostile regression and deliberately updates both vitest and @vitest/coverage-v8 to the patched 4.1.11 line. Therefore keep this PR Draft and open while #569 incorporates the valid Dependabot resolution evidence plus an exact reviewed lockfile policy. Close #571 only after a normally merged successor has demonstrably inherited this package/lock delta and security evidence; do not use Dependabot rebase/recreate to erase current evidence.
seonghobae
left a comment
There was a problem hiding this comment.
Fresh exact-head review: this lane is not merge-ready and is not yet a verified successor to #569. Application CI 34307879575 fails at the repository's fail-closed verify lockfile change control step because this lockfile mutation does not carry the reviewed schemaVersion 3 .github/lockfile-change-policy.json bound to exact base 8108bae1128c20b92d79dacaf65c3d9e3d55b758; the regeneration and downstream install/test steps are therefore correctly skipped. Separately, this PR changes only package.json/package-lock.json: it does not inherit #569's test/vitest-security-lock.test.ts regression or #569's direct @vitest/coverage-v8 requirement bump, so closing #569 as superseded would lose valid delta/test evidence. Keep Draft. Repair the exact lockfile policy without weakening the gate, then require fresh unchanged-exact application CI/reviewer-ci/Security Scan/patch-validator-image GREEN. Only after independent complete inheritance is demonstrated may successor/closure semantics be considered.
seonghobae
left a comment
There was a problem hiding this comment.
Fresh successor review: keep this Draft and do not close #569 in its favor. This exact changes only the direct Vitest requirement/lock and does not inherit #569's direct @vitest/coverage-v8 requirement, CVE regression, explicit @rolldown/binding-wasm32-wasi static-validator contract, exact lockfile-change-policy evidence, or the hosted RED→repair lineage. #569's promoted 4.1.11 lock exposed a real patch-validator materialization RED because Rolldown 1.2.7 no longer implicitly carries the WASI binding; #569 now owns that causal repair. Re-evaluate succession only after a candidate independently proves complete inheritance and fresh unchanged-exact four-gate GREEN.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head dependency review confirms this bump is narrower than the owner repair and is not yet a safe successor.
| "esbuild": "0.28.1", | ||
| "typescript": "^5.9.0", | ||
| "vitest": "^4.1.9", | ||
| "vitest": "^4.1.11", |
There was a problem hiding this comment.
vitest만 4.1.11로 올리면 현재 Noema validator 계약을 완전히 승계하지 못합니다. 이 exact의 hosted image는 dependency materialization에서 이미 RED이고, owner repair #569는 같은 graph에서 드러난 Rolldown 1.2.7의 WASI binding 누락을 @rolldown/binding-wasm32-wasi@1.2.7 exact devDependency로 보완하며 @vitest/coverage-v8도 4.1.11 line에 맞추고 security/runtime regression과 lock-policy evidence를 함께 보존합니다. #569 protected integration의 완전 승계를 검증하기 전에는 이 PR을 successor/close 근거로 쓰지 마십시오.
|
Superseded by merged PR #569 (merge |
|
Looks like vitest is up-to-date now, so this is no longer needed. |
Dependabot proposes
vitest4.1.9 → 4.1.11, but this exact lane is not a verified successor of issue #568 / Draft #569.Current #571 exact is
ee7677036311df66e66da42cf26fcb55bdd229a6on protectedmain@8108bae1128c20b92d79dacaf65c3d9e3d55b758. reviewer-ci34307879552and Security Scan34307879706are SUCCESS, while application CI34307879575is FAILURE and patch-validator-image34307879564/ job102328247794is a terminal reality RED. The image job passed exact checkout, stale-head refusal and toolchain setup, then failed atMaterialize exact patch-validator dependenciesbefore Buildx/image/smoke/SBOM. The 4.1.11/Vite graph advances Rolldown to 1.2.7 without preserving Noema's required WASI-only validator binding.Draft #569 has already carried that RED through the minimal causal repair on current exact
626be6a917a54c17f7a0c26beb40747a24e73299: it additionally advances direct@vitest/coverage-v8, explicitly pins@rolldown/binding-wasm32-wasi@1.2.7, adds a security/runtime regression, promotes the hosted canonical lock artifact without synthesized integrity metadata, and binds the final lock delta to the exact protected base in lockfile-change policy evidence. #569 currently has application CI, reviewer-ci and required Security Scan GREEN while its exact image build is still running.Keep this PR Draft and open until #569 normally integrates. Only after the resulting protected main independently proves that every valid #571 delta is present may this lane be closed as fully superseded. Do not invoke Dependabot rebase/recreate to overwrite reviewed owner evidence, and do not use this PR's narrower dependency bump to replace #569's security/runtime contract.