Skip to content

chore(deps-dev): bump vitest from 4.1.9 to 4.1.11 - #571

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.11
Closed

chore(deps-dev): bump vitest from 4.1.9 to 4.1.11#571
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Dependabot proposes vitest 4.1.9 → 4.1.11, but this exact lane is not a verified successor of issue #568 / Draft #569.

Current #571 exact is ee7677036311df66e66da42cf26fcb55bdd229a6 on protected main@8108bae1128c20b92d79dacaf65c3d9e3d55b758. reviewer-ci 34307879552 and Security Scan 34307879706 are SUCCESS, while application CI 34307879575 is FAILURE and patch-validator-image 34307879564 / job 102328247794 is a terminal reality RED. The image job passed exact checkout, stale-head refusal and toolchain setup, then failed at Materialize exact patch-validator dependencies before Buildx/image/smoke/SBOM. The 4.1.11/Vite graph advances Rolldown to 1.2.7 without preserving Noema's required WASI-only validator binding.

Draft #569 has already carried that RED through the minimal causal repair on current exact 626be6a917a54c17f7a0c26beb40747a24e73299: it additionally advances direct @vitest/coverage-v8, explicitly pins @rolldown/binding-wasm32-wasi@1.2.7, adds a security/runtime regression, promotes the hosted canonical lock artifact without synthesized integrity metadata, and binds the final lock delta to the exact protected base in lockfile-change policy evidence. #569 currently has application CI, reviewer-ci and required Security Scan GREEN while its exact image build is still running.

Keep this PR Draft and open until #569 normally integrates. Only after the resulting protected main independently proves that every valid #571 delta is present may this lane be closed as fully superseded. Do not invoke Dependabot rebase/recreate to overwrite reviewed owner evidence, and do not use this PR's narrower dependency bump to replace #569's security/runtime contract.

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.9 to 4.1.11.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@seonghobae
seonghobae marked this pull request as draft September 9, 2026 03:54

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reality review found this Dependabot security delta is valid but not merge authority in its current form. Exact ee7677036311df66e66da42cf26fcb55bdd229a6 passes reviewer-ci and required Security Scan, but application CI 34307879575 fails the repository's schema-v3 lockfile change-control contract before install: .github/lockfile-change-policy.json is not rebound to current main@8108bae1128c20b92d79dacaf65c3d9e3d55b758, does not enumerate the exact changed package keys, and does not bind the before/after package-object digests. patch-validator-image also fails. This is a repair finding, not grounds to weaken or bypass the gate.

The existing security-owner lane #569/#568 additionally carries the hostile regression and deliberately updates both vitest and @vitest/coverage-v8 to the patched 4.1.11 line. Therefore keep this PR Draft and open while #569 incorporates the valid Dependabot resolution evidence plus an exact reviewed lockfile policy. Close #571 only after a normally merged successor has demonstrably inherited this package/lock delta and security evidence; do not use Dependabot rebase/recreate to erase current evidence.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh exact-head review: this lane is not merge-ready and is not yet a verified successor to #569. Application CI 34307879575 fails at the repository's fail-closed verify lockfile change control step because this lockfile mutation does not carry the reviewed schemaVersion 3 .github/lockfile-change-policy.json bound to exact base 8108bae1128c20b92d79dacaf65c3d9e3d55b758; the regeneration and downstream install/test steps are therefore correctly skipped. Separately, this PR changes only package.json/package-lock.json: it does not inherit #569's test/vitest-security-lock.test.ts regression or #569's direct @vitest/coverage-v8 requirement bump, so closing #569 as superseded would lose valid delta/test evidence. Keep Draft. Repair the exact lockfile policy without weakening the gate, then require fresh unchanged-exact application CI/reviewer-ci/Security Scan/patch-validator-image GREEN. Only after independent complete inheritance is demonstrated may successor/closure semantics be considered.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh successor review: keep this Draft and do not close #569 in its favor. This exact changes only the direct Vitest requirement/lock and does not inherit #569's direct @vitest/coverage-v8 requirement, CVE regression, explicit @rolldown/binding-wasm32-wasi static-validator contract, exact lockfile-change-policy evidence, or the hosted RED→repair lineage. #569's promoted 4.1.11 lock exposed a real patch-validator materialization RED because Rolldown 1.2.7 no longer implicitly carries the WASI binding; #569 now owns that causal repair. Re-evaluate succession only after a candidate independently proves complete inheritance and fresh unchanged-exact four-gate GREEN.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head dependency review confirms this bump is narrower than the owner repair and is not yet a safe successor.

Comment thread package.json
"esbuild": "0.28.1",
"typescript": "^5.9.0",
"vitest": "^4.1.9",
"vitest": "^4.1.11",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

vitest만 4.1.11로 올리면 현재 Noema validator 계약을 완전히 승계하지 못합니다. 이 exact의 hosted image는 dependency materialization에서 이미 RED이고, owner repair #569는 같은 graph에서 드러난 Rolldown 1.2.7의 WASI binding 누락을 @rolldown/binding-wasm32-wasi@1.2.7 exact devDependency로 보완하며 @vitest/coverage-v8도 4.1.11 line에 맞추고 security/runtime regression과 lock-policy evidence를 함께 보존합니다. #569 protected integration의 완전 승계를 검증하기 전에는 이 PR을 successor/close 근거로 쓰지 마십시오.

@seonghobae

Copy link
Copy Markdown
Contributor

Superseded by merged PR #569 (merge be7df55), verified complete inheritance: this lane's valid delta (vitest requirement ^4.1.9 -> ^4.1.11) is fully contained in #569's merged delta, which additionally carries @vitest/coverage-v8@^4.1.11, the canonical regenerated lock (vitest/@vitest/mocker/coverage all at 4.1.11), the reviewed lockfile change policy, the explicit WASI binding pin, and the test/vitest-security-lock.test.ts regression gate. This branch's lock artifact is stale-base and policy-nonconforming, so it cannot integrate independently. Closing as superseded; branch kept per precedent (#563/#562). After close, Dependabot should observe vitest 4.1.11 already on protected main and stay quiet.

@dependabot @github

dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Looks like vitest is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 9, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/vitest-4.1.11 branch September 9, 2026 06:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant