Skip to content

chore(deps): bump vite from 8.0.13 to 8.0.16 in the npm_and_yarn group across 1 directory - #42

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-bed0206944
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-bed0206944

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the / directory: vite.

Updates vite from 8.0.13 to 8.0.16

Release notes

Sourced from vite's releases.

v8.0.16

Please refer to CHANGELOG.md for details.

v8.0.15

Please refer to CHANGELOG.md for details.

v8.0.14

Please refer to CHANGELOG.md for details.

Changelog

Sourced from vite's changelog.

8.0.16 (2026-06-01)

Bug Fixes

8.0.15 (2026-06-01)

Features

Bug Fixes

  • capitalize error messages and remove spurious space in parse error (#22488) (85a0eff)
  • deps: update all non-major dependencies (#22511) (2686d7d)
  • dev: fix html-proxy cache key mismatch for /@fs/ HTML paths (#21762) (47c4213)
  • glob: error on relative glob in virtual module when no files match (#22497) (5c8e98f)
  • optimizer: close the rolldown bundle when write() rejects (#22528) (e3cfb9d)
  • resolve: provide onWarn for viteResolvePlugin in JS plugin containers (#22509) (40985f1)

Miscellaneous Chores

Code Refactoring

8.0.14 (2026-05-21)

Features

Bug Fixes

  • deps: update all non-major dependencies (#22471) (98b8163)
  • dev: handle errors when sending messages to vite server (#22450) (e8e9a34)
  • html: handle trailing slash paths in transformIndexHtml (#22480) (5d94d1b)
  • optimizer: pass oxc jsx options to transformSync in dependency scan (#22342) (b3132da)

Miscellaneous Chores

  • deps: update rolldown-related dependencies (#22470) (7cb728e)
  • remove irrelevant commits from changelog (2c69495)

Code Refactoring

  • glob: do not rewrite import path for absolute base (#22310) (0ae2844)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the / directory: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).


Updates `vite` from 8.0.13 to 8.0.16
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.0.16
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 29, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
livemark c0f20ea Commit Preview URL

Branch Preview URL
Jun 29 2026, 03:23 PM

@claude

claude Bot commented Jun 29, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 1m 35s —— View job


PR Review: Vite 8.0.13 → 8.0.16

  • Gather context
  • Analyze changelog for security relevance
  • Review changed files
  • Check CI status
  • Post findings

Summary

This PR bumps vite from 8.0.13 → 8.0.16 and also silently bumps vite-plus from 0.1.24 → 0.2.1 (not mentioned in the PR title). The vite upgrade includes meaningful security patches, but the vite-plus bump introduces a breaking version mismatch that causes CI to fail.


CI Status

Job Result
test (ubuntu-latest) ❌ Failure
test (windows-latest) Cancelled
test (macos-latest) Cancelled
scan ✅ Pass

Root cause of CI failure: vite-plus@0.2.1 now bundles vitest@4.1.9, but @vitest/coverage-v8@4.1.6 remains pinned in package.json. The new version of vite-plus enforces a strict version match between the coverage provider and test runner:

Error: vite-plus bundles vitest@4.1.9, but @vitest/coverage-v8@4.1.6 is installed.
A coverage provider must match the test runner version.
Pin @vitest/coverage-v8 to 4.1.9 in your dependencies.

Required fix: Update @vitest/coverage-v8 from 4.1.6 → 4.1.9 in package.json.


Security Analysis (OWASP Top 10)

Severity: LOW — security patches applied (not introduced)

The vite 8.0.16 changelog includes two security-relevant fixes:

  • Path traversal / Broken Access Control (OWASP A01): reject UNC paths for launch-editor-middleware (#22571) and reject windows alternate paths (#22572). These prevent path traversal via UNC paths (\\server\share) and Windows alternate data streams/device paths in the dev server's launch-editor middleware.

These fixes only affect the development server (not production builds), but upgrading to 8.0.16 is the correct call to pick them up.

No other OWASP concerns identified:

  • No hardcoded secrets or credentials
  • No new cryptographic changes
  • No SSRF, SQLi, XSS, or CSRF surface changes
  • No unsafe deserialization
  • The lockfile integrity hashes are present and consistent

Code Quality

Medium concern — undisclosed additional dependency bump

vite-plus was bumped from 0.1.24 → 0.2.1 alongside this PR, but this is not reflected in the PR title or description. This is likely because dependabot grouped them, but it's worth noting since the vite-plus bump is what causes the test failure, not the vite bump itself.

The lockfile diff is large (+710/-464 lines) but consistent with vite and vite-plus resolution chain updates — no unexpected packages introduced.


Recommendation

Do not merge as-is — CI is failing. The fix is straightforward:

Update @vitest/coverage-v8 in package.json from 4.1.6 to 4.1.9 to match the vitest version bundled by vite-plus@0.2.1. Fix this →

Once that is fixed and CI passes, this PR is safe to merge — the vite upgrade contains worthwhile security patches.

@roll roll closed this Jul 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-bed0206944 branch July 1, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant