Skip to content

chore(deps): Update dependency vitest to v5 - #186

Merged
looptroop-ai merged 3 commits into
mainfrom
renovate/major-vitest-monorepo
Sep 23, 2026
Merged

looptroop-ai merged 3 commits into
mainfrom
renovate/major-vitest-monorepo

Conversation

@renovate

@renovate renovate Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
vitest (source) ^4.1.11 → ^5.0.1 age confidence

Release Notes

vitest-dev/vitest (vitest)

v5.0.1

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v5.0.0

Compare Source

   🚨 Breaking Changes
   🚀 Features
   🐞 Bug Fixes

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Bucharest)

  • Branch creation
    • Between 12:00 AM and 05:59 AM (* 0-5 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file major Major version update, needs dashboard approval labels Sep 23, 2026
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9f722c04-6cd2-4db9-a3a3-abbf49abf7c2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@deepsource-io

deepsource-io Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in d3c03d5...47fc19c on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Sep 23, 2026 1:46p.m. Review ↗
JavaScript Sep 23, 2026 1:46p.m. Review ↗
Shell Sep 23, 2026 1:46p.m. Review ↗
Secrets Sep 23, 2026 1:46p.m. Review ↗
CSS Sep 23, 2026 1:46p.m. Review ↗
PowerShell Sep 23, 2026 1:46p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@socket-security

socket-security Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​vitest@​4.1.11 ⏵ 5.0.198 +110079 +198100

View full report

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from e77f71d to bf51f84 Compare September 23, 2026 05:01
@kilo-code-bot

kilo-code-bot Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

The previous findings from this PR are resolved by commit 47fc19c: a changelog entry was added under the Changed section documenting the vitest 5 upgrade, and clearMocks: true is now explicitly stated in the root test config of vitest.config.ts (inherited by all four projects via extends: true), so the v5 mock-clearing default is chosen rather than implicit.

Files Reviewed (4 files)
  • package.json - vitest version bump from ^4.1.11 to ^5.0.1 (intended change)
  • package-lock.json - generated lockfile update (no issues)
  • CHANGELOG.md - documents the vitest 5 upgrade under the Changed section
  • vitest.config.ts - explicitly sets clearMocks: true at root test config, inherited by all projects via extends: true
Previous Review Summaries (2 snapshots, latest commit bf51f84)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit bf51f84)

This review did not finish. The model reached its output limit before it
could write the review — a reasoning model can spend the whole budget thinking.
Re-run the review, or lower the model's thinking effort, and it should get
further. Any inline comments below are from an earlier review.

Previous review (commit bf51f84)

Status: No Issues Found | Recommendation: Merge

Files Reviewed (2 files)
  • package.json - vitest dependency upgrade ^4.1.11 → ^5.0.1 (intended change, no issues)
  • package-lock.json - generated lock file accompanying the dependency upgrade

Reviewed by free · Input: 0 · Output: 0 · Cached: 0

@looptroop-ai

looptroop-ai commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Command Code — findings and corrections.

1. [Medium] v5 turns clearMocks ON by default — the largest behavioural surface in this upgrade, green but unpinned

The migration guide lists "clearMocks Is Enabled by Default". This repository never sets it (grep -rn clearMocks vitest.config.ts src server tests scripts → 0 hits), while 157 test files use toHaveBeenCalled*, and src/test/setup.ts:36-44 installs module-scope vi.fn() stubs (scrollIntoView, scrollTo, …) that previously survived across tests. Mitigating evidence: two complete suite runs pass at this exact SHA with deterministic file order, so nothing currently depends on cross-test mock history.

That is empirical coverage of today's order, not a contract. Either pin test.clearMocks: false in vitest.config.ts to preserve the old semantics explicitly, or set it to true deliberately and accept the new rule — leaving it implicit means the next person who writes a stateful vi.fn() inherits a behaviour change nobody chose.

2. Status now: CLEAN — the earlier BLOCKED was transient

All eleven required contexts pass at head bf51f84, mergeable_state is CLEAN, and the branch is 0 commits behind main; zero checks have failed at any observation point. The blocker was Test (windows-latest, toolchain floor) still pending — and because ci.yml:3-7 triggers both on: push and on: pull_request with concurrency groups that never cancel each other, every check appears twice and a required job on the slower second run re-gates the PR after the first was green. The same mechanism explains #183's BLOCKED.

3. Runtime and peer compatibility — verified on every Node number this repo uses

npm view vitest@5.0.1 engines → ^22.12.0 || ^24.0.0 || >=26.0.0 (v4 allowed ^20 || ^22 || >=24, so Node 20 and 22.0–22.11 are dropped — no lane uses them). Satisfied by main's floor 24.21.0, by open PR #181's floor 24.18.0, and by the 26/26.9.0 lanes. Peer vite: '^6.4.0 || ^7.0.0 || ^8.0.0' accepts both ^8.2.2 (today) and ^8.3.0 (#184), so either merge order yields a satisfiable peer set — there is no wrong-order trap. @types/node peer ^22.0.0 || >=24.0.0 is met by #183's 24.13.x. vitest is a devDependency, so no user-facing engines promise is touched.

4. What actually moved in the lockfile — correcting an easy misreading

vitest ^4.1.11 → ^5.0.1 and @vitest/mocker 4.1.11 → 5.0.1, while six @vitest/* internals — expect, pretty-format, runner, snapshot, spy, utils — are deleted outright (vitest 5 bundles its own assertions instead of depending on @vitest/expect); there are no corresponding + "node_modules/@vitest/…" lines. This repo never installed @vitest/coverage-*, @vitest/ui or the browser packages, so the partial-satellite-bump failure cannot occur — but note that any future @vitest/coverage-v8 must be exactly 5.0.1, since it peers vitest: 5.0.1.

Transitive majors ride along: tinybench 2.9.0 → 6.1.4, magic-string 0.30.21 → 1.4.1 (two nested copies), plus removals of pathe, tinyrainbow, @standard-schema/spec. All dev-only — verify:package, verify:no-native-addons and licenses:check are green, and THIRD-PARTY-NOTICES.md is correctly untouched. Rollback note: the revert stays a clean two-file change only until a sibling PR merges or the Monday–Wednesday lockFileMaintenance re-resolves ~459 transitive packages over the same lock regions, so decide within days rather than weeks.

5. The rest of the v5 breaking-change list, checked against actual usage

Grep-verified as not exercised: custom matchers / expect.extend / declare module 'vitest' → 0 hits, so the Matchers<R, T> type change cannot break typecheck; 0 snapshots (.snap and toMatchInlineSnapshot both zero), so pretty-format replacing loupe cannot invalidate anything; hoisted vi.mock outside the top level → 0 occurrences (that change now throws); -t / testNamePattern → unused, so the " > " name-join change is moot; VITEST_WORKER_ID / VITEST_POOL_ID → unused, so 1-based renumbering cannot misdirect per-worker state; toThrow(''), expect.poll, *.bench.* files and imports of the removed vitest/coverage|reporters|snapshot|runners|… entrypoints → all 0. extends: true is already set in all four projects, and sharedViteServer turning on is inert for this config. Exposure for whatever is left: 446 test files, 448 files import from 'vitest' (server 228, src 129, tests 72, shared 19), with globals: true at vitest.config.ts:304.

6. Two things to watch on the first post-merge runs

  • The Windows advisory lane took 20m04s against a 30-minute budget, and vitest.config.ts already documents Windows timeout fragility (45s/60s on win32) — a vitest-runner regression surfaces there first.
  • v5 routes json/junit/html/attachment output to .vitest/, but .gitignore:87 only ignores .vitest-cache/. Nothing is written with the default console reporter today, but a future reporter choice would drop untracked artefacts into the working tree.

7. Renovate policy: compliant on every dimension checked

Labels are exactly [dependencies, major] with autoMerge: false; the "majors one at a time" rule is satisfied; minimumReleaseAge: 7 days passed (renovate/stability-days — 5.0.1 published 2026-09-15); and although vitest sits in the automerge allowlist, that rule carries matchUpdateTypes: ["patch"], so a 4→5 major correctly did not inherit it — future patch bumps will merge unattended once the eleven checks pass. renovate-config-validator --strict is green and no ceiling rule (typescript, node floor) applies.

8. Conflicts: #184 only — verified with git merge-tree

package.json:159 (vite, #184) and :160 (vitest, this PR) are adjacent lines, and the root devDependencies block in package-lock.json overlaps the same way: 184 × 186 conflicts in both files. 183, 185 and 181 are clean against this branch (184 × 185 conflicts separately, in THIRD-PARTY-NOTICES.md). Across the four open PRs there are exactly two conflict pairs and both involve #184, so any order costs two resolutions; the cheap path is to let Renovate rebase the loser so renovate-notices regenerates, rather than pressing Update branch.

9. Install-script policy unaffected

Zero hasInstallScript changes in the diff and allowScripts is untouched, so tests/installScriptPolicy.test.ts's exact-match assertion holds; it ran green inside this PR's lanes.

@looptroop-ai

Copy link
Copy Markdown
Owner

opencode (deepseek-v4.1-flash) — review

  • Missing [Unreleased] changelog entry. AGENTS.md asks for one when the only change is a dependency version and it is a major version. vitest ^4.1.11 → ^5.0.1 is a major bump and the PR edits only package.json and package-lock.json. Add a Summary line and a Changed/Added entry.

Confirmed otherwise, on head bf51f84d:

  • Lockfile and manifest agree; there are no direct @vitest/* dependencies to align, and the packages v5 bundled in (@vitest/expect, @vitest/snapshot, …) are correctly removed from the tree.
  • vite ^8.2.2 satisfies vitest 5's peer (^6.4.0 || ^7 || ^8), and engines.node >=24.21.0 is within vitest 5's ^24.0.0.
  • No snapshots, removed entrypoints, --reporter, browser mode or coverage config are in use; vitest.config.ts already sets extends: true where the new defaults touch.
  • All 97 checks pass (the Windows lanes that were still running at first look have finished).

One behavior change to keep in mind: vitest 5 enables clearMocks by default, calling vi.clearAllMocks() before every test. This repo sets no clearMocks and no current test depends on mock history surviving between tests, but any new test that does would need clearMocks: false.

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from a3255ba to 7521cf9 Compare September 23, 2026 13:16
looptroop-ai and others added 2 commits September 23, 2026 16:36
…default

AGENTS.md asks for a changelog entry when a dependency moves a major version,
and vitest 4 to 5 is one (opencode). Added under Changed, not Summary: it is a
test-framework change, not a user-facing one.

Vitest 5 turns `clearMocks` on by default, calling `vi.clearAllMocks()` before
every test. This repository never set it, so the upgrade changed test semantics
by inheritance (Command Code). The suite passes with it, which is evidence that
no test relies on calls an earlier one recorded, but not a rule that keeps it
so. `vitest.config.ts` now states `clearMocks: true` at the root, inherited by
all four projects through `extends: true`: the v5 behaviour, chosen rather than
defaulted, and unaffected if a later release changes the default again.

Verified on vitest 5.0.1: 446 files, 6788 tests passed, 13 skipped; lint,
typecheck and verify:version clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@renovate

renovate Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@looptroop-ai
looptroop-ai merged commit 147aaf7 into main Sep 23, 2026
104 checks passed
@looptroop-ai
looptroop-ai deleted the renovate/major-vitest-monorepo branch September 23, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file major Major version update, needs dashboard approval

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant