deps(backend): bump vitest from 4.1.11 to 5.0.0 in /backend - #196
deps(backend): bump vitest from 4.1.11 to 5.0.0 in /backend#196dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.11 to 5.0.0. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 5.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
There was a problem hiding this comment.
Sorry @dependabot[bot], this account has used its review budget of 2,500,000 diff characters for the last 7 days.
You can request another review in 1 day and 1 hour by commenting @sourcery-ai review.
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Sep 7, 2026 7:43p.m. | Review ↗ | |
| Kotlin | Sep 7, 2026 7:43p.m. | Review ↗ | |
| SQL | Sep 7, 2026 7:43p.m. | Review ↗ | |
| Swift | Sep 7, 2026 7:43p.m. | Review ↗ | |
| Secrets | Sep 7, 2026 7:43p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|
Tick the box to add this pull request to the merge queue (same as
|
| "@types/node": "^26.4.1", | ||
| "typescript": "^7.0.2", | ||
| "vitest": "~4.1.11", | ||
| "vitest": "~5.0.0", |
There was a problem hiding this comment.
🟡 Backend tests use incompatible runners
Installing [email protected] violates the worker pool's Vitest 4 peer contract. The lockfile mixes Vitest 5 with version 4 runners, so backend tests cannot run reliably.
Prompt for agents
The Vitest 5 upgrade is incompatible with @cloudflare/vitest-pool-workers 0.22.0. That package declares peers on vitest, @vitest/runner, and @vitest/snapshot at ^4.1.0. The generated backend/package-lock.json keeps the pool's runner and snapshot packages at 4.1.11 while installing Vitest 5. Either retain Vitest 4 or upgrade the Cloudflare pool and any related configuration to a release that explicitly supports Vitest 5. Regenerate the lockfile and verify a clean npm ci plus the worker-backed test suite.
Was this helpful? React with 👍 or 👎 to provide feedback.
✅MegaLinter analysis: Success
See detailed reports in MegaLinter artifacts MegaLinter is provided by OX Security |
🐤 Kanarek · 🔴 blocked
Backend · 2 files |
Bumps vitest from 4.1.11 to 5.0.0.
Release notes
Sourced from vitest's releases.
... (truncated)
Commits
f441c6fchore: release v5.0.0 (#11130)d46a747fix: treat test.describe as a suite during static collection (#11128)584cf30fix: add a warning if inline project has duplicate plugins due to unexpected ...f08ce4bfix: apply queued mocks from doMock() in queue order (fixes #10706) (#11127)897f51fchore: release v5.0.0-rc.4 (#11107)1339b06chore(deps): update all non-major dependencies (#11104)51e9494feat!: parse files statically in vitest list by default (#11088)2122ffdfix: propagate --maxWorkers to projects (#11102)dc10f5ffix(browser): report the action error when a task times out (#11101)d4fe198feat: promote clearCache out of experimental (#11086)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)