Skip to content

chore(deps): update dependency vitest to v4 [security] - #3789

Merged
jrusso1020 merged 2 commits into
mainfrom
renovate/npm-vitest-vulnerability
Sep 10, 2026
Merged

chore(deps): update dependency vitest to v4 [security]#3789
jrusso1020 merged 2 commits into
mainfrom
renovate/npm-vitest-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Upgrades Vitest to 4.1.11 across all 13 manifests affected by GHSA-82fw-gwwq-j7x9 (Dependabot alerts #21#33), and aligns @vitest/coverage-v8 with that version. The installed tree resolves Vitest, mocker and coverage-v8 to 4.1.11.

Preserves existing tests under Vitest 4 by using constructable Audio/Image mocks, explicit mock types, explicit mock-history cleanup, a test-only confirm fallback, and explicit Node types in Studio. No production behavior, test assertions, coverage thresholds, Vite or React plugin versions change. The relevant Studio test/type fixes were selectively backported from #3620; its separate Vite 8 migration remains out of scope.

Validation:

  • Full workspace build and signed commit hooks (lint, format, strict type checks) pass.
  • Studio: 4,822 pass, 18 todo; player: 370 pass; core: 2,759 pass; CLI: 3,171 pass, 3 skipped. Remaining lint/parser/SDK/playground/shader/server suites pass.
  • Engine: four initial failures were an unhydrated LFS PNG fixture; after hydrating that exact fixture, all 115 tests in the affected file pass (the other 73 files passed already).
  • Runtime coverage passes existing thresholds: 86.25% statements, 79.84% branches, 87.36% functions, 89.95% lines.
  • Producer: 663 pass, 1 skipped, one local AAC loudness assertion fails with 3.9 versus a 3 LU limit. The unchanged Vitest 3 baseline fails identically at 3.9. No threshold relaxed; native CI must pass before merge.
  • Fallow's changed-code gate passes with 25 inherited findings excluded and duplication warnings disclosed for reviewer assessment.

The first unrestricted local parallel run was discarded due to machine contention. Results above use capped workers. Native CI and independent review are required before merge; verify Dependabot closes all 13 alerts after landing.

@renovate renovate Bot added the security label Sep 8, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 4f7e7d8 to 2c41b15 Compare September 8, 2026 23:54
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 8, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 2c41b15 to a30005c Compare September 9, 2026 02:00
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from a30005c to 2922509 Compare September 9, 2026 02:10
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 2922509 to 248addf Compare September 9, 2026 02:16
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 248addf to a32462f Compare September 9, 2026 04:09
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from a32462f to e95f9cc Compare September 9, 2026 04:48
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from e95f9cc to b66c567 Compare September 9, 2026 10:28
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from b66c567 to 328a303 Compare September 9, 2026 11:17
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 328a303 to 0849deb Compare September 9, 2026 16:38
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 0849deb to bec44ca Compare September 9, 2026 16:44
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from bec44ca to 3e29312 Compare September 9, 2026 17:21
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 3e29312 to 4aada05 Compare September 9, 2026 18:00
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 4aada05 to 6fa8f22 Compare September 9, 2026 20:03
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 6fa8f22 to 2569645 Compare September 9, 2026 23:39
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 2569645 to b5f5c5e Compare September 10, 2026 00:45
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from b5f5c5e to 1461c32 Compare September 10, 2026 01:56
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 1461c32 to 637d877 Compare September 10, 2026 02:45
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 637d877 to 297718c Compare September 10, 2026 03:11
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 297718c to d84f43c Compare September 10, 2026 05:17
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from d84f43c to 19b1b81 Compare September 10, 2026 08:31
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 19b1b81 to 66f652b Compare September 10, 2026 11:22
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from 66f652b to e9ee0b9 Compare September 10, 2026 12:01
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from e9ee0b9 to b5f3763 Compare September 10, 2026 16:00
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from b5f3763 to e282599 Compare September 10, 2026 16:32
@renovate renovate Bot changed the title chore(deps): update dependency vitest to v4 [security] chore(deps): update dependency vitest to ^3.2.7 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-vitest-vulnerability branch from e282599 to adc23f7 Compare September 10, 2026 16:57
@renovate renovate Bot changed the title chore(deps): update dependency vitest to ^3.2.7 [security] chore(deps): update dependency vitest to v4 [security] Sep 10, 2026
@renovate

renovate Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@miga-heygen miga-heygen left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed at head e4fe6d7968280a43365e4b720f0cdf4739a5436c (two commits on top of main at c98d6fba: the Renovate bump and the compatibility fix). Did a real bun install --frozen-lockfile in an isolated worktree and ran every changed suite under the installed Vitest 4.1.11, then mutation-checked each shim.

Strengths

  • packages/studio/src/test-setup.ts:8 — the confirm fallback is the right place and the right default: production calls window.confirm(...) directly in five components, only two suites reach those paths, and both stub it via vi.spyOn; a () => false default means an unstubbed path declines rather than proceeding.
  • packages/cli/src/registry/remote.test.ts:59.mockClear() on the re-spied fetch reproduces the Vitest 3 semantics exactly (a fresh spy with empty history), so toHaveBeenCalledTimes(1) still means "the second call made exactly one network attempt". No assertion weakened.

Verified

  • Scope: git diff --stat vs merge-base is 27 files, all of them bun.lock, 13 package.json manifests, *.test.ts(x), test-setup.ts and packages/studio/tsconfig.json. No production source changed. tsconfig.json is noEmit; tsup.config.ts builds from tsconfig.lib.json, which excludes tests and test-setup.ts, so nothing here reaches build output.
  • Lockfile: vitest, @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format,coverage-v8} all resolve to exactly 4.1.11. vite stays 6.4.2; no @vitejs/*, rollup, esbuild, react or react-dom entries move. Transitive deltas are confined to Vitest's own tree: chai 5→6, std-env 3→4, tinyrainbow 2→3, magicast 0.3→0.5 (with nested @babel/parser/types 7.29.8), ast-v8-to-istanbul 0.3→1.0, es-module-lexer 1.7→2.3, obug new; vite-node, tinypool, tinyspy, loupe, test-exclude, istanbul-lib-source-maps dropped. Vitest 4's vite range ^6 || ^7 || ^8 and @types/node >=24 are both satisfied by what's already installed.
  • Also in the lock diff, unrelated to Vitest: the workspace version fields move 0.8.14 → 0.8.33 and the CLI gains the hyperframes-localize-fonts bin. Both already match package.json on main; the lockfile was simply stale and this install caught it up. Harmless, noting it so nobody hunts for the commit that "bumped" packages.
  • Suites under Vitest 4.1.11 at this head: CLI remote.test.ts 28/28; core captionOverrides + mediaProxy 48/48; player 148/148; the seven changed Studio files plus the two confirm-stubbing suites 162/162.
  • Every shim is load-bearing (mutation, then restored): drop both .mockClear() → 3 red; drop vi.clearAllMocks() in the two core files → 8 red; one Audio mock back to an arrow → 6 red (not a constructor); Image mock back to an arrow → 1 red; drop the confirm fallback → 4 red (can only spy on a function). No test skipped, no assertion or threshold changed.
  • vi.clearAllMocks() is in afterEach only, so it affects cross-test isolation, not intra-test call ordering; both files assert within a test.
  • Producer AAC loudness: audioPadTrim.integration.test.ts passes on main under Vitest 3 in my environment (3.5 s), so I can't reproduce the local 3.9 LU reading either way. It is an ffmpeg-build-dependent measurement, the test is untouched by this PR, and the Test lane is green at this head, so I'm treating it as environmental rather than a regression.
  • CI: all 8 required checks pass at e4fe6d79 (Build, Typecheck, Test, Test: runtime contract, Tests on windows-latest, Render on windows-latest, regression, Semantic PR title). The earlier "fail" rows were the cancelled runs superseded by this push.

Nits (non-blocking)

  • packages/studio/tsconfig.json:20types: ["vite/client", "node"] widens the type environment for the whole browser package (and, via tsconfig.lib.json, the d.ts build), so browser code that accidentally reaches for process/Buffer now typechecks. A test-only tsconfig or a /// <reference types="node" /> in test-setup.ts would scope it. Fine to leave for the Vite 8 migration.
  • packages/core/src/runtime/mediaProxy.test.ts:61vi.restoreAllMocks() moved above the DOM cleanup; harmless, just noting it's an ordering change rather than an addition.

Verdict: APPROVE
Reasoning: Security bump lands with a single resolved Vitest 4 tree and no non-test source change; every compatibility shim is necessary (proven by mutation) and preserves the original assertions; all required checks green at this head.

— Miga

@jrusso1020

Copy link
Copy Markdown
Collaborator

@miga-heygen Thanks for the exact-head approval. All replacement CI runs are green and there are no unresolved threads at e4fe6d7. Please explicitly confirm acceptance of the Fallow inherited findings and duplication warnings disclosed in the PR description, or identify anything requiring a fix. This is the remaining review gate before protected merge. Your Node-type scope and cleanup-order nits are recorded as nonblocking.

@miga-heygen

Copy link
Copy Markdown
Contributor

Confirming, with the audit re-run rather than from the description. I ran the CI invocation (fallow audit --base origin/main --fail-on-issues, fallow 2.75.0) at e4fe6d79 in a fresh frozen-lockfile install and read the JSON output:

  • Verdict warn, exit 0, gate new-only. Dead code 0 / 0, complexity 0 / 0 (789 functions analysed, none above threshold). Duplication: 25 inherited clone groups, 1 introduced — that is the "25 inherited findings" the description discloses, plus the duplication warnings.
  • All 26 groups are fallow/code-duplication, severity minor, entirely inside three test files (captionOverrides.test.ts, mediaProxy.test.ts, TimelineAutomationLane.test.tsx). None is in production code or in a manifest.
  • The one group attributed as introduced is the mount / mountRerenderable pair in TimelineAutomationLane.test.tsx:599 and :786. Both blocks exist byte-for-byte on main apart from the two casts; this PR only renames as ReturnType<typeof vi.fn> to as Mock, which shortens the token stream enough for the detector's fingerprint to match where it previously did not. It is a pre-existing duplication surfacing under a type rename, not new duplicated logic.

Accepted. Nothing here requires a fix before merge: the inherited findings are untouched by this PR, the single "introduced" group is an attribution artifact of the type rename, and duplication is warn-level in this repo's gate. If anyone wants the mount / mountRerenderable pair collapsed, that is a test-hygiene follow-up on main, not a condition of this bump. Approval at e4fe6d79 stands.

— Miga

@jrusso1020
jrusso1020 merged commit eae4892 into main Sep 10, 2026
63 of 95 checks passed
@jrusso1020
jrusso1020 deleted the renovate/npm-vitest-vulnerability branch September 10, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants