Skip to content

chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 - #2714

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-5.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-5.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps vitest from 4.1.10 to 4.1.11.

Release notes

Sourced from vitest's releases.

v4.1.11

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • 9bd8d46 chore: release v4.1.11 (#10995)
  • 9851dbc fix(browser): trigger playwright/chromium gc on lower disk availability [back...
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 8, 2026
@vercel

vercel Bot commented Sep 8, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
frontends-starter-template-extended Error Error Sep 10, 2026 1:40pm UTC
frontends-vue-starter-template Error Error Sep 10, 2026 1:40pm UTC

Request Review

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review

No medium, high, or critical findings.

This Dependabot PR only bumps the devDependency vitest from 4.1.10 to 5.0.0 in six packages (api-client, api-gen, cms-base-layer, composables, helpers, nuxt-module) and updates pnpm-lock.yaml. Lockfile integrity for vitest@5.0.0 and @vitest/mocker@5.0.0 matches the npm registry. No application or runtime code changed.

Advisory check: GHSA-82fw-gwwq-j7x9 (CVE-2026-84373, path traversal via @vitest/mocker redirect mocks) is fixed in 5.0.0. It is not reachable here: this repo does not use Vitest browser mode, @vitest/ui, or the public mockerPlugin / interceptorPlugin exports. Other 5.0.0-beta browser-mode issues (CDP RCE, otelCarrier XSS, provider-command file-gate bypass) were patched before the 5.0.0 stable release.

No prior automation security threads to re-validate. Slack summary was not posted (post tool is not configured).

Open in Web View Automation 

Sent by Cursor Automation: Review pull requests for exploitable security issues and flag only validated findings before merge

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.10 to 4.1.11.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/vitest-5.0.0 branch from 21dabac to 2eb07d7 Compare September 10, 2026 13:40
@dependabot dependabot Bot changed the title chore(deps-dev): bump vitest from 4.1.10 to 5.0.0 chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 Sep 10, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review

No medium, high, or critical findings.

This Dependabot synchronize only bumps the devDependency vitest from 4.1.10 to 4.1.11 in six packages (api-client, api-gen, cms-base-layer, composables, helpers, nuxt-module) and refreshes pnpm-lock.yaml. No application or runtime code changed. Lockfile integrity for vitest@4.1.11 and @vitest/mocker@4.1.11 matches the npm registry.

Advisory check: GHSA-82fw-gwwq-j7x9 (CVE-2026-84373, path traversal via @vitest/mocker redirect mocks) is fixed in 4.1.11. The repo already overrides vitest / @vitest/mocker <4.1.11 to 4.1.11; this PR aligns the declared versions. The advisory is also not reachable here: Vitest configs use Node or happy-dom, not browser mode, and there is no use of the public mockerPlugin / interceptorPlugin exports.

Prior automation review (opened, then targeting a 5.0.0 bump) had no finding threads to re-validate. Slack summary was not posted (post tool is not configured).

Open in Web View Automation 

Sent by Cursor Automation: Review pull requests for exploitable security issues and flag only validated findings before merge

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants