Skip to content

feat(deps): upgrade upstream dependencies - #2773

Merged
fengmk2 merged 2 commits into
mainfrom
deps/upstream-update
Sep 21, 2026
Merged

fengmk2 merged 2 commits into
mainfrom
deps/upstream-update

Conversation

@voidzero-guard

Copy link
Copy Markdown
Contributor
  • Upgrade oxlint 1.83.0 -> 1.84.0 and oxfmt 0.68.0 -> 0.69.0.
  • Upgrade the oxc crates (@oxc-project/runtime, @oxc-project/types, oxc-minify, oxc-parser, oxc-transform) 0.150.0 -> 0.151.0.
  • Hoist inner function declarations to module scope in the upgrade-deps script, org manifest, and two test files to satisfy unicorn/consistent-function-scoping as now reported by oxlint 1.84.0.

Dependency updates

Package From To
oxfmt 0.68.0 0.69.0
oxlint 1.83.0 1.84.0
@oxc-project/runtime 0.150.0 0.151.0
@oxc-project/types 0.150.0 0.151.0
oxc-minify 0.150.0 0.151.0
oxc-parser 0.150.0 0.151.0
oxc-transform 0.150.0 0.151.0
Unchanged dependencies
  • rolldown: v1.2.9 (5b4746e)
  • vite: v8.3.0 (434e8e9)
  • vitest: 5.0.1
  • @vitest/browser: 5.0.1
  • @vitest/browser-playwright: 5.0.1
  • @vitest/browser-preview: 5.0.1
  • @vitest/mocker: 5.0.1
  • @vitest/pretty-format: 5.0.1
  • @vitest/snapshot: 5.0.1
  • @vitest/spy: 5.0.1
  • @vitest/utils: 5.0.1
  • tsdown: 0.23.0
  • @tsdown/css: 0.23.0
  • @tsdown/exe: 0.23.0
  • lightningcss: ^1.33.0
  • lint-staged: 17.5.1
  • @oxc-node/cli: 0.1.3
  • @oxc-node/core: 0.1.3
  • oxlint-tsgolint: 7.0.2002
  • VITEST_VERSION constant: 5.0.1
  • README vitest pins: 5.0.1

Code changes

  • .github/scripts/upgrade-deps.ts — hoist the formatVersion/formatOld helpers from inside writeMetaFiles() to module scope.
  • packages/cli/src/create/org-manifest.ts — hoist the makeError closure out of validateCreateTemplates() as module-scope makeCreateConfigError (with formatter re-wrap of the call).
  • packages/cli/src/__tests__/define-config-vitest-resolver.spec.ts — move the resolver helper out of the describe block to module scope.
  • packages/cli/src/migration/__tests__/migrator.spec.ts — move the overrideFile/overrideMap helpers out of the describe block to module scope.

All four hoists address inner function declarations reported by oxlint 1.84.0's unicorn/consistent-function-scoping rule. Remaining edits are the version bumps in pnpm-workspace.yaml and the pnpm-lock.yaml refresh.

Build status

  • sync-remote-and-build: success
  • build-upstream: success

- oxfmt: 0.68.0 -> 0.69.0
- oxlint: 1.83.0 -> 1.84.0
- @oxc-project/runtime: 0.150.0 -> 0.151.0
- @oxc-project/types: 0.150.0 -> 0.151.0
- oxc-minify: 0.150.0 -> 0.151.0
- oxc-parser: 0.150.0 -> 0.151.0
- oxc-transform: 0.150.0 -> 0.151.0

Code changes:
- .github/scripts/upgrade-deps.ts: hoist formatVersion/formatOld helpers from writeMetaFiles() to module scope
- packages/cli/src/create/org-manifest.ts: hoist the makeError closure out of validateCreateTemplates() as module-scope makeCreateConfigError
- packages/cli/src/__tests__/define-config-vitest-resolver.spec.ts: move the resolver helper out of the describe block to module scope
- packages/cli/src/migration/__tests__/migrator.spec.ts: move the overrideFile/overrideMap helpers out of the describe block to module scope
@voidzero-guard

Copy link
Copy Markdown
Contributor Author

✅ No upstream CLI help changes detected

Compared normalized --help output for the upstream CLIs mirrored by Vite+.

➖ Vite: no version update (8.3.0)

No version update was detected, so there is no CLI help diff.

➖ Vitest: no version update (5.0.1)

No version update was detected, so there is no CLI help diff.

✅ Oxlint: no CLI help changes (1.83.0 → 1.84.0)

The version was updated, but the normalized CLI help output has no differences.

✅ Oxfmt: no CLI help changes (0.68.0 → 0.69.0)

The version was updated, but the normalized CLI help output has no differences.

➖ tsdown: no version update (0.23.0)

No version update was detected, so there is no CLI help diff.

@socket-security

socket-security Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​oxc-project/​types@​0.151.01001007295100
Addednpm/​@​oxc-project/​runtime@​0.151.01001007495100
Addednpm/​oxfmt@​0.69.0861008895100
Updatednpm/​oxc-parser@​0.150.0 ⏵ 0.151.089100100 +195 -1100

View full report

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://deps-upstream-update-viteplus-dev.voidzero-docs.workers.dev (commit 599c45a)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://369f9680-viteplus-dev.voidzero-docs.workers.dev 599c45a 2026-09-21T14:42:53.493Z Visit the dashboard ↗

@github-actions

Copy link
Copy Markdown
Contributor

CLI artifact sizes (599c45a)

Final release artifacts built by the canonical build-upstream and build-windows-cli actions.
The dist rows use the Linux build. The core total excludes .node files to match the release artifact.

Artifact Format Base PR Change
packages/cli/dist Directory total 2.12 MiB 2.12 MiB +47 B (+0.00%)
packages/core/dist Directory total 3.95 MiB 3.95 MiB 0 B (0.00%)
Combined package dist Directory total 6.06 MiB 6.06 MiB +47 B (+0.00%)
vp (Linux x64) Binary 11.25 MiB 11.25 MiB 0 B (0.00%)
vp (Linux x64) gzip -9 4.87 MiB 4.87 MiB 0 B (0.00%)
NAPI (Linux x64) Binary 32.08 MiB 32.08 MiB 0 B (0.00%)
NAPI (Linux x64) gzip -9 12.72 MiB 12.72 MiB 0 B (0.00%)
vp (macOS ARM64) Binary 8.39 MiB 8.39 MiB 0 B (0.00%)
vp (macOS ARM64) gzip -9 4.25 MiB 4.25 MiB 0 B (0.00%)
NAPI (macOS ARM64) Binary 39.69 MiB 39.69 MiB 0 B (0.00%)
NAPI (macOS ARM64) gzip -9 17.03 MiB 17.03 MiB 0 B (0.00%)
vp (Windows x64) Binary 9.14 MiB 9.14 MiB 0 B (0.00%)
vp (Windows x64) gzip -9 3.99 MiB 3.99 MiB 0 B (0.00%)
NAPI (Windows x64) Binary 27.04 MiB 27.04 MiB 0 B (0.00%)
NAPI (Windows x64) gzip -9 10.83 MiB 10.83 MiB -8 B (-0.00%)
Trampoline (Windows x64) Binary 13.50 KiB 13.50 KiB 0 B (0.00%)
Trampoline (Windows x64) gzip -9 7.09 KiB 7.09 KiB 0 B (0.00%)
Installer (Windows x64) Binary 4.56 MiB 4.56 MiB 0 B (0.00%)
Installer (Windows x64) gzip -9 2.13 MiB 2.13 MiB -1 B (-0.00%)

@fengmk2
fengmk2 merged commit 84708c3 into main Sep 21, 2026
118 of 119 checks passed
@fengmk2
fengmk2 deleted the deps/upstream-update branch September 21, 2026 15:09
fengmk2 added a commit that referenced this pull request Sep 22, 2026
…2780)

Vite+ now uses Vitest 5, and `vp migrate` helps Vitest 4 projects adopt
the new APIs and defaults. Standalone installs and upgrades now require
verified npm provenance for release binaries.

### Breaking Changes

#### Vitest 5

`vp test` and the public `vite-plus/test*` exports now use
`vitest@5.0.1`
([#2551](#2551)), by
@fengmk2.

| Area | Old | New |
| --- | --- | --- |
| Test runner | `vitest@4.1.11` | `vitest@5.0.1` |
| CLI Node.js range | `^20.19.0 \|\| ^22.18.0 \|\| >=24.11.0` |
`^22.18.0 \|\| ^24.11.0 \|\| >=26.0.0` |
| `vite-plus/test/runners` and `vite-plus/test/suite` | Vite+
compatibility exports | Use supported APIs from `vite-plus/test`; review
unsupported runner and expect plugins |
| `vite-plus/test/browser-webdriverio` | Bundled export | Use the
community `@vitest/browser-webdriverio` package |

Run `vp migrate` from the workspace root before you install the new
dependencies. The migrator updates supported config, source, benchmark,
command, and import changes. It reports manual work as `BLOCK` or
`REVIEW` items. See the [Vitest 5 migration
guide](https://viteplus.dev/guide/vitest-v5) for the full process.
Projects can stay on the prior release until their runtimes and tests
are ready.

#### `vp staged` runtime requirements

`vp staged` now uses `lint-staged@17.5.1`
([#2754](#2754)), by
@fengmk2.

| Requirement | Old | New |
| --- | --- | --- |
| Node.js for `vp staged` | The Vite+ CLI runtime range | `^22.22.1 \|\|
^24.11.0 \|\| >=26.0.0` |
| Git | No separate documented minimum | `>=2.32.0` |

Update Node.js and Git on developer machines and CI runners that execute
`vp staged` or its pre-commit hook. Other workflows do not use these
extra requirements.

### Highlights

- Standalone installers, `vp upgrade`, and `vp-setup.exe` now reject
release binaries without supported SLSA provenance
([#2440](#2440)), by
@kazupon.
- Installers now show progress and the exact shell activation command.
Download progress preserves earlier terminal output
([#2744](#2744),
[#2741](#2741)), by
@fengmk2.
- System-first runtime and package-manager shims now use a fallback
directory at the end of `PATH`. Setup restores missing package-manager
preferences
([#2758](#2758),
[#2763](#2763)), by
@liangmiQwQ and @fengmk2.
- `vp run` now finishes when background processes remain. Large file
traces run without caching instead of killing the task
([#2767](#2767),
[vite-task#675](voidzero-dev/vite-task#675)), by
@wan9chi.

### Features

- `vp add` now supports shared install options such as `--offline`,
`--frozen-lockfile`, and `--lockfile-only`
([#2722](#2722)), by
@jong-kyung.
- `vp pm patch` and `vp pm patch-commit` now use the native commands in
npm 12 and later
([#2736](#2736)), by
@jong-kyung.
- `vp rebuild` now supports Yarn Berry and forwards package names and
extra arguments
([#2761](#2761)), by
@jong-kyung.
- The bundled tools update `oxlint` `1.83.0` -> `1.85.0`,
`oxlint-tsgolint` `7.0.2001` -> `7.0.2002`, and `oxfmt` `0.68.0` ->
`0.70.0` ([#2745](#2745),
[#2773](#2773),
[#2778](#2778)), by
@voidzero-guard[bot]. These versions can flag or format code that passed
before. Run `vp fmt` after upgrading if CI runs `vp check`.

### Fixes & Enhancements

- `oxlint` and `oxfmt` no longer expose bin wrappers that conflict with
upstream packages. Editors must use `vp lint --lsp`, `vp fmt --lsp`, or
`vp fmt --stdin-filepath`
([#2672](#2672)), by
@fengmk2.
- `vp create vite:generator` now replaces catalog references for package
managers that do not support catalogs
([#2720](#2720)), by
@SaKaNa-Y.
- Unpinned npm projects now use the npm version bundled with the
selected Node.js runtime. The same policy works during migration
([#2742](#2742),
[#2748](#2748)), by
@liangmiQwQ.
- The CLI now loads its local versions module through a file URL,
including on Windows paths
([#2749](#2749)), by
@YanChenBai.
- Package-manager commands now use pnpm when the project has no detected
package manager
([#2750](#2750)), by
@liangmiQwQ.
- `vp migrate` now removes unused `@oxlint/plugins` dependencies after
it rewrites plugin imports
([#2751](#2751)), by
@fengmk2.
- `vp update --no-save` now warns that Yarn Classic and Yarn Berry do
not support the option
([#2762](#2762)), by
@jong-kyung.
- `vp migrate` now explains its `tsdown@0.23` compatibility settings and
links to removal guidance
([#2769](#2769)), by
@fengmk2.
- Environment setup now installs and diagnoses the official `pn` and
`pnx` aliases for pnpm
([#2770](#2770)), by
@iruoy.
- Cached tasks now receive GitHub Actions OIDC variables, so npm Trusted
Publishing works through `vp run`
([vite-task#691](voidzero-dev/vite-task#691)),
by @naokihaba.
- Automatic task input tracking now records file access from signal
handlers
([vite-task#687](voidzero-dev/vite-task#687)),
by @wan9chi.

### Refactor

- `vp lint`, `vp fmt`, and `vp check` now use native config discovery.
Package commands keep matching workspace-root settings, while explicit
config flags take precedence
([#2731](#2731)), by
@fengmk2.

### Chore

- Generated workflows and `vp migrate` now use `setup-vp@v1.21.1`,
including its installation fixes
([#2760](#2760),
[#2772](#2772)), by
@renovate[bot] and @fengmk2.

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| vite | `8.3.0` |
[`434e8e9`](vitejs/vite@434e8e9)
|
| rolldown | `1.2.9` |
[`5b4746e`](rolldown/rolldown@5b4746e)
|
| tsdown | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) |
| vitest | `5.0.1` | [npm](https://npmx.dev/package/vitest/v/5.0.1) |
| oxlint | `1.85.0` | [npm](https://npmx.dev/package/oxlint/v/1.85.0) |
| oxlint-tsgolint | `7.0.2002` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2002) |
| oxfmt | `0.70.0` | [npm](https://npmx.dev/package/oxfmt/v/0.70.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@YanChenBai, @iruoy

**Full Changelog**:
v0.3.3...v1.0.0-rc.0

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant