Skip to content

chore(deps): bump vitest to 4.1.11, resolve all Dependabot alerts - #29

Merged
CakeRepository merged 1 commit into
masterfrom
claude/dependabot-updates-review-341c1e
Oct 4, 2026
Merged

CakeRepository merged 1 commit into
masterfrom
claude/dependabot-updates-review-341c1e

Conversation

@CakeRepository

Copy link
Copy Markdown
Owner

Summary

Consolidates the five open Dependabot PRs (#24, #25, #26, #27, #28) into a single lockfile update. They all rewrite package-lock.json, so merging them one at a time would conflict.

All changes are dev-only. Runtime dependencies are untouched, so the published npm package doesn't change and no version bump is needed.

Test plan

  • npm ci installs cleanly
  • npm run build and npm run lint pass
  • npm test: 7 files, 104 tests pass on vitest 4.1.11 (Node 22.16)
  • CI green on Node 20 / 22 / 24

🤖 Generated with Claude Code

Consolidates Dependabot PRs #24-#28 into one lockfile update. vitest
4.1.11 pulls in patched @vitest/mocker, vite 8, postcss, nanoid and
picomatch, and drops rollup. npm audit reports 0 vulnerabilities.

Drop Node 18 from the CI matrix (engines already requires >=20, and
vite 8 needs node:util styleText) and add Node 24.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@CakeRepository
CakeRepository merged commit 09dd1cd into master Oct 4, 2026
3 checks passed
@CakeRepository CakeRepository mentioned this pull request Oct 4, 2026
4 of 5 tasks
CakeRepository added a commit that referenced this pull request Oct 4, 2026
Bump version in package.json, package-lock.json, server.json and
SERVER_VERSION, and cut the 4.0.3 CHANGELOG entry covering the
vitest 4.1.11 dev dependency update (#29), the Node 20/22/24 CI
matrix, and SECURITY.md (#30).

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant