Skip to content

build(deps-dev): update dependency vitest to v5 - #245

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-vitest-monorepo
Closed

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-vitest-monorepo

Conversation

@renovate

@renovate renovate Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
vitest (source) 4.1.115.0.1 age confidence

Release Notes

vitest-dev/vitest (vitest)

v5.0.1

Compare Source

   🚀 Features
   🐞 Bug Fixes
    View changes on GitHub

v5.0.0

Compare Source

   🚨 Breaking Changes
   🚀 Features
   🐞 Bug Fixes

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the Type: Dependencies Dependency issues or Changes to dependency files label Sep 6, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

renovateによるvitest 4.1.11 -> 5.0.0のメジャー更新です。

ロックファイル上で@vitest/expect, @vitest/runner, @vitest/snapshot, @vitest/utils, @vitest/pretty-format, pathe, tinyrainbow, convert-source-mapが消えていますが、これはvitest本体へのインライン化と依存整理によるもので、意図しない削除ではありません。magic-stringは1.2.3へ、tinybenchは6.1.4へ上がっています。

本プロジェクトのテストが使うAPIはdescribe/it/expect/beforeEach/afterEachのみで、v5の主要な破壊的変更(vi.mockのトップレベル制約, clearMocksのデフォルト変更, test.sequential削除, benchmark API刷新, browser mode変更)はいずれも該当しません。vite.config.tsが使うdefineConfig/configDefaultsもv5で維持されています。ピア依存もvite 8.2.2 / @types/node 22.20.1で要求を満たしています。

ブロッカーとなる問題はないためAPPROVEとします。engines.nodeの整合について1点だけNOTEを残しました。

Review metadata

Comment thread package.json Outdated
"typescript-eslint": "8.68.0",
"vite": "8.2.2",
"vitest": "4.1.11"
"vitest": "5.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

📦 Dependency 🧪 Test

vitest 5.0.0はNode要求が^20.0.0 || ^22.0.0 || >=24.0.0から^22.12.0 || ^24.0.0 || >=26.0.0へ引き上げられました。一方で本プロジェクトのengines.node>=22.22のままです。

下限としては22.22 >= 22.12なので問題ありませんが、>=22.22はNode 23や25といった奇数系メジャーも許容してしまい、これらはvitest 5のサポート範囲外です。flake.nix経由のnodejsは偶数系に固定されるため実害は出にくいですが、^22.22.0 || ^24.0.0 || >=26.0.0のようにvitest 5の範囲へ揃えておくと、開発環境外で誤ったNodeが使われた際にEBADENGINEで早期に検出できます。

参考として、vitest 5.0.0はリリースから日が浅く(2026-09-03公開)パッチリリースがまだ出ていません。テスト終了時にEnvironmentTeardownError: Closing rpc while "onUserConsoleLog" was pendingが断続的に発生する回帰報告(https://github.com/vitest-dev/vitest/issues/11153)があります。本プロジェクトはgitコマンドを実行する統合テストを含むため、CIが断続的に落ちるようになった場合はこの既知問題を疑い、5.0.1以降に速やかに追随することを推奨します。

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from a10a6c2 to 6bff434 Compare September 15, 2026 21:32

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

renovateによるvitest 4.1.11 -> 5.0.0のメジャー更新の再レビューです。

前回レビュー時点からpackage-lock.jsonのvitest依存ツリーが更新されており(magic-stringが1.2.3から1.3.1へ、@jridgewell/trace-mapping@jridgewell/resolve-uriが新規追加)、いずれもvitest内部のdev依存のみで、vite buildのバンドル成果物には含まれません。

v5の破壊的変更(clearMocksのデフォルト変更、vi.mockのトップレベル制約、ベンチマークAPI刷新、test.sequential削除、値整形のpretty-format化、出力先の.vitest/集約、Browser Mode厳格化)を一通り確認しましたが、本プロジェクトのテストは同期的なdescribe/it/expectbeforeEach/afterEachのみを使っており、vi.*もbenchも未使用のため影響はありません。engines.node>=22.22でv5の要求^22.12.0 || ^24.0.0 || >=26.0.0を満たす点も前回指摘の通りです。

ブロッカーはないためAPPROVEします。ピン先を5.0.1にする提案のみインラインで残します。

Review metadata

Comment thread package.json Outdated
"typescript-eslint": "8.68.0",
"vite": "8.2.2",
"vitest": "4.1.11"
"vitest": "5.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tip

📦 Dependency 🧪 Test

バージョンのピン先を5.0.0ではなく5.0.1にすることを推奨します。

5.0.0には初期リグレッションが複数あり、直後の5.0.1で修正されています。本プロジェクトに関係しうるのは以下です。

Renovateの次回更新を待つ運用でも実害は小さいですが、メジャーアップグレードを取り込むタイミングで最新パッチに合わせておくほうが安全です。

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 6bff434 to 6770e28 Compare September 18, 2026 20:59

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

renovateによるvitest 4.1.11 -> 5.0.1のメジャー更新の再レビューです。

前回レビュー時点ではピン先が5.0.0でしたが、5.0.1へ更新されています。5.0.1は5.0.0の初期リグレッション(vitest listの終了コード、automockのprototype再帰、ResolvedConfigexactOptionalPropertyTypes型エラー等)を修正済みのバージョンであり、既存スレッドでの推奨どおりの妥当な選択です。

v5の破壊的変更を一通り確認しましたが、本プロジェクトへの実害は見つかりませんでした。

  • Node 22.12以上 / Vite 6.4以上が必須。engines.node>=22.22viteは8.2.2で要件を満たします。
  • @vitest/expect / @vitest/runner / @vitest/snapshot / @vitest/utils / @vitest/spy / @vitest/pretty-format / pathe / tinyrainbowのlockfileからの消失はvitest本体へのインライン化によるもので、本プロジェクトは@vitest/*を直接importしていません。
  • 非推奨エントリポイント(vitest/reporters, vitest/environments等)の削除。使用はvitestvitest/configのみで影響なし。
  • clearMocksのデフォルトがtrueへ変更、vi.mockのトップレベル制約の厳格化。vi.mock/vi.fnを一切使っていないため影響なし。
  • sequentialオプション削除、test.for/eachのタイトル変数のクオート除去、Locatorのオブジェクト化、ブラウザ/ベンチマーク/カバレッジAPI変更。いずれも未使用。
  • awaitされていない非同期アサーションがテスト失敗になる変更。test/内のexpectはすべて同期マッチャでresolves/rejectsの使用がありません。
  • 設定ファイルの祖先ディレクトリ探索の廃止。ルートのvite.config.tsをルートから実行するため影響なし。
  • vite.config.tsが使うconfigDefaultsは5.0.1でもvitest/configからexportされ続けており、defaultExcludeの値も4.1.11と同一なので現行設定はそのまま動作します。

v5.0.xの既知のリグレッション(vitest-dev/vitest#11296 のMap/Set等値判定、vitest-dev/vitest#11246fsModuleCachevitest-dev/vitest#11281 の複数プロジェクトのキャッシュキー衝突、vitest-dev/vitest#11237 のfixtureリトライ)も確認しましたが、現在のテスト内容では踏まない見込みです。

セキュリティ面では@vitest/mockerのパストラバーサル(GHSA-82fw-gwwq-j7x9)は4.1.11で既に修正済みで、v5ではUI API・ブラウザorchestratorのアクセス制御が強化されています。

既存スレッドで指摘済みのengines.nodeの範囲がvitestのサポート範囲より広い点は重複するため再掲しません。nix-fast-buildnpm testが通ることの確認をもって取り込んで問題ないと判断します(本レビュー環境では実行検証はできていません)。指摘すべき新規事項はないためAPPROVEとします。

Review metadata

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 6770e28 to e68c2bd Compare September 19, 2026 11:33

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

renovateによるvitest 4.1.11 -> 5.0.1のメジャー更新の再レビューです。

前回レビュー(commit 6770e28)からの差分はmasterの取り込みとpackage-lock.jsonのvitest依存ツリー更新が中心で、package.json側のピン先は5.0.1のままです。

v5の破壊的変更は前回までのレビューで確認済みの通り、本プロジェクトへの実害はありません。

  • Node要求^22.12.0 || ^24.0.0 || >=26.0.0に対しengines.node: >=22.22で下限は充足。
  • peerのvite ^6.4.0 || ^7.0.0 || ^8.0.0に対しvite 8.2.2、@types/node ^22.0.0 || >=24.0.0に対し22.20.3でいずれも充足。
  • clearMocksのデフォルトtrue化、未awaitの非同期アサーションの失敗扱い、test.sequential削除、testNamePatternのフルネームマッチ、ベンチAPI刷新、browser mode/UIの変更はいずれも該当コードなし。
  • エントリポイント削除の影響も、vite.config.tsが使うvitest/configは維持されているためなし。

lockfileで@vitest/*サブパッケージやpathe, tinyrainbowが消え、chaiが直接依存化しているのは、vitest 5が依存を本体へバンドルした設計変更によるもので意図通りです。

code-quality, documentation, performance, security, testの各観点では新規の指摘はありませんでした。マージして問題ないと判断します。

Review metadata

Comment thread package.json
"typescript-eslint": "8.68.0",
"vite": "8.2.2",
"vitest": "4.1.11"
"vitest": "5.0.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tip

📦 Dependency 🧪 Test

参考情報として、vitest 5.0.1時点で未修正の既知issueを挙げておきます。いずれも緊急度は低く、このPRのマージを妨げるものではありません。

また、v5ではjson/junitレポータの出力先が.vitest/配下に統一されています。今はレポータ設定がないため影響ありませんが、将来導入する場合は.gitignoreへの追加が必要になります。

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from e68c2bd to 4e514af Compare September 19, 2026 12:46

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

vitest 4.1.11 -> 5.0.1 のメジャーアップデートです。

Renovateによる依存更新のみで、プロダクションコードやテストコードの変更はありません。
メジャーアップデートですが、本リポジトリの使い方の範囲では破壊的変更の影響を受けないと判断しました。

  • 実行要件 (Node.js ^22.12.0 || ^24 || >=26、Vite >=6.4.0) は engines.node: ">=22.22"vite: 8.2.2 で充足。
  • vite が vitest の直接依存から peerDependency へ変わりましたが、devDependencies に明示済みで問題なし。
  • clearMocks 既定値変更、sequential 削除、expect.poll の挙動変更、Browser Mode、カバレッジといった主要な破壊的変更は、test/ 配下で該当機能を使っていないため影響なし。
  • vite.config.tstest 設定は exclude のみで、削除/変更されたオプションには触れていません。

公開セキュリティアドバイザリで 5.0.0/5.0.1 を対象とするものはありません。

CI のテストがグリーンであることを確認した上でマージしてください。

Review metadata

Comment thread package.json
"typescript-eslint": "8.68.0",
"vite": "8.2.2",
"vitest": "4.1.11"
"vitest": "5.0.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

📦 Dependency

vitest 5 系の主な破壊的変更と本リポジトリへの影響の整理です。実害は見当たりません。

  • 実行要件: Node.js ^22.12.0 || ^24 || >=26、Vite >=6.4.0engines.node: ">=22.22"vite: 8.2.2 なので充足。
  • vite が vitest の直接依存から peerDependency に変更。devDependencies に明示済みで問題なし。
  • @vitest/expect が vitest 本体へインライン化され、@vitest/runner 等と共に独立パッケージとして非推奨化 (ロックファイルからも @vitest/expect/runner/snapshot/utils/pretty-format が消滅)。直接 import していないため影響なし。
  • 挙動変更: clearMocks の既定が true に、未 await の非同期アサーション (.resolves/.rejects/スナップショット) がテスト失敗に、test.sequential 系の削除 (concurrent: false へ)、値整形が loupe から pretty-format に変更 (test.each$ 補間で文字列の引用符が消える)、-t/testNamePattern がフルネーム照合に、親ディレクトリの設定ファイル探索廃止、成果物の .vitest/ 集約、VITEST_POOL_ID/VITEST_WORKER_ID が 1 始まりに。
  • test/ 配下 (delete-merged-branch.test.tsgit-lfs.test.tstest/@commitlint/rules/*) に vi.*sequentialexpect.poll、Browser Mode、ベンチマーク、カバレッジの利用は無く、vite.config.tstestexclude のみです。

セキュリティ面では @vitest/mocker のパストラバーサル (GHSA-82fw-gwwq-j7x9) は既に 4.1.11 で修正済みのため、今回の更新による修正効果はありません。5.0.0/5.0.1 自体を対象とする公開アドバイザリもありません。

なお vitest 5.0.x には未解決のリグレッション報告が残っています (例: vitest-dev/vitest#11310 vi.hoisted 内の動的 import で vi.mock 登録が失われる、vitest-dev/vitest#11289 vmThreads + isolate:false でのモック取りこぼし、vitest-dev/vitest#11285 v8 カバレッジが v4 比 3-6 倍遅い、vitest-dev/vitest#11296 toContainEqual が任意の Map/Set を等価判定)。いずれもモック/Browser Mode/カバレッジ関連で本リポジトリは該当しない見込みですが、マージ前に CI 上で npm test がグリーンであること、特に vite.config.ts が使用する vitest/configconfigDefaults が v5 でも解決されることを確認してください。

@renovate
renovate Bot force-pushed the renovate/major-vitest-monorepo branch from 4e514af to 718ea7e Compare September 19, 2026 13:02

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

renovateによるvitest 4.1.11 -> 5.0.1のメジャー更新の再レビューです。

前回レビュー(commit 4e514af)からの差分はmasterの取り込みとpackage-lock.jsonのvitest依存ツリー更新のみで、package.jsonのピン先は5.0.1のままです。

  • 依存ツリーの変化は@vitest/expect/@vitest/runner/@vitest/snapshot/@vitest/utils/@vitest/pretty-formatがvitest本体へバンドルされたことに伴うもので、残るvitest系依存は@vitest/mockerのみです。magic-string 1.x化とtinybench 6.x化もvitest内部利用に閉じています。
  • v5の破壊的変更(clearMocksデフォルト有効化、vi.mockのトップレベル強制、test.sequential削除、bench API刷新、json/junitレポーターのファイル出力化、設定ファイルの親ディレクトリ探索廃止、ブラウザモードのトークン認証必須化など)は、本リポジトリのテストがdescribe/it/expect/beforeEach/afterEachしか使っていないため該当しません。
  • 実行要件のNode.js ^22.12.0 || ^24 || >=26とVite >=6.4.0は、engines.node: ">=22.22"vite 8.2.2で満たしています。viteのpeerDependency化もnpm利用かつ明示的にdevDependenciesにあるため問題ありません。
  • デフォルトpoolは5でもforksのままなので、process.chdir()を使うtest/delete-merged-branch.test.tsも従来通り動作します。
  • tinybench 6.1.4の型がDOMHighResTimeStampを参照する既知の問題(https://github.com/vitest-dev/vitest/issues/11282)は、`tsconfig.json`で`skipLibCheck: true`にしているため影響しません。
  • @vitest/mockerのパストラバーサル(https://github.com/advisories/GHSA-82fw-gwwq-j7x9)は5.0.0正式版で修正済みです。

engines.nodeとvitestのサポート範囲のずれについては既にインラインコメントで指摘済みのため、今回は再掲しません。CIのテストが通ることが確認できればマージして問題ないと考えます。

Review metadata

@ncaq ncaq closed this Sep 19, 2026
@renovate

renovate Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 5.x releases. But if you manually upgrade to 5.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Type: Dependencies Dependency issues or Changes to dependency files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant