Skip to content

chore(deps): update npm packages - #1779

Merged
fengmk2 merged 8 commits into
mainfrom
renovate/npm-packages
Jun 10, 2026
Merged

chore(deps): update npm packages#1779
fengmk2 merged 8 commits into
mainfrom
renovate/npm-packages

Conversation

@renovate

@renovaterenovateBot commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

PackageChangeAgeAdoptionPassingConfidence
@ast-grep/napi (source)^0.42.1^0.43.0ageadoptionpassingconfidence
@babel/preset-typescript (source)7.28.57.29.7ageadoptionpassingconfidence
@blazediff/core (source)1.9.11.9.2ageadoptionpassingconfidence
@clack/core (source)1.4.01.4.1ageadoptionpassingconfidence
@iconify/vue (source)5.0.05.0.1ageadoptionpassingconfidence
@nkzw/safe-word-list3.1.03.1.2ageadoptionpassingconfidence
@oxlint/plugins (source)=1.61.0=1.68.0ageadoptionpassingconfidence
@rollup/plugin-commonjs (source)29.0.029.0.3ageadoptionpassingconfidence
@typescript/native-preview (source)7.0.0-dev.20260122.27.0.0-dev.20260605.1ageadoptionpassingconfidence
@​voidzero-dev/vitepress-theme4.8.34.8.4ageadoptionpassingconfidence
@yarnpkg/fslib (source)3.1.43.1.5ageadoptionpassingconfidence
bingo (source)0.9.20.9.3ageadoptionpassingconfidence
bingo (source)^0.7.0^0.9.0ageadoptionpassingconfidence
fast-wrap-ansi^0.1.3^0.2.0ageadoptionpassingconfidence
fs-extra11.3.211.3.5ageadoptionpassingconfidence
glob13.0.013.0.6ageadoptionpassingconfidence
minimatch10.2.410.2.5ageadoptionpassingconfidence
mocha (source)11.7.511.7.6ageadoptionpassingconfidence
obug2.1.12.1.2ageadoptionpassingconfidence
pixelmatch7.1.07.2.0ageadoptionpassingconfidence
pkg-types2.3.02.3.1ageadoptionpassingconfidence
playwright (source)1.57.01.60.0ageadoptionpassingconfidence
react (source)19.2.019.2.7ageadoptionpassingconfidence
react-dom (source)19.2.019.2.7ageadoptionpassingconfidence
reka-ui2.9.22.9.9ageadoptionpassingconfidence
remeda (source)2.34.12.37.0ageadoptionpassingconfidence
rollup (source)4.60.44.61.1ageadoptionpassingconfidence
semver7.8.17.8.2ageadoptionpassingconfidence
serve-static2.2.02.2.1ageadoptionpassingconfidence
std-env4.0.04.1.0ageadoptionpassingconfidence
tailwindcss (source)4.2.14.3.0ageadoptionpassingconfidence
tinybench6.0.06.0.2ageadoptionpassingconfidence
typescript (source)6.0.26.0.3ageadoptionpassingconfidence
vitepress (source)2.0.0-alpha.152.0.0-alpha.17ageadoptionpassingconfidence
vitepress-plugin-llms1.12.21.13.1ageadoptionpassingconfidence
vue (source)3.5.303.5.35ageadoptionpassingconfidence
vue3-carousel^0.16.0^0.17.0ageadoptionpassingconfidence
zod (source)4.3.54.4.3ageadoptionpassingconfidence

Release Notes

ast-grep/ast-grep (@​ast-grep/napi)

v0.43.0

Compare Source

  • chore(deps): update dependency @​types/node to v24.12.4 #2636
  • chore(deps): update rust crate assert_cmd to v2.2.2 #2632
  • chore(deps): update rust crate similar to v3.1.1 #2662
  • fix(lsp): initialize tracing subscriber to surface tower-lsp errors #2639
  • fix(deps): update rust-wasm-bindgen monorepo #2660
  • chore(deps): update rust crate tree-sitter to v0.26.9 #2656
  • chore(deps): update rust crate serde_json to v1.0.150 #2659
  • chore(deps): update rust crate clap_complete to v4.6.5 #2634
  • chore(deps): update dependency @​ast-grep/napi to v0.42.3 #2653
  • chore(deps): update dependency oxlint to v1.66.0 #2651
  • chore(deps): update dependency web-tree-sitter to v0.26.9 #2654
  • fix: strip trailing comment artifact in comment suppression #2644
  • feat: support ESQuery style selector in run command #2663
  • feat: add --follow arg for sg test #2657
  • test: add test for run --kind d0d0b30
  • feat: add markdown support beacc9e
  • fix: use Rule instead of pattern in run 2759fda

v0.42.3

Compare Source

19 May 2026

  • feat: support nth-last-child esquery #2631
  • chore(deps): update rust crate dashmap to v6.2.1 #2645
  • chore(deps): update dependency oxlint to v1.65.0 #2635
  • chore(deps): update rust crate napi-derive to v3.5.6 #2642
  • chore(deps): update rust crate napi-build to v2.3.2 #2641
  • chore(deps): update rust crate napi to v3.9.0 #2643
  • chore(deps): update dependency @​ast-grep/napi to v0.42.2 #2630
  • fix: fix windows installation 4021ae0

v0.42.2

Compare Source

  • chore(deps): update rust crate tokio to v1.52.3 #2620
  • fix(deps): update rust-wasm-bindgen monorepo #2623
  • chore(deps): update rust crate clap_complete to v4.6.4 #2627
  • chore(deps): update dependency @​types/node to v24.12.3 #2624
  • chore(deps): update rust crate tree-sitter-swift to v0.7.2 #2619
  • chore(deps): update dependency oxlint to v1.63.0 #2621
  • fix: replace postinstall script with binary resolution in ast-grep #2595
  • fix(lsp): use cwd instead of config dir as workspace fallback #2600
  • fix(deps): update rust-wasm-bindgen monorepo #2613
  • chore(deps): update rust crate napi-derive to v3.5.5 #2615
  • chore(deps): update rust crate napi to v3.8.6 #2614
  • chore(deps): update rust crate clap_complete to v4.6.3 #2610
  • chore(deps): update dependency oxlint to v1.62.0 #2611
  • chore(deps): update astral-sh/setup-uv action to v8 #2604
  • chore(deps): update rust crate tree-sitter-c to v0.24.2 #2608
  • fix(deps): update rust crate tree-sitter-dart to 0.2.0 #2609
  • chore(deps): update robinraju/release-downloader action to v1.13 #2606
  • fix(lsp): report unused suppressions without rules #2607
  • chore(deps): update rust crate clap_complete to v4.6.2 #2589
  • chore(deps): update dependency oxlint to v1.61.0 #2605
  • chore(deps): update rust crate similar to v3.1.0 #2587
  • fix(deps): update rust crate tree-sitter-scala to 0.26.0 #2602
  • chore(deps): update rust crate tree-sitter-scala to v0.25.1 #2601
  • chore(deps): update rust crate tree-sitter-c-sharp to v0.23.5 #2591
  • chore(deps): update dependency oxlint to v1.60.0 #2588
  • chore(deps): update rust crate assert_cmd to v2.2.1 #2599
  • chore(deps): update dependency typescript to v6.0.3 #2598
  • chore(deps): update dependency @​napi-rs/cli to v3.6.2 #2593
  • chore(deps): update rust crate napi-derive to v3.5.4 #2597
  • chore(deps): update rust crate napi to v3.8.5 #2596
  • chore(deps): update rust crate tokio to v1.52.1 #2592
  • chore(deps): update rust crate clap to v4.6.1 #2594
  • chore(deps): update pyo3/maturin-action action to v1.51.0 #2510
  • fix(deps): update rust-wasm-bindgen monorepo #2568
  • chore(deps): update dependency @​napi-rs/cli to v3.6.1 #2583
  • chore(deps): update dependency @​ast-grep/napi to v0.42.1 #2580
  • chore(deps): update dependency oxlint to v1.59.0 #2581
  • chore(deps): update rust crate toml_edit to v0.25.11 #2582
  • chore(deps): update rust crate tokio to v1.51.1 #2584
  • chore(deps): update dependency dprint to v0.54.0 #2585
  • chore(deps): update rust crate clap_complete to v4.6.1 #2586
  • chore(deps): update dependency @​types/node to v24.12.2 #2579
  • fix: enable npx install fallback but still keep postinstall fbc5b9b
  • chore: bump kotlin version 6f09a5b
  • fix: solve linting 945328a
babel/babel (@​babel/preset-typescript)

v7.29.7

Compare Source

v7.29.7 (2026-05-25)

Re-release all packages with npm provenance attestations

teimurjan/blazediff (@​blazediff/core)

v1.9.2

Compare Source

Patch Changes
  • f0c3b78: Speed up core with single pass on no output
bombshell-dev/clack (@​clack/core)

v1.4.1

Compare Source

Patch Changes
rollup/plugins (@​rollup/plugin-commonjs)

v29.0.3

2026-05-29

Bugfixes

v29.0.2

2026-03-06

Bugfixes
  • commonjs: conditional exports (#​1952)

v29.0.1

2026-03-05

Bugfixes
  • commonjs: correctly replaces shorthand "global" property in object (#​1957)
microsoft/typescript-go (@​typescript/native-preview)

v7.0.0-dev.20260605.1

Compare Source

v7.0.0-dev.20260604.1

Compare Source

v7.0.0-dev.20260603.1

Compare Source

v7.0.0-dev.20260602.1

Compare Source

v7.0.0-dev.20260601.1

Compare Source

v7.0.0-dev.20260527.2

Compare Source

v7.0.0-dev.20260527.1

Compare Source

v7.0.0-dev.20260526.1

Compare Source

v7.0.0-dev.20260525.1

Compare Source

v7.0.0-dev.20260524.1

Compare Source

v7.0.0-dev.20260523.1

Compare Source

v7.0.0-dev.20260522.1

Compare Source

v7.0.0-dev.20260521.1

Compare Source

v7.0.0-dev.20260519.1

Compare Source

v7.0.0-dev.20260518.1

Compare Source

v7.0.0-dev.20260517.1

Compare Source

v7.0.0-dev.20260516.1

Compare Source

v7.0.0-dev.20260515.1

Compare Source

v7.0.0-dev.20260514.1

Compare Source

v7.0.0-dev.20260513.1

Compare Source

v7.0.0-dev.20260512.1

Compare Source

v7.0.0-dev.20260511.1

Compare Source

v7.0.0-dev.20260510.1

Compare Source

v7.0.0-dev.20260509.2

Compare Source

v7.0.0-dev.20260508.1

Compare Source

v7.0.0-dev.20260507.1

Compare Source

v7.0.0-dev.20260506.1

Compare Source

v7.0.0-dev.20260505.1

Compare Source

v7.0.0-dev.20260504.1

Compare Source

v7.0.0-dev.20260503.1

Compare Source

v7.0.0-dev.20260502.1

Compare Source

v7.0.0-dev.20260501.1

Compare Source

v7.0.0-dev.20260430.1

Compare Source

v7.0.0-dev.20260429.1

Compare Source

v7.0.0-dev.20260428.1

Compare Source

v7.0.0-dev.20260427.1

Compare Source

v7.0.0-dev.20260426.1

Compare Source

v7.0.0-dev.20260425.1

Compare Source

v7.0.0-dev.20260424.2

Compare Source

v7.0.0-dev.20260424.1

Compare Source

v7.0.0-dev.20260423.1

Compare Source

v7.0.0-dev.20260422.1

Compare Source

v7.0.0-dev.20260421.2

Compare Source

v7.0.0-dev.20260421.1

Compare Source

v7.0.0-dev.20260420.1

Compare Source

v7.0.0-dev.20260419.1

Compare Source

v7.0.0-dev.20260418.1

Compare Source

v7.0.0-dev.20260417.1

Compare Source

v7.0.0-dev.20260416.2

Compare Source

v7.0.0-dev.20260416.1

Compare Source

v7.0.0-dev.20260415.1

Compare Source

v7.0.0-dev.20260414.1

Compare Source

v7.0.0-dev.20260413.1

Compare Source

v7.0.0-dev.20260412.1

Compare Source

v7.0.0-dev.20260411.1

Compare Source

v7.0.0-dev.20260410.1

Compare Source

v7.0.0-dev.20260409.1

Compare Source

v7.0.0-dev.20260408.1

Compare Source

v7.0.0-dev.20260407.1

Compare Source

v7.0.0-dev.20260406.1

Compare Source

v7.0.0-dev.20260405.1

Compare Source

v7.0.0-dev.20260404.1

Compare Source

v7.0.0-dev.20260403.1

Compare Source

v7.0.0-dev.20260401.1

Compare Source

v7.0.0-dev.20260331.1

Compare Source

v7.0.0-dev.20260330.1

[Compare Source](h

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • "before 10am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovateBot commented Jun 7, 2026

Copy link
Copy Markdown
ContributorAuthor

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
Scope: all 6 workspace projects
ENOENT ENOENT: no such file or directory, open '/tmp/renovate/repos/github/voidzero-dev/vite-plus/vite/patches/sirv@3.0.2.patch'
pnpm: ENOENT: no such file or directory, open '/tmp/renovate/repos/github/voidzero-dev/vite-plus/vite/patches/sirv@3.0.2.patch'
at async open (node:internal/fs/promises:639:25)
at async Object.readFile (node:internal/fs/promises:1243:14)
at async readNormalizedFile (/opt/containerbase/tools/pnpm/10.33.2/22.18.0/node_modules/pnpm/dist/pnpm.cjs:51185:23)
at async createHexHashFromFile (/opt/containerbase/tools/pnpm/10.33.2/22.18.0/node_modules/pnpm/dist/pnpm.cjs:51182:28)
at async /opt/containerbase/tools/pnpm/10.33.2/22.18.0/node_modules/pnpm/dist/pnpm.cjs:140925:17
at async /opt/containerbase/tools/pnpm/10.33.2/22.18.0/node_modules/pnpm/dist/pnpm.cjs:140902:24
at async Promise.all (index 0)
at async pMapValue (/opt/containerbase/tools/pnpm/10.33.2/22.18.0/node_modules/pnpm/dist/pnpm.cjs:140901:7)
at async _install (/opt/containerbase/tools/pnpm/10.33.2/22.18.0/node_modules/pnpm/dist/pnpm.cjs:163490:134)
at async mutateModules (/opt/containerbase/tools/pnpm/10.33.2/22.18.0/node_modules/pnpm/dist/pnpm.cjs:163438:23)

@netlify

netlifyBot commented Jun 7, 2026

Copy link
Copy Markdown

Deploy Preview for viteplus-preview ready!

NameLink
🔨 Latest commited9a8fa
🔍 Latest deploy loghttps://app.netlify.com/projects/viteplus-preview/deploys/6a291997433a4d5a51c5ee0e
😎 Deploy Previewhttps://deploy-preview-1779--viteplus-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changesRun an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@socket-security

socket-securityBot commented Jun 7, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​@​iconify/​vue@​5.0.0 ⏵ 5.0.19910010083100
Addednpm/​tailwindcss@​4.3.01001008498100
Updatednpm/​vitepress@​2.0.0-alpha.15 ⏵ 2.0.0-alpha.1798+110086+390100
Updatednpm/​vitepress-plugin-llms@​1.12.2 ⏵ 1.13.193+1100100+195+2100
Updatednpm/​reka-ui@​2.9.2 ⏵ 2.9.99910097+194100

View full report

@socket-security

socket-securityBot commented Jun 7, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm @internationalized/date is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:docs/pnpm-lock.yamlnpm/reka-ui@2.9.9npm/@internationalized/date@3.12.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@internationalized/date@3.12.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

github-actionsBot commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

✅ Staging deployment successful!

Preview: https://viteplus-staging.void.app/
Commit: ed9a8fa

@renovate
renovateBotforce-pushed the renovate/npm-packages branch from c332f66 to 8463529CompareJune 9, 2026 03:11
fengmk2and others added 4 commits June 10, 2026 14:38
Renovate cannot update lockfile artifacts in this repo: pnpm-workspace.yaml
and Cargo.toml reference the gitignored vite/ and rolldown/ checkouts, so
pnpm and cargo fail in Renovate's clone. Add a workflow that checks out the
vendored repos at their pinned hashes and regenerates the lockfiles on
renovate/** branch pushes, disable npm lockfile updates in Renovate, and
ignore the workflow's commits via gitIgnoredAuthors so Renovate keeps
managing the branches.
The workflow's own lockfile push retriggers it in the same concurrency
group, and cancel-in-progress cancelled the effective run at its final
step, leaving a misleading cancelled conclusion.
@fengmk2

This comment was marked as outdated.

@fengmk2fengmk2 self-assigned this Jun 10, 2026
Dependency bumps are exactly what these suites should cover, but the
job gates only fired for labeled PRs, deps/upstream-update, or related
source changes, so Renovate PRs skipped them.
@fengmk2

This comment was marked as off-topic.

@fengmk2

Copy link
Copy Markdown
Member

@codex review

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:6cad03072f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.github/renovate.json Outdated
@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@fengmk2fengmk2 mentioned this pull request Jun 10, 2026
1 task
Keep the mechanism description in the npm block only; the packageRule
description restated it.
updateLockFiles is npm-only and deprecated (it migrates to
skipArtifactsUpdate); the cross-manager option also stops cargo
artifact-update failures on rust crate branches, which the
renovate-lockfiles workflow regenerates as well.
@fengmk2

Copy link
Copy Markdown
Member

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@fengmk2fengmk2 added the test: install-e2e run vite install e2e test label Jun 10, 2026
@fengmk2
fengmk2 merged commit bc79117 into mainJun 10, 2026
184 checks passed
@fengmk2
fengmk2 deleted the renovate/npm-packages branch June 10, 2026 08:11
@fengmk2fengmk2 mentioned this pull request Jun 17, 2026
fengmk2 added a commit that referenced this pull request Jun 17, 2026
Release vite-plus v0.2.0.
Vite+ now consumes upstream Vitest directly (no wrapper), raises the
minimum supported Node.js version to 22.18.0, and ships corepack and
devEngines support.
### Highlights
- **`vp test` now runs upstream Vitest directly (breaking)**: Vite+ used
to ship `@voidzero-dev/vite-plus-test`, a rebundled copy of Vitest that
lagged upstream releases. That package is removed; `vp test` now runs
the real upstream `vitest`, which is installed automatically as a
dependency of `vite-plus` (you no longer add `vitest` or `@vitest/*`
yourself, and `vite` still resolves to `@voidzero-dev/vite-plus-core`
via package-manager overrides). Your `import ... from 'vite-plus/test'`
code keeps working unchanged and `vp migrate` updates existing projects
([#1588](#1588)), by
@Brooooooklyn
- **Minimum supported Node.js version raised to `^22.18.0 || >=24.11.0`
(breaking)**: Node 20 reached end-of-life and the bundled tsdown already
required `^22.18.0`, so the published engines range now matches what `vp
pack` can actually deliver; `vp exec` / `vp run` / `vp dlx` reject
projects resolving an older Node with the existing incompatibility error
([#1813](#1813)), by
@fengmk2
- **Corepack now works under Vite+**: `corepack` is a default `vp env
setup` shim, resolved managed-global, then Node-bundled (Node <= 24),
then auto-installed (Node 25+, which dropped corepack); `corepack
enable` / `disable` land their pnpm/yarn launchers on PATH and
Vite+-owned shims are restored if corepack replaces them
([#1808](#1808)), by
@fengmk2
- **devEngines support for runtime and package-manager selection**:
Vite+ reads `devEngines.runtime` (ranked above `engines.node`) and
`devEngines.packageManager`; auto-pin and `vp migrate` write
`devEngines.packageManager`, `vp env pin` / `unpin` target
`devEngines.runtime`, and `vp env doctor` reports conflicts instead of
silently resolving them
([#1760](#1760)), by
@fengmk2
### Features
- `vp pm approve-builds`: forward to npm's new `approve-scripts` /
`deny-scripts` (npm >= 11.16.0) instead of the previous no-op, matching
`pnpm approve-builds` / `bun pm trust`; mixed approve+deny is rejected
with actionable guidance and npm's advisory-only caveat is surfaced
([#1733](#1733)), by
@fengmk2
- `vp create`: support local monorepo templates declared in
`create.templates` in `vite.config.ts`; `vp create vite:generator`
scaffolds a Bingo generator and auto-registers it in the picker,
replacing the old package.json-keyword inference
([#1777](#1777)), by
@fengmk2
- `vp create`: detect direct dependencies whose build scripts the
package manager gated (e.g. native builds like `better-sqlite3`) and act
on them; prompt to approve each (default off) interactively, point at
`vp pm approve-builds` non-interactively, or build them with
`--approve-builds`
([#1828](#1828)), by
@fengmk2
- `vp config`: add `--no-hooks` and `--no-agent` opt-outs to skip
git-hook installation and coding-agent instruction updates
([#1842](#1842)), by
@leno23
- `vp list -g`: sort the global package list output so entries appear in
a stable order
([#1748](#1748)), by
@liangmiQwQ
- Upgrade upstream dependencies: rolldown `1.0.3 -> 1.1.1`, tsdown
`0.22.1 -> 0.22.3`, oxlint `1.67.0 -> 1.70.0`, oxfmt `0.52.0 -> 0.55.0`,
vitest `4.1.8 -> 4.1.9`, and the oxc toolchain `0.133.0 -> 0.136.0`
([#1749](#1749),
[#1767](#1767),
[#1812](#1812),
[#1834](#1834),
[#1855](#1855)), by
@voidzero-guard[bot]
### Fixes & Enhancements
- Security: resolve open Rust Dependabot advisories by bumping
transitive `openssl` `0.10.76 -> 0.10.80` (`openssl-sys` `0.9.112 ->
0.9.116`), fixing five high-severity rust-openssl issues (buffer
overflows in key derivation, AES key wrap, and digest finalization; an
unchecked PSK/cookie trampoline length leaking adjacent memory; and
OCSP-responder undefined behavior:
[GHSA-pqf5-4pqq-29f5](GHSA-pqf5-4pqq-29f5),
[GHSA-8c75-8mhr-p7r9](GHSA-8c75-8mhr-p7r9),
[GHSA-ghm9-cr32-g9qj](GHSA-ghm9-cr32-g9qj),
[GHSA-hppc-g8h3-xhp3](GHSA-hppc-g8h3-xhp3),
[GHSA-xp3w-r5p5-63rr](GHSA-xp3w-r5p5-63rr)),
and drop the unmaintained, unsound `libyml`
([GHSA-gfxp-f68g-8x78](GHSA-gfxp-f68g-8x78),
high) by removing dead `serde_yml` code
([#1742](#1742)), by
@fengmk2
- Security (docs site): update `mermaid` `11.13.0 -> 11.15.0` to fix
improper `classDef` sanitization in state diagrams that allowed HTML
injection
([CVE-2026-41149](https://nvd.nist.gov/vuln/detail/CVE-2026-41149) /
[GHSA-ghcm-xqfw-q4vr](GHSA-ghcm-xqfw-q4vr),
medium severity; `<script>` tags are stripped so it does not reach XSS)
([#1745](#1745)), by
@renovate[bot]
- `vp check --fix` / `vp staged`: create/migrate now wrap inline Vite
`plugins: [...]` arrays with `lazyPlugins(...)` so plugin factories
aren't eagerly executed (and don't hang on open handles) during
lint/format/check config loading
([#1752](#1752)), by
@jong-kyung
- `vp migrate`: complete pending migration work for projects that
already have `vite-plus` installed (scripts, imports, tsconfig types,
ESLint/Prettier, legacy hooks, package-manager settings) instead of
treating `vite-plus` as migration-complete; fully migrated projects stay
idempotent
([#1821](#1821)), by
@jong-kyung
- `vp create` / `vp migrate`: detect shorthand `fmt,` / `lint,` config
keys so a duplicate inline block is no longer injected
([#1843](#1843)), by
@fengmk2
- IDE oxlint/oxfmt wrappers: set `VP_COMMAND` so `lazyPlugins()` skips
framework plugins during LSP config reads, preventing a stray
`.svelte-kit` (and similar) directory at the monorepo root
([#1764](#1764)), by
@jong-kyung
- `vp lint` / `vp run -r lint` on Windows: keep the absolute `tsgolint`
path for workspace lint runs instead of downgrading it to a wrong
cwd-relative path
([#1758](#1758)), by
@semimikoh
- oxlint wrapper: set the `tsgolint` path so type-aware lint resolves it
([#1811](#1811)), by
@jong-kyung
- `vp install -g`: use a unique backup directory and treat stale-backup
cleanup as best-effort so a locked Windows binary no longer fails an
otherwise successful reinstall
([#1753](#1753)), by
@fengmk2
- `vp install -g`: remove stale managed binary shims when a reinstalled
package drops a bin from its `package.json#bin`
([#1765](#1765)), by
@liangmiQwQ
- `vp create --git`: surface git's actual stdout/stderr when the initial
commit fails instead of always blaming `user.name` / `user.email`
([#1819](#1819)), by
@fengmk2
- `vp create vite:generator`: reject `--git` / `--no-git`, since adding
a generator to an existing monorepo does not initialize git
([#1788](#1788)), by
@jong-kyung
- Global CLI: harden `find_system_tool` against a self-exec loop (skip
the running executable's own bin directory) and fix two
`vite_global_cli` tests that could hang
([#1820](#1820)), by
@fengmk2
- CLI help: unify alias display
([#1832](#1832)), show
supported `run` options
([#1797](#1797)), show
`--fail-if-no-match` in `exec` help
([#1798](#1798)), add the
`implode` documentation link
([#1796](#1796)), and
handle nested-command typo help
([#1803](#1803)), by
@jong-kyung
### Docs
- Document `vp create` opt-out options
([#1790](#1790)), by
@jong-kyung
- Document `vp upgrade` options
([#1847](#1847)), by
@jong-kyung
- Align the config overview with the sidebar
([#1846](#1846)), by
@jong-kyung
- Sync the documented command lists with the help output
([#1850](#1850)), by
@jong-kyung
- Clarify lazy plugin side effects
([#1841](#1841)), by
@leno23
- Add JongKyung's X profile
([#1844](#1844)) and
update Christoph's X profile
([#1845](#1845)) on the
team page, by @jong-kyung
### Refactor
- Remove the CLI tips system; the shortcuts it printed on `vp install`
are already covered by the help system and added unnecessary complexity
([#1799](#1799)), by
@cpojer
### Chore
- Re-enable Renovate dependency updates with a targeted ignore-list
([#1744](#1744)), by
@fengmk2
- Keep generated NAPI bindings during upgrade-deps
([#1759](#1759)), by
@fengmk2
- Remove the `vite_glob` dependency from vite-plus
([#1763](#1763)), by
@wan9chi
- Keep `sync-remote` from churning `pnpm-workspace.yaml` (dedupe
`minimumReleaseAgeExclude`, preserve comments)
([#1787](#1787)), by
@fengmk2
- Make unix `just test` runnable
([#1755](#1755)), by
@situ2001
- CI: reuse `just lint` and `just test` as the single source of truth
([#1809](#1809)), pin
`cargo-zigbuild` to a git rev to fix the aarch64-musl link failure
([#1815](#1815)), and keep
upgrade-deps green when rolldown bumps oxc
([#1833](#1833)), by
@fengmk2
- Update Rust to nightly-2026-06-10
([#1725](#1725)), typos to
v1.47.1 / v1.47.2
([#1772](#1772),
[#1775](#1775)), GitHub
Actions ([#1778](#1778),
[#1829](#1829)), and npm
packages ([#1779](#1779)),
by @renovate[bot]
- Bump `oxc-project/setup-node` to v1.3.1
([#1792](#1792)), by
@Boshen
- Refresh trusted stack stats on the docs homepage
([#1786](#1786),
[#1837](#1837)), by
@voidzero-guard[bot]
### Bundled Versions
| Tool | Version | Source |
| --- | --- | --- |
| vite | `8.0.16` |
[`f94df87`](vitejs/vite@f94df87)
|
| rolldown | `1.1.1` |
[`d7f919c`](rolldown/rolldown@d7f919c)
|
| tsdown | `0.22.3` | [npm](https://npmx.dev/package/tsdown/v/0.22.3) |
| vitest | `4.1.9` | [npm](https://npmx.dev/package/vitest/v/4.1.9) |
| oxlint | `1.70.0` | [npm](https://npmx.dev/package/oxlint/v/1.70.0) |
| oxlint-tsgolint | `0.23.0` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/0.23.0) |
| oxfmt | `0.55.0` | [npm](https://npmx.dev/package/oxfmt/v/0.55.0) |
### Upgrading from 0.1.24 to 0.2.0
This release has two breaking changes. For most projects the upgrade is
`vp upgrade`, bump the project's `vite-plus`, then `vp migrate`.
#### 1. Update the CLI
```bash
vp upgrade
```
#### 2. Node.js 20 is no longer supported
The minimum supported Node.js version is now `^22.18.0 || >=24.11.0`
(Node 20 reached end-of-life). If you are still on Node 20:
- Check your version: `node --version` (or `vp env doctor`)
- Move to a supported release: `vp env pin 22.18.0` (or a newer LTS), or
update your `.node-version` / `devEngines.runtime`
`vp exec` / `vp run` / `vp dlx` now refuse to run against a project that
resolves Node < 22.18.0.
#### 3. Vitest is now upstream (the wrapper is gone)
`@voidzero-dev/vite-plus-test` has been removed; Vite+ consumes upstream
`vitest` directly. Bump `vite-plus` first, then migrate:
```bash
vp update vite-plus --latest # project's vite-plus -> 0.2.0 (ignores the old range, updates the lockfile); monorepo: add -r
vp migrate # local vite-plus is now 0.2.0, so the new migration runs
```
`vp update --latest` re-resolves `vite-plus` to the newest release
regardless of the old semver range, so the lockfile cannot pin you back
to 0.1.24. The project's local `vite-plus` is then 0.2.0, and since the
global `vp` delegates `migrate` to the project's local install, `vp
migrate` runs the new migration.
- Your `import { vi, ... } from 'vite-plus/test'` code is unchanged. `vp
migrate` rewrites any leftover `vitest` / `@vitest/*` imports and
normalizes stale `vitest: npm:@voidzero-dev/vite-plus-test@*` aliases.
- You no longer add `vitest` or `@vitest/*` yourself; they arrive
transitively through `vite-plus`.
### New Contributors
Welcome to our new contributor @situ2001! 🎉
**Full Changelog**:
v0.1.24...v0.2.0
---
Merging this PR will trigger the release workflow.
---------
Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK <fengmk2@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test: install-e2erun vite install e2e test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@fengmk2