Uh oh!
There was an error while loading. Please reload this page.
fix(static_config): only trust defineConfig fromvite-plus - #2060
Conversation
✅ Deploy Preview for viteplus-preview canceled.
|
liangmiQwQ
commented
Jul 6, 2026
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit:bf702d8c87
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
liangmiQwQ
commented
Jul 6, 2026
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit:2d343cc552
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
liangmiQwQ
commented
Jul 6, 2026
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit:4bded2ec89
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Uh oh!
There was an error while loading. Please reload this page.
liangmiQwQ
commented
Jul 6, 2026
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit:1cae72a270
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
defineConfig from untrusted sourcesdefineConfig fromvitestdefineConfig fromvitestdefineConfig fromvite-plusliangmiQwQ
commented
Jul 6, 2026
@codex review |
Codex Review: Didn't find any major issues. Delightful! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
fengmk2
left a comment
There was a problem hiding this comment.
@liangmiQwQ That was indeed a problem, thank you for fixing it.
fengmk2
commented
Jul 6, 2026
@liangmiQwQ Could you add the error message to the PR description? This way, people can get a clearer understanding of the specific issue being fixed. Even if I know what the error is, others who are unfamiliar with it should be able to understand the problem at a glance. |
liangmiQwQ
commented
Jul 6, 2026
@fengmk2 It may just be simple |
fengmk2
commented
Jul 6, 2026
@liangmiQwQ I will run a round simplify before I merge. |
- Reuse oxc's ModuleExportName::name() instead of the hand-rolled three-variant matcher. - Collapse the eager import scan plus interleaved mutable flag into a single immutable pass over the program body. - Extract the duplicated "vite-plus" / "defineConfig" literals into named constants.
336d469 to
4e5a3cbCompareUh oh!
There was an error while loading. Please reload this page.
…xes (#2081) Release vite-plus v0.2.3: config extraction, create, and `vp run` reliability fixes. A patch release that restores static config extraction for projects importing `defineConfig` from `vite`, fixes `vp create` for org templates on registries that strip custom package fields, cleans up terminal output after Ctrl-C during `vp run`, and updates bundled Vite to 8.1.3. ### Highlights - **Custom `VP_HOME` is honored on every run**: the global `vp` now respects a user-set `VP_HOME` for its home directory instead of falling back to `~/.vite-plus`, and persists it in the generated env files, so a custom install location no longer produces multiple instances or unusable packages ([#2029](#2029)), by @liangmiQwQ ### Features - Upgrade bundled Vite from `8.1.2` to `8.1.3` (inlined CSS after the shebang line, CSS preload for nested dynamic imports, SSR stacktrace column fix) ([#2042](#2042)), by @voidzero-guard[bot] ### Fixes & Enhancements - `vp run` no longer misreads a `vite.config.ts` when its `defineConfig` comes from a preset or a custom wrapper instead of `vite-plus` or `vite`. Such configs are now evaluated at runtime rather than assumed to be Vite+'s own, so projects that use them no longer wrongly report `Task "build" not found` ([#2060](#2060), [#2075](#2075)), by @liangmiQwQ and @fengmk2 - Killing a `vp run` task with Ctrl-C no longer leaves odd OSC escape sequences in the terminal; `vp` defers its own Ctrl-C handling until the child process exits ([#2079](#2079)), by @forehalo - `vp migrate`: rewriting a `package.json` prettier script now emits a single `--check`, so scripts that combined `--check` with `--list-different` / `-l` / `-c` no longer produce a duplicated `vp fmt --check --check` ([#2044](#2044)), by @shulaoda - `vp create @org:name`: read the org template catalog (`createConfig`) from the published tarball when the registry (e.g. GitHub Packages) strips custom fields from packument metadata ([#2063](#2063)), by @hiro-daikin - `vp run`: missing env vars requested through `@voidzero-dev/vite-task-client` now return `undefined` instead of `null`, preserving Vite production `NODE_ENV` semantics when builds run through `vp run` ([vite-task#508](voidzero-dev/vite-task#508), via [#2076](#2076)), by @wan9chi ### Refactor - `static_config`: drop the unreachable `vite.config.json` branch ([#2045](#2045)), and remove unused exported CLI helpers ([#2046](#2046)), by @shulaoda ### Docs - Update the announcement links and callout for the beta release ([#2027](#2027)), remove the stale `Dockerfile.alpine` comment ([#2068](#2068)), by @fengmk2 - Add the missing `pnpm-workspace.yaml` to the docs Dockerfile ([#2059](#2059)), by @wan-kong - Refresh the root agent guide ([#2072](#2072)), by @jong-kyung ### Chore - Cross-compile Windows tests and CLI binaries on Linux with cargo-xwin ([#1824](#1824)), install local vite-plus builds through a local npm registry ([#2021](#2021)), fast docs format check for docs-only PRs ([#2028](#2028)), pack local dirs for the registry bridge instead of pkg.pr.new ([#2038](#2038)), remove the stale create workflow updater ([#2061](#2061)), and add PTY-based interactive CLI snapshot tests ([#2052](#2052)), by @fengmk2 - Cache `vp run` output for docs builds ([#2006](#2006)), by @wan9chi - Remove legacy completion cleanup ([#2050](#2050)), by @nekomoyi - Update the crate-ci/typos action ([#2039](#2039)) and GitHub Actions ([#2055](#2055), [#1905](#1905)), by @renovate[bot] - Refresh the Node.js release keyring ([#2058](#2058)) and the docs trusted-stack stats ([#2064](#2064)), by @voidzero-guard[bot] ### Bundled Versions | Tool | Version | Source | | --- | --- | --- | | vite | `8.1.3` | [`578ffb8`](vitejs/vite@578ffb8) | | rolldown | `1.1.4` | [`6cbd233`](rolldown/rolldown@6cbd233) | | tsdown | `0.22.3` | [npm](https://npmx.dev/package/tsdown/v/0.22.3) | | vitest | `4.1.9` | [npm](https://npmx.dev/package/vitest/v/4.1.9) | | oxlint | `1.72.0` | [npm](https://npmx.dev/package/oxlint/v/1.72.0) | | oxlint-tsgolint | `0.24.0` | [npm](https://npmx.dev/package/oxlint-tsgolint/v/0.24.0) | | oxfmt | `0.57.0` | [npm](https://npmx.dev/package/oxfmt/v/0.57.0) | ### Upgrade ```bash vp upgrade ``` ### New Contributors @wan-kong and @hiro-daikin made their first contributions. **Full Changelog**: v0.2.2...v0.2.3 --- Merging this PR will trigger the release workflow. --------- Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com> Co-authored-by: wan9chi <dk4rest@gmail.com>
At present, static config only checks if the
export defaultstatement's callee isdefineConfig.So, if I import
defineConfigfrom other sources and modify the input in the function, or define a variable calleddefineConfig, the static config analyze will get broken.For example, if you are using a preset which automatically generates tasks, you will get:
If the
defineConfigmodify its import structure, you may get:This PR adds source check and only trust
defineConfigfromvite-pluspackage.This problem is discovered when I am doing attempts in my personal Vite+ config preset.
🤖 Generated with Codex