Repository navigation
build(deps-dev): bump vitest and eslint majors with their companions - #228
Conversation
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
✅ Deploy Preview for react-xarrows ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to The Dependabot policy excludes major updates from that group; the inaccurate comment does not change update behavior. No concrete merge-blocking issue remains. Pre-merge checks |
|
…mpanions vitest 3 -> 4 with @vitest/coverage-v8 3 -> 4, and eslint 9 -> 10 with @eslint/js 9 -> 10. Dependabot bumped each main package on its own (#222, without CI noticing. examples/ moves to vitest 4.1.11 as well, since coverage-v8 pins the exact vitest version. Also stops dependabot proposing React majors: the root React is the oldest version the library is tested against, and grouping react with @types/react let the ignored major types bump through (#221).
ca18a5f to
d7b6fa4
Compare
Replaces #222 and #225, and closes the loop on #221.
What Problem This Solves
Dependabot bumps a package's major version on its own, without the package that has to move with it:
@vitest/coverage-v8on 3. coverage-v8 pins the exact vitest version, sotest:coveragebreaks. CI does not run coverage, so build(deps-dev): bump vitest from 3.2.7 to 4.1.11 #222 still went green.@eslint/json 9.dependabot.ymlalready ignores major@types/reactbumps, but grouping it withreactlet one through.Changes
@vitest/coverage-v83 → 4.1.11.examples/vitest 4.1.10 → 4.1.11, since coverage-v8 pins the exact vitest version.@eslint/js9 → 10.0.1.dependabot.ymlignores majorreact/react-dombumps.vitest stays on 4 rather than going to 5:
examples/is already on 4, and this keeps one vitest major in the workspace.Evidence
Run locally:
format:check,lint(0 errors, the same 17 warnings as main),type-check, tests 101/101,test:coverage,build,test:types, and the examples tests and build all pass.pnpm installreports no unmet peers.Not touched: #223 and #224, which are minor/patch updates and get merged as they are.
Summary by CodeRabbit
Security alerts
This also clears 8 of the 9 open dependabot alerts on main, all in dev dependencies: both critical
tinypoolalerts (vitest 4 no longer uses it), the highjs-yamlandsource-map-jsalerts, and the mediumvitest,@vitest/mockerandbrace-expansionalerts. The one left issprintf-js, which has no patched version.