Skip to content

Bump @vitest/mocker, @vitest/coverage-v8, @vitest/ui and vitest in /web - #15

Merged
and3rn3t merged 1 commit into
mainfrom
dependabot/npm_and_yarn/web/multi-77af0a84ba
Sep 19, 2026
Merged

and3rn3t merged 1 commit into
mainfrom
dependabot/npm_and_yarn/web/multi-77af0a84ba

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bumps @vitest/mocker to 5.0.1 and updates ancestor dependencies @vitest/mocker, @vitest/coverage-v8, @vitest/ui and vitest. These dependencies need to be updated together.

Updates @vitest/mocker from 3.2.6 to 5.0.1

Release notes

Sourced from @​vitest/mocker's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits

Updates @vitest/coverage-v8 from 3.2.6 to 5.0.1

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits

Updates @vitest/ui from 3.2.6 to 5.0.1

Release notes

Sourced from @​vitest/ui's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits

Updates vitest from 3.2.6 to 5.0.1

Release notes

Sourced from vitest's releases.

v5.0.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits
  • 03630a5 chore: release v5.0.1 (#11275)
  • a47d790 fix(fakeTimers): force queueMicrotask and nextTick in toNotFake (#11261)
  • 2ce29d5 fix: warn when deprecated deps.optimizer.web is used (#11214)
  • ccd6d05 docs: fix typecheck exclude default in documentation (#11223)
  • 91ab158 fix(doctor): measure vm pools for custom environments (#11212)
  • 23dda73 fix: share the server on self-referencing extends (#11034)
  • 498fbe9 fix: resolve ResolvedConfig exactOptionalPropertyTypes errors (#11175)
  • 115c3f6 fix: correct typos in error message and comments (#11187)
  • 7361465 fix: keep metadata file when clearing the cache (#11199)
  • 972e24b fix(browser): avoid double quotes in config.define (#11198)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Dependency updates javascript Pull requests that update javascript code labels Sep 10, 2026
@github-actions github-actions Bot removed the dependencies Dependency updates label Sep 10, 2026
@github-actions

github-actions Bot commented Sep 10, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@jridgewell/sourcemap-codec 1.6.0 UnknownUnknown
npm/@vitest/coverage-v8 5.0.1 UnknownUnknown
npm/@vitest/istanbul-lib-coverage 1.0.1 UnknownUnknown
npm/@vitest/istanbul-lib-report 1.0.1 UnknownUnknown
npm/@vitest/mocker 5.0.1 UnknownUnknown
npm/@vitest/pretty-format 5.0.1 UnknownUnknown
npm/@vitest/spy 5.0.1 UnknownUnknown
npm/@vitest/ui 5.0.1 UnknownUnknown
npm/@vitest/utils 5.0.1 UnknownUnknown
npm/ast-v8-to-istanbul 1.0.6 UnknownUnknown
npm/chai 6.2.2 🟢 7.1
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 8Found 4/5 approved changesets -- score normalized to 8
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Packaging🟢 10packaging workflow detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/es-module-lexer 2.3.2 🟢 4.5
Details
CheckScoreReason
Code-Review⚠️ 2Found 6/30 approved changesets -- score normalized to 2
Maintained🟢 1030 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/flatted 3.4.4 🟢 4.3
Details
CheckScoreReason
Code-Review⚠️ 0Found 2/22 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 88 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 8
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 4security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
SAST🟢 6SAST tool is not run on all commits -- score normalized to 6
npm/magic-string 1.4.1 🟢 5.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 6Found 19/30 approved changesets -- score normalized to 6
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/magicast 0.5.5 UnknownUnknown
npm/obug 2.2.1 UnknownUnknown
npm/picomatch 4.0.7 🟢 6.8
Details
CheckScoreReason
Code-Review🟢 5Found 7/13 approved changesets -- score normalized to 5
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST🟢 5SAST tool is not run on all commits -- score normalized to 5
npm/std-env 4.2.0 UnknownUnknown
npm/tinybench 6.1.4 UnknownUnknown
npm/tinyexec 1.3.0 UnknownUnknown
npm/tinyglobby 0.2.17 UnknownUnknown
npm/tinyrainbow 3.1.1 UnknownUnknown
npm/vitest 5.0.1 UnknownUnknown

Scanned Files

  • web/package-lock.json

@socket-security

socket-security Bot commented Sep 10, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​vitest/​ui@​3.2.6 ⏵ 5.0.19910075 -698100
Updatednpm/​@​vitest/​coverage-v8@​3.2.6 ⏵ 5.0.19910079 +798100
Updatednpm/​vitest@​3.2.6 ⏵ 5.0.198 +1100 +279 +199 +1100

View full report

@and3rn3t

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/multi-77af0a84ba branch from e141c15 to 590b854 Compare September 19, 2026 04:58
and3rn3t added a commit that referenced this pull request Sep 19, 2026
…adroom (#20)

The coverage gate is `fail_under = 40` and main sat at exactly 40.00%, so any
change that adds statements without tests tips it under. Dependabot #15, which
touches only web/ files, failed its Python job at 39.95% for precisely that
reason: the log-stream rewrite and the secret-key resolver added statements to
api/server.py without adding tests for them.

Rather than lower the gate, cover the two pieces that had none.

run_script is the subprocess wrapper behind every management endpoint, and had
no direct coverage: endpoints that call it mock it out wholesale, so the
not-found path, the exception path and the timeout handling were never
exercised. The timeout is the part worth testing, since it is what stops a
real-sized backup being reported as a failure.

The WebSocket log stream had none either. These tests pin the behaviour the
rewrite is for: one follower process no matter how many clients subscribe,
every line fanned out to every subscriber in order, blank lines dropped, the
follower stopping when the last client leaves, the child process reaped on the
way out, and a clear error rather than a crash when Docker is absent. The
disconnect test covers why it uses discard rather than remove: a disconnect can
arrive for a session already dropped, and that must not raise.

Coverage 40.00% -> 41.98%, tests 193 -> 221.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@and3rn3t

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [@vitest/mocker](https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker) to 5.0.1 and updates ancestor dependencies [@vitest/mocker](https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker), [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8), [@vitest/ui](https://github.com/vitest-dev/vitest/tree/HEAD/packages/ui) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest). These dependencies need to be updated together.


Updates `@vitest/mocker` from 3.2.6 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/mocker)

Updates `@vitest/coverage-v8` from 3.2.6 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/coverage-v8)

Updates `@vitest/ui` from 3.2.6 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/ui)

Updates `vitest` from 3.2.6 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.0
  dependency-type: direct:development
- dependency-name: "@vitest/mocker"
  dependency-version: 5.0.0
  dependency-type: indirect
- dependency-name: "@vitest/ui"
  dependency-version: 5.0.0
  dependency-type: direct:development
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/multi-77af0a84ba branch from 590b854 to f98e38f Compare September 19, 2026 05:05
@and3rn3t
and3rn3t merged commit edc354e into main Sep 19, 2026
17 checks passed
@and3rn3t
and3rn3t deleted the dependabot/npm_and_yarn/web/multi-77af0a84ba branch September 19, 2026 05:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant