Skip to content

chore(deps-dev): bump the npm_and_yarn group across 8 directories with 1 update#4835

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/realtime/npm_and_yarn-3edb4aa9a2
Closed

chore(deps-dev): bump the npm_and_yarn group across 8 directories with 1 update#4835
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/realtime/npm_and_yarn-3edb4aa9a2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jun 1, 2026

Bumps the npm_and_yarn group with 1 update in the /apps/realtime directory: vitest.
Bumps the npm_and_yarn group with 1 update in the /apps/sim directory: vitest.
Bumps the npm_and_yarn group with 1 update in the /packages/audit directory: vitest.
Bumps the npm_and_yarn group with 1 update in the /packages/logger directory: vitest.
Bumps the npm_and_yarn group with 1 update in the /packages/security directory: vitest.
Bumps the npm_and_yarn group with 1 update in the /packages/testing directory: vitest.
Bumps the npm_and_yarn group with 1 update in the /packages/ts-sdk directory: vitest.
Bumps the npm_and_yarn group with 1 update in the /packages/utils directory: vitest.

Updates vitest from 3.2.6 to 4.1.8

Release notes

Sourced from vitest's releases.

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.1.5

   🚀 Experimental Features

   🐞 Bug Fixes

    View changes on GitHub

... (truncated)

Commits
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • a09d472 chore: release v4.1.7
  • a8fd24c chore: release v4.1.6
  • 18af98c fix(browser): simplify orchestrator otel carrier (#10285)
  • 3188260 feat(browser): provide project reference in ToMatchScreenshotResolvePath (#...
  • e399846 chore: release v4.1.5
  • 7dc6d54 Revert "fix: respect diff config options in soft assertions (#8696)"
  • 9787ded fix: respect diff config options in soft assertions (#8696)
  • 325463a fix(ast-collect): recognize _vi_import prefix in static test discovery (#10...
  • Additional commits viewable in compare view

Updates vitest from 3.2.6 to 4.1.8

Release notes

Sourced from vitest's releases.

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.1.5

   🚀 Experimental Features

   🐞 Bug Fixes

    View changes on GitHub

... (truncated)

Commits
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • a09d472 chore: release v4.1.7
  • a8fd24c chore: release v4.1.6
  • 18af98c fix(browser): simplify orchestrator otel carrier (#10285)
  • 3188260 feat(browser): provide project reference in ToMatchScreenshotResolvePath (#...
  • e399846 chore: release v4.1.5
  • 7dc6d54 Revert "fix: respect diff config options in soft assertions (#8696)"
  • 9787ded fix: respect diff config options in soft assertions (#8696)
  • 325463a fix(ast-collect): recognize _vi_import prefix in static test discovery (#10...
  • Additional commits viewable in compare view

Updates vitest from 3.2.6 to 4.1.8

Release notes

Sourced from vitest's releases.

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.1.5

   🚀 Experimental Features

   🐞 Bug Fixes

    View changes on GitHub

... (truncated)

Commits
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • a09d472 chore: release v4.1.7
  • a8fd24c chore: release v4.1.6
  • 18af98c fix(browser): simplify orchestrator otel carrier (#10285)
  • 3188260 feat(browser): provide project reference in ToMatchScreenshotResolvePath (#...
  • e399846 chore: release v4.1.5
  • 7dc6d54 Revert "fix: respect diff config options in soft assertions (#8696)"
  • 9787ded fix: respect diff config options in soft assertions (#8696)
  • 325463a fix(ast-collect): recognize _vi_import prefix in static test discovery (#10...
  • Additional commits viewable in compare view

Updates vitest from 3.2.6 to 4.1.8

Release notes

Sourced from vitest's releases.

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.1.5

   🚀 Experimental Features

   🐞 Bug Fixes

    View changes on GitHub

... (truncated)

Commits
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • a09d472 chore: release v4.1.7
  • a8fd24c chore: release v4.1.6
  • 18af98c fix(browser): simplify orchestrator otel carrier (#10285)
  • 3188260 feat(browser): provide project reference in ToMatchScreenshotResolvePath (#...
  • e399846 chore: release v4.1.5
  • 7dc6d54 Revert "fix: respect diff config options in soft assertions (#8696)"
  • 9787ded fix: respect diff config options in soft assertions (#8696)
  • 325463a fix(ast-collect): recognize _vi_import prefix in static test discovery (#10...
  • Additional commits viewable in compare view

Updates vitest from 3.2.6 to 4.1.8

Release notes

Sourced from vitest's releases.

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.1.5

   🚀 Experimental Features

   🐞 Bug Fixes

    View changes on GitHub

... (truncated)

Commits
  • e61f2dd chore: release v4.1.8
  • e4067b3 fix(browser): disable client cdp API when allowWrite/allowExec: false [ba...
  • a09d472 chore: release v4.1.7
  • a8fd24c chore: release v4.1.6
  • 18af98c fix(browser): simplify orchestrator otel carrier (#10285)
  • 3188260 feat(browser): provide project reference in ToMatchScreenshotResolvePath (#...
  • e399846 chore: release v4.1.5
  • 7dc6d54 Revert "fix: respect diff config options in soft assertions (#8696)"
  • 9787ded fix: respect diff config options in soft assertions (#8696)
  • 325463a fix(ast-collect): recognize _vi_import prefix in static test discovery (#10...
  • Additional commits viewable in compare view

Updates vitest from 3.2.6 to 4.1.8

Release notes

Sourced from vitest's releases.

v4.1.8

   🐞 Bug Fixes

    View changes on GitHub

v4.1.7

   🐞 Bug Fixes

    View changes on GitHub

v4.1.6

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub

v4.1.5

   🚀 Experimental Features

   🐞 Bug Fixes

…h 1 update

Bumps the npm_and_yarn group with 1 update in the /apps/realtime directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).
Bumps the npm_and_yarn group with 1 update in the /apps/sim directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).
Bumps the npm_and_yarn group with 1 update in the /packages/audit directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).
Bumps the npm_and_yarn group with 1 update in the /packages/logger directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).
Bumps the npm_and_yarn group with 1 update in the /packages/security directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).
Bumps the npm_and_yarn group with 1 update in the /packages/testing directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).
Bumps the npm_and_yarn group with 1 update in the /packages/ts-sdk directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).
Bumps the npm_and_yarn group with 1 update in the /packages/utils directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

Updates `vitest` from 3.2.6 to 4.1.8
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: vitest
  dependency-version: 4.1.8
  dependency-type: direct:development
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 1, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented Jun 1, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs Error Error Jun 1, 2026 8:47pm

Request Review

@cursor
Copy link
Copy Markdown

cursor Bot commented Jun 1, 2026

PR Summary

Medium Risk
Major-version test runner upgrade across the monorepo can break tests or tooling; peer @sim/testing and @vitest/coverage-v8 v3 pins were not updated in this diff.

Overview
This PR bumps the devDependency vitest from ^3.0.8 to ^4.1.8 in eight workspaces: apps/realtime, apps/sim, and packages audit, logger, security, testing, ts-sdk, and utils. No application source, Vitest config files, or test scripts change—only package.json version pins.

Reviewers should note what the diff does not update: @sim/testing still declares peerDependencies.vitest as ^3.0.0, and apps/sim / packages/ts-sdk still pin @vitest/coverage-v8 at ^3.0.8 while Vitest itself moves to v4. CI and local vitest run / coverage may need a follow-up if installs or coverage plugins complain about version skew.

Reviewed by Cursor Bugbot for commit 84e7e73. Bugbot is set up for automated code reviews on this repo. Configure here.

Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 84e7e73. Configure here.

Comment thread apps/sim/package.json
"typescript": "^5.7.3",
"vite-tsconfig-paths": "^5.1.4",
"vitest": "^3.0.8"
"vitest": "^4.1.8"
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Vitest and coverage-v8 major version mismatch

High Severity

@vitest/coverage-v8 remains at ^3.0.8 while vitest is bumped to ^4.1.8. Vitest requires its companion packages to share the same major version and actively warns (or errors) on mismatch. This will cause coverage collection to fail at runtime in both apps/sim and packages/ts-sdk.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 84e7e73. Configure here.

"@sim/tsconfig": "workspace:*",
"typescript": "^5.7.3",
"vitest": "^3.0.8"
"vitest": "^4.1.8"
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Outdated peerDependencies for vitest in testing package

Medium Severity

The peerDependencies declares "vitest": "^3.0.0" but devDependencies now uses ^4.1.8. All consumer packages also use vitest 4.x, so the peer dependency range is unsatisfied, generating warnings or install failures depending on the package manager's strictness settings.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 84e7e73. Configure here.

@greptile-apps
Copy link
Copy Markdown
Contributor

greptile-apps Bot commented Jun 1, 2026

Greptile Summary

This is an automated dependabot bump of vitest from ^3.0.8 to ^4.1.8 across 8 workspace packages. The upgrade spans a major version boundary (v3 → v4) and picks up numerous bug fixes in the runner, browser mode, coverage, and snapshot subsystems.

  • Seven of the eight packages update only vitest and are straightforward.
  • packages/ts-sdk also depends on @vitest/coverage-v8, which was left at ^3.0.8 while vitest was bumped to ^4.1.8, creating a major-version mismatch that will break coverage reporting.

Confidence Score: 3/5

Safe to merge only after aligning @vitest/coverage-v8 to ^4.1.8 in packages/ts-sdk; the mismatch will break coverage runs in that package.

All seven other packages are straightforward version bumps with no issues. The single problem is in packages/ts-sdk, where @vitest/coverage-v8 was not updated alongside vitest — these companion packages require matching major versions, so coverage collection will fail until this is corrected.

packages/ts-sdk/package.json requires @vitest/coverage-v8 to be bumped to ^4.1.8 to match the new vitest version.

Important Files Changed

Filename Overview
packages/ts-sdk/package.json Bumps vitest to ^4.1.8 but leaves companion @vitest/coverage-v8 at ^3.0.8 — major version mismatch will break coverage reporting.
apps/realtime/package.json Bumps vitest from ^3.0.8 to ^4.1.8 with no other changes; looks correct.
apps/sim/package.json Bumps vitest from ^3.0.8 to ^4.1.8 with no other changes; looks correct.
packages/audit/package.json Bumps vitest from ^3.0.8 to ^4.1.8 with no other changes; looks correct.
packages/logger/package.json Bumps vitest from ^3.0.8 to ^4.1.8 with no other changes; looks correct.
packages/security/package.json Bumps vitest from ^3.0.8 to ^4.1.8 with no other changes; looks correct.
packages/testing/package.json Bumps vitest from ^3.0.8 to ^4.1.8 with no other changes; looks correct.
packages/utils/package.json Bumps vitest from ^3.0.8 to ^4.1.8 with no other changes; looks correct.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[dependabot bump: vitest ^3.0.8 → ^4.1.8] --> B[apps/realtime ✅]
    A --> C[apps/sim ✅]
    A --> D[packages/audit ✅]
    A --> E[packages/logger ✅]
    A --> F[packages/security ✅]
    A --> G[packages/testing ✅]
    A --> H[packages/utils ✅]
    A --> I[packages/ts-sdk ⚠️]
    I --> J[vitest → ^4.1.8 ✅]
    I --> K["@vitest/coverage-v8 stays at ^3.0.8 ❌\nMajor version mismatch — coverage will break"]
Loading

Reviews (1): Last reviewed commit: "chore(deps-dev): bump the npm_and_yarn g..." | Re-trigger Greptile

@@ -43,7 +43,7 @@
"@types/node": "^20.5.1",
"@vitest/coverage-v8": "^3.0.8",
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 @vitest/coverage-v8 is a companion package that must match the major version of vitest. With vitest now at ^4.1.8, keeping @vitest/coverage-v8 at ^3.0.8 will cause a peer-dependency conflict at install time and coverage reporting will fail at runtime because the v3 coverage plugin is incompatible with the v4 runner API.

Suggested change
"@vitest/coverage-v8": "^3.0.8",
"@vitest/coverage-v8": "^4.1.8",

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Jun 1, 2026

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/apps/realtime/npm_and_yarn-3edb4aa9a2 branch June 1, 2026 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant