Skip to content

Bump vite from 5.3.6 to 7.2.4#2062

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/vite-7.2.4
Open

Bump vite from 5.3.6 to 7.2.4#2062
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/vite-7.2.4

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 27, 2026

Bumps vite from 5.3.6 to 7.2.4.

Release notes

Sourced from vite's releases.

v7.2.4

Please refer to CHANGELOG.md for details.

v7.2.3

Please refer to CHANGELOG.md for details.

v7.2.2

Please refer to CHANGELOG.md for details.

[email protected]

Please refer to CHANGELOG.md for details.

v7.2.1

Please refer to CHANGELOG.md for details.

[email protected]

Please refer to CHANGELOG.md for details.

v7.2.0

Please refer to CHANGELOG.md for details.

v7.2.0-beta.1

Please refer to CHANGELOG.md for details.

v7.2.0-beta.0

Please refer to CHANGELOG.md for details.

v7.1.12

Please refer to CHANGELOG.md for details.

v7.1.11

Please refer to CHANGELOG.md for details.

v7.1.10

Please refer to CHANGELOG.md for details.

v7.1.9

Please refer to CHANGELOG.md for details.

v7.1.8

Please refer to CHANGELOG.md for details.

v7.1.7

Please refer to CHANGELOG.md for details.

v7.1.6

Please refer to CHANGELOG.md for details.

v7.1.5

Please refer to CHANGELOG.md for details.

... (truncated)

Changelog

Sourced from vite's changelog.

7.2.4 (2025-11-20)

Bug Fixes

  • revert "perf(deps): replace debug with obug (#21107)" (2d66b7b)

7.2.3 (2025-11-20)

Bug Fixes

  • allow multiple bindCLIShortcuts calls with shortcut merging (#21103) (5909efd)
  • deps: update all non-major dependencies (#21096) (6a34ac3)
  • deps: update all non-major dependencies (#21128) (4f8171e)

Performance Improvements

Miscellaneous Chores

  • deps: update dependency @​rollup/plugin-commonjs to v29 (#21099) (02ceaec)
  • deps: update rolldown-related dependencies (#21095) (39a0a15)
  • deps: update rolldown-related dependencies (#21127) (5029720)

7.2.2 (2025-11-07)

Bug Fixes

7.2.1 (2025-11-06)

Bug Fixes

Code Refactoring

  • build: rename indexOfMatchInSlice to findPreloadMarker (#21054) (f83264f)

7.2.0 (2025-11-05)

Bug Fixes

  • css: fallback to sass when sass-embedded platform binary is missing (#21002) (b1fd616)
  • module-runner: make getBuiltins response JSON serializable (#21029) (ad5b3bf)
  • types: add undefined to optional properties for exactOptionalProperties type compatibility (#21040) (2833c55)

Miscellaneous Chores

7.2.0-beta.1 (2025-10-29)

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for vite since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Medium Risk
Tooling-only dependency updates, but changes to vite/rollup/bundler transitive deps can affect local dev and production build output.

Overview
Bumps vite from 7.2.4 to 7.2.6 in package.json.

Regenerates pnpm-lock.yaml to align Vite plugins and the underlying bundling stack (notably rollup and various Metro/transitive packages) with the new Vite patch release.

Written by Cursor Bugbot for commit 8128d89. This will update automatically on new commits. Configure here.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jan 27, 2026
@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Jan 27, 2026

Deploying carbon-app-tac with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8128d89
Status: ✅  Deploy successful!
Preview URL: https://c3984738.carbon-app-tac.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-vite-puq8.carbon-app-tac.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Jan 27, 2026

Deploying carbon-app-ton-tg with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8128d89
Status: ✅  Deploy successful!
Preview URL: https://7deaefd6.carbon-app-ton-tg.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-vite-f1dz.carbon-app-ton-tg.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Jan 27, 2026

Deploying carbon-app-celo with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8128d89
Status: ✅  Deploy successful!
Preview URL: https://42d79f3f.carbon-app-celo.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-vite-0258.carbon-app-celo.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Jan 27, 2026

Deploying carbon-app-sei with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8128d89
Status: ✅  Deploy successful!
Preview URL: https://425c1c68.carbon-app-sei.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-vite-8oyx.carbon-app-sei.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Jan 27, 2026

Deploying carbon-app with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8128d89
Status: ✅  Deploy successful!
Preview URL: https://9f994558.carbon-app-csq.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-vite-tftr.carbon-app-csq.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Jan 27, 2026

Deploying carbon-app-coti with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8128d89
Status: ✅  Deploy successful!
Preview URL: https://9fca2e78.carbon-app-coti.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-vite-jn7p.carbon-app-coti.pages.dev

View logs

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/vite-7.2.4 branch from e1ff9e2 to eb2a1d7 Compare February 25, 2026 12:41
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 5.3.6 to 7.2.4.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v7.2.4/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 7.2.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/vite-7.2.4 branch from eb2a1d7 to 8128d89 Compare February 26, 2026 13:09
Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Bugbot Free Tier Details

Your team is on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle for each member of your team.

To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable autofix in the Cursor dashboard.

debug: 4.4.3
pony-cause: 2.1.11
semver: 7.7.3
semver: 7.7.4
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@scure/base downgrade in @metamask/utils wallet flow

Medium Severity

The lockfile now resolves @metamask/[email protected] to @scure/[email protected] instead of 1.2.6. This downgrade may introduce missing security or behavior fixes from 1.2.x into wallet-related flows (MetaMask, wagmi). @metamask/[email protected] still uses @scure/[email protected], so resolution changed only for 8.5.0.

Fix in Cursor Fix in Web

[email protected]:
dependencies:
readable-stream: 4.5.2
readable-stream: 3.6.2
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

readable-stream downgrade in extension-port-stream

Low Severity

extension-port-stream now resolves to [email protected] instead of 4.5.2. Version 4.x differs from 3.x in behavior (e.g. autoDestroy, event ordering, Node 18 alignment). This package handles MetaMask extension messaging; the downgrade may affect stream lifecycle or error handling in unusual conditions.

Fix in Cursor Fix in Web

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants