Skip to content

Commit 173e734

Browse files
release: v1.0.0-rc.0: Vitest 5 migration and npm provenance checks (#2780)
Vite+ now uses Vitest 5, and `vp migrate` helps Vitest 4 projects adopt the new APIs and defaults. Standalone installs and upgrades now require verified npm provenance for release binaries. ### Breaking Changes #### Vitest 5 `vp test` and the public `vite-plus/test*` exports now use `vitest@5.0.1` ([#2551](#2551)), by @fengmk2. | Area | Old | New | | --- | --- | --- | | Test runner | `vitest@4.1.11` | `vitest@5.0.1` | | CLI Node.js range | `^20.19.0 \|\| ^22.18.0 \|\| >=24.11.0` | `^22.18.0 \|\| ^24.11.0 \|\| >=26.0.0` | | `vite-plus/test/runners` and `vite-plus/test/suite` | Vite+ compatibility exports | Use supported APIs from `vite-plus/test`; review unsupported runner and expect plugins | | `vite-plus/test/browser-webdriverio` | Bundled export | Use the community `@vitest/browser-webdriverio` package | Run `vp migrate` from the workspace root before you install the new dependencies. The migrator updates supported config, source, benchmark, command, and import changes. It reports manual work as `BLOCK` or `REVIEW` items. See the [Vitest 5 migration guide](https://viteplus.dev/guide/vitest-v5) for the full process. Projects can stay on the prior release until their runtimes and tests are ready. #### `vp staged` runtime requirements `vp staged` now uses `lint-staged@17.5.1` ([#2754](#2754)), by @fengmk2. | Requirement | Old | New | | --- | --- | --- | | Node.js for `vp staged` | The Vite+ CLI runtime range | `^22.22.1 \|\| ^24.11.0 \|\| >=26.0.0` | | Git | No separate documented minimum | `>=2.32.0` | Update Node.js and Git on developer machines and CI runners that execute `vp staged` or its pre-commit hook. Other workflows do not use these extra requirements. ### Highlights - Standalone installers, `vp upgrade`, and `vp-setup.exe` now reject release binaries without supported SLSA provenance ([#2440](#2440)), by @kazupon. - Installers now show progress and the exact shell activation command. Download progress preserves earlier terminal output ([#2744](#2744), [#2741](#2741)), by @fengmk2. - System-first runtime and package-manager shims now use a fallback directory at the end of `PATH`. Setup restores missing package-manager preferences ([#2758](#2758), [#2763](#2763)), by @liangmiQwQ and @fengmk2. - `vp run` now finishes when background processes remain. Large file traces run without caching instead of killing the task ([#2767](#2767), [vite-task#675](voidzero-dev/vite-task#675)), by @wan9chi. ### Features - `vp add` now supports shared install options such as `--offline`, `--frozen-lockfile`, and `--lockfile-only` ([#2722](#2722)), by @jong-kyung. - `vp pm patch` and `vp pm patch-commit` now use the native commands in npm 12 and later ([#2736](#2736)), by @jong-kyung. - `vp rebuild` now supports Yarn Berry and forwards package names and extra arguments ([#2761](#2761)), by @jong-kyung. - The bundled tools update `oxlint` `1.83.0` -> `1.85.0`, `oxlint-tsgolint` `7.0.2001` -> `7.0.2002`, and `oxfmt` `0.68.0` -> `0.70.0` ([#2745](#2745), [#2773](#2773), [#2778](#2778)), by @voidzero-guard[bot]. These versions can flag or format code that passed before. Run `vp fmt` after upgrading if CI runs `vp check`. ### Fixes & Enhancements - `oxlint` and `oxfmt` no longer expose bin wrappers that conflict with upstream packages. Editors must use `vp lint --lsp`, `vp fmt --lsp`, or `vp fmt --stdin-filepath` ([#2672](#2672)), by @fengmk2. - `vp create vite:generator` now replaces catalog references for package managers that do not support catalogs ([#2720](#2720)), by @SaKaNa-Y. - Unpinned npm projects now use the npm version bundled with the selected Node.js runtime. The same policy works during migration ([#2742](#2742), [#2748](#2748)), by @liangmiQwQ. - The CLI now loads its local versions module through a file URL, including on Windows paths ([#2749](#2749)), by @YanChenBai. - Package-manager commands now use pnpm when the project has no detected package manager ([#2750](#2750)), by @liangmiQwQ. - `vp migrate` now removes unused `@oxlint/plugins` dependencies after it rewrites plugin imports ([#2751](#2751)), by @fengmk2. - `vp update --no-save` now warns that Yarn Classic and Yarn Berry do not support the option ([#2762](#2762)), by @jong-kyung. - `vp migrate` now explains its `tsdown@0.23` compatibility settings and links to removal guidance ([#2769](#2769)), by @fengmk2. - Environment setup now installs and diagnoses the official `pn` and `pnx` aliases for pnpm ([#2770](#2770)), by @iruoy. - Cached tasks now receive GitHub Actions OIDC variables, so npm Trusted Publishing works through `vp run` ([vite-task#691](voidzero-dev/vite-task#691)), by @naokihaba. - Automatic task input tracking now records file access from signal handlers ([vite-task#687](voidzero-dev/vite-task#687)), by @wan9chi. ### Refactor - `vp lint`, `vp fmt`, and `vp check` now use native config discovery. Package commands keep matching workspace-root settings, while explicit config flags take precedence ([#2731](#2731)), by @fengmk2. ### Chore - Generated workflows and `vp migrate` now use `setup-vp@v1.21.1`, including its installation fixes ([#2760](#2760), [#2772](#2772)), by @renovate[bot] and @fengmk2. ### Bundled Versions | Tool | Version | Source | | --- | --- | --- | | vite | `8.3.0` | [`434e8e9`](vitejs/vite@434e8e9) | | rolldown | `1.2.9` | [`5b4746e`](rolldown/rolldown@5b4746e) | | tsdown | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) | | vitest | `5.0.1` | [npm](https://npmx.dev/package/vitest/v/5.0.1) | | oxlint | `1.85.0` | [npm](https://npmx.dev/package/oxlint/v/1.85.0) | | oxlint-tsgolint | `7.0.2002` | [npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2002) | | oxfmt | `0.70.0` | [npm](https://npmx.dev/package/oxfmt/v/0.70.0) | ### Upgrade ```bash vp upgrade ``` ### New Contributors @YanChenBai, @iruoy **Full Changelog**: v0.3.3...v1.0.0-rc.0 --- Merging this PR will trigger the release workflow. --------- Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com> Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
1 parent 1e16526 commit 173e734

16 files changed

Lines changed: 101 additions & 79 deletions

File tree

‎Cargo.lock‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/download_progress/snapshots/installation_progress_ci.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44

55
```
66
Before installation: preserve this output.
7-
info: installing vite-plus@0.3.3...
7+
info: installing vite-plus@<version>...
88
info: Preparing Node.js and pnpm...
99
info: Installing dependencies...
1010
✓ Dependencies installed.

‎crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/download_progress/snapshots/installation_progress_failure.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66

77
```
88
Before installation: preserve this output.
9-
info: installing vite-plus@0.3.3...
9+
info: installing vite-plus@<version>...
1010
⠿ Preparing Node.js and pnpm... <duration>
1111
```
1212

@@ -16,7 +16,7 @@ info: installing vite-plus@0.3.3...
1616

1717
```
1818
Before installation: preserve this output.
19-
info: installing vite-plus@0.3.3...
19+
info: installing vite-plus@<version>...
2020
⠿ Downloading pnpm <version>... <size> B (<size> B/s)
2121
```
2222

@@ -26,15 +26,15 @@ info: installing vite-plus@0.3.3...
2626

2727
```
2828
Before installation: preserve this output.
29-
info: installing vite-plus@0.3.3...
29+
info: installing vite-plus@<version>...
3030
⠿ Installing dependencies... <duration>
3131
```
3232

3333
**← write-key:** `enter`
3434

3535
```
3636
Before installation: preserve this output.
37-
info: installing vite-plus@0.3.3...
37+
info: installing vite-plus@<version>...
3838
error: Setup error: Failed to install production dependencies (exit code: 17). See log for details: <workspace>/home/upgrade.log
3939
Failure log preserves pnpm stdout and stderr.
4040
After installation.

‎crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/download_progress/snapshots/installation_progress_interactive.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66

77
```
88
Before installation: preserve this output.
9-
info: installing vite-plus@0.3.3...
9+
info: installing vite-plus@<version>...
1010
⠿ Preparing Node.js and pnpm... <duration>
1111
```
1212

@@ -16,7 +16,7 @@ info: installing vite-plus@0.3.3...
1616

1717
```
1818
Before installation: preserve this output.
19-
info: installing vite-plus@0.3.3...
19+
info: installing vite-plus@<version>...
2020
⠿ Downloading pnpm <version>... <size> B (<size> B/s)
2121
```
2222

@@ -26,15 +26,15 @@ info: installing vite-plus@0.3.3...
2626

2727
```
2828
Before installation: preserve this output.
29-
info: installing vite-plus@0.3.3...
29+
info: installing vite-plus@<version>...
3030
⠿ Installing dependencies... <duration>
3131
```
3232

3333
**← write-key:** `enter`
3434

3535
```
3636
Before installation: preserve this output.
37-
info: installing vite-plus@0.3.3...
37+
info: installing vite-plus@<version>...
3838
✓ Dependencies installed.
3939
Setup:
4040
Preparing vite-plus environment.

‎crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/download_progress/snapshots/installation_progress_non_tty.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
Before installation: preserve this output.
77
Bootstrap stdout contains only shell assignments.
88
After installation.
9-
info: installing vite-plus@0.3.3...
9+
info: installing vite-plus@<version>...
1010
info: Preparing Node.js and pnpm...
1111
info: Installing dependencies...
1212
✓ Dependencies installed.

‎crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/redaction/snapshots.toml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,5 +10,6 @@ stems, https:// URLs) survive.
1010
steps = [
1111
{ argv = ["vpt", "print-native-path", "src/index.ts", "dist/assets/app.js"], comment = "prints OS-native separators; the snapshot must show forward slashes on every OS" },
1212
{ argv = ["vpt", "print", "dist/assets/index-Dra_-aT4.js 0.71 kB / gzip: 0.40 kB / total 1 MB"], comment = "sizes and hash suffixes are masked" },
13+
{ argv = ["vpt", "print", "info: installing vite-plus@9.8.7-rc.6..."], comment = "standalone installer versions are masked" },
1314
{ argv = ["vpt", "print", "keep vite-tsconfig.js and https://viteplus.dev/guide/ intact"], comment = "lowercase 8-letter stems and URLs survive redaction" },
1415
]

‎crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/redaction/snapshots/redaction_selftest.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,14 @@ sizes and hash suffixes are masked
2222
dist/assets/index-<hash>.js <size> kB / gzip: <size> kB / total <size> MB
2323
```
2424

25+
## `vpt print 'info: installing vite-plus@9.8.7-rc.6...'`
26+
27+
standalone installer versions are masked
28+
29+
```
30+
info: installing vite-plus@<version>...
31+
```
32+
2533
## `vpt print 'keep vite-tsconfig.js and https://viteplus.dev/guide/ intact'`
2634

2735
lowercase 8-letter stems and URLs survive redaction

‎crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -120,6 +120,16 @@ static VP_VERSION_RE: LazyLock<regex::Regex> = LazyLock::new(|| {
120120
)
121121
.unwrap()
122122
});
123+
// Standalone installation progress prints the release version in
124+
// `info: installing vite-plus@0.3.3...`. The value changes for every release,
125+
// so mask only this status-line context and keep other `vite-plus@<version>`
126+
// output available for assertions.
127+
static VP_INSTALL_VERSION_RE: LazyLock<regex::Regex> = LazyLock::new(|| {
128+
regex::Regex::new(
129+
r"(installing vite-plus@)\d+\.\d+\.\d+(?:-[0-9A-Za-z-]+(?:\.[0-9A-Za-z-]+)*)?",
130+
)
131+
.unwrap()
132+
});
123133
// `vp create`/`vp migrate` pin the exact resolved runtime and package-manager
124134
// version into a scaffolded manifest's `devEngines` block (`{ "name": "yarn",
125135
// "version": "4.17.0", ... }`, likewise pnpm/bun/node). Those track whatever
@@ -539,6 +549,9 @@ pub fn redact_output(
539549
// (see VP_VERSION_RE), which bumps on every release.
540550
output = VP_VERSION_RE.replace_all(&output, "${1}<version>").into_owned();
541551

552+
// Redact the release version in standalone installation progress output.
553+
output = VP_INSTALL_VERSION_RE.replace_all(&output, "${1}<version>").into_owned();
554+
542555
// Redact scaffolded devEngines runtime/package-manager pins by name
543556
// context (see DEV_ENGINES_VERSION_RE), which track upstream releases.
544557
output = DEV_ENGINES_VERSION_RE.replace_all(&output, "${1}<version>").into_owned();

‎crates/vp_global_cli/Cargo.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
[package]
22
name = "vp_global_cli"
3-
version = "0.3.3"
3+
version = "1.0.0-rc.0"
44
authors.workspace = true
55
edition.workspace = true
66
license.workspace = true

‎docs/.vitepress/theme/data/migration-prompts.ts‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
const localMigrationPrompt = `Without a global installation, run the target CLI through the package manager from the workspace root. For the 1.0.0 release, use \`pnpm dlx --package=vite-plus@1.0.0 vp migrate --no-interactive\` or \`npx --package=vite-plus@1.0.0 vp migrate --no-interactive\`. First run the same command with \`help migrate\` instead of \`migrate --no-interactive\` to read its help. These commands fetch the target CLI without replacing the old project dependencies first.`;
1+
const localMigrationPrompt = `Without a global installation, run the target CLI through the package manager from the workspace root. For the 1.0.0-rc.0 release, use \`pnpm dlx --package=vite-plus@1.0.0-rc.0 vp migrate --no-interactive\` or \`npx --package=vite-plus@1.0.0-rc.0 vp migrate --no-interactive\`. First run the same command with \`help migrate\` instead of \`migrate --no-interactive\` to read its help. These commands fetch the target CLI without replacing the old project dependencies first.`;
22

33
const compatibilityReviewPrompt = `After establishing a passing baseline, try to remove the generated "Vitest v4 compatibility" settings with no code changes or small, localized fixes:
44
@@ -28,7 +28,7 @@ Use the CLI from the target Vite+ 1.0 release or its preview build. Use a suppor
2828
- With a global vp installation, follow ${__DOCS_ORIGIN__}/guide/upgrade to select the target release and check \`vp toolchain --global\`. Run \`vp help\` and \`vp help migrate\`, then \`vp migrate --no-interactive\` from the workspace root.
2929
- ${localMigrationPrompt}
3030
31-
Replace 1.0.0 with the intended release version. For a preview, use the version from its PR and pass \`--registry=https://registry-bridge.viteplus.dev\` to pnpm or npx before the vp command.
31+
Replace 1.0.0-rc.0 with the intended release version. For a preview, use the version from its PR and pass \`--registry=https://registry-bridge.viteplus.dev\` to pnpm or npx before the vp command.
3232
3333
Do not run migration with an old project's node_modules/.bin/vp. Migrate monorepos from the workspace root so shared manifests, catalogs, overrides, and lockfiles remain consistent.
3434
@@ -64,7 +64,7 @@ Use the CLI from the target Vite+ 1.0 release or its preview build. A global ins
6464
- With a global vp installation, follow ${__DOCS_ORIGIN__}/guide/upgrade to upgrade it and check \`vp toolchain --global\`. Run \`vp help migrate\`, then \`vp migrate --no-interactive\` from the workspace root.
6565
- ${localMigrationPrompt}
6666
67-
Replace 1.0.0 with the intended release version. For a preview, use the version from its PR and pass \`--registry=https://registry-bridge.viteplus.dev\` to pnpm or npx before the vp command. Do not run migration with the old project's node_modules/.bin/vp. Keep the existing project setup; do not use --full unless I request it.
67+
Replace 1.0.0-rc.0 with the intended release version. For a preview, use the version from its PR and pass \`--registry=https://registry-bridge.viteplus.dev\` to pnpm or npx before the vp command. Do not run migration with the old project's node_modules/.bin/vp. Keep the existing project setup; do not use --full unless I request it.
6868
6969
Resolve BLOCK findings and rerun migration. Review each REVIEW finding using its documentation link, even if migration exits with success. Preserve test intent and keep the generated Vitest v4 and tsdown <0.23 compatibility settings and comments for the first validation run.
7070
@@ -91,7 +91,7 @@ A global installation is optional. To install the global \`vp\` CLI when it is n
9191
9292
Open a new terminal after installation. Follow ${__DOCS_ORIGIN__}/guide/upgrade to select the target release or preview and check \`vp toolchain --global\` before scaffolding.
9393
94-
Without a global installation, use a supported Node.js runtime from the compatibility guide. For the 1.0.0 release, run \`pnpm dlx --package=vite-plus@1.0.0 vp create\` or \`npx --package=vite-plus@1.0.0 vp create\`. Replace 1.0.0 with the intended release version. For a preview, use the version from its PR and pass \`--registry=https://registry-bridge.viteplus.dev\` to pnpm or npx before the vp command.
94+
Without a global installation, use a supported Node.js runtime from the compatibility guide. For the 1.0.0-rc.0 release, run \`pnpm dlx --package=vite-plus@1.0.0-rc.0 vp create\` or \`npx --package=vite-plus@1.0.0-rc.0 vp create\`. Replace 1.0.0-rc.0 with the intended release version. For a preview, use the version from its PR and pass \`--registry=https://registry-bridge.viteplus.dev\` to pnpm or npx before the vp command.
9595
9696
Run \`vp install\`, \`vp check\`, and \`vp test\`, then \`vp build\` for applications or \`vp pack\` for libraries. Without a global CLI, install with the project's package manager and run the local CLI through it, such as \`pnpm exec vp check\` or \`npm exec -- vp check\`. Explain how to use \`vp dev\` for the dev server and \`vp run <task>\` for project scripts or tasks. Report the setup changes, validation results, and any remaining work. Do not commit or push unless I ask.
9797

0 commit comments

Comments
 (0)