Skip to content

feat(deps): upgrade upstream dependencies - #2670

Merged
fengmk2 merged 1 commit into
mainfrom
chore/upgrade-upstream-deps-2026-09-11
Sep 12, 2026
Merged

fengmk2 merged 1 commit into
mainfrom
chore/upgrade-upstream-deps-2026-09-11

Conversation

@fengmk2

@fengmk2 fengmk2 commented Sep 11, 2026

Copy link
Copy Markdown
Member

Upgrade Rolldown to 1.2.8, Vite to 8.3.0, Oxlint to 1.82.0, and Oxfmt to 0.67.0.

Update the Rust parser for the Oxc fatal_error field. Add a test for invalid configuration files and keep the generated NAPI updates. Isolate the missing-dependency test from pnpm’s NODE_PATH and the Bun fixture from old bun x caches.

Dependency updates

Package From To
rolldown 1.2.7 (26b4c6e) 1.2.8 (9704b56)
vite 8.2.2 (de1111a) 8.3.0 (434e8e9)
oxfmt 0.66.0 0.67.0
oxlint 1.81.0 1.82.0
@oxc-project/runtime 0.148.0 0.149.0
@oxc-project/types 0.148.0 0.149.0
oxc-minify 0.148.0 0.149.0
oxc-parser 0.148.0 0.149.0
oxc-transform 0.148.0 0.149.0
@vitejs/devtools development range ^0.4.12 ^0.7.1
@vitejs/devtools peer range ^0.4.0 || ^0.5.0 ^0.7.1
@napi-rs/cli catalog ^3.8.2 ^3.9.0
web-tree-sitter catalog ^0.26.0 ^0.27.0
Rust Oxc crates 0.148.0 0.149.0
jsonschema workspace range 0.46.5 0.55.0
smallvec workspace range 1.15.1 1.16.0
Unchanged dependencies
  • vitest: 4.1.11
  • @vitest/browser: 4.1.11
  • @vitest/browser-playwright: 4.1.11
  • @vitest/browser-preview: 4.1.11
  • @vitest/browser-webdriverio: 4.1.11
  • @vitest/expect: 4.1.11
  • @vitest/mocker: 4.1.11
  • @vitest/pretty-format: 4.1.11
  • @vitest/runner: 4.1.11
  • @vitest/snapshot: 4.1.11
  • @vitest/spy: 4.1.11
  • @vitest/utils: 4.1.11
  • tsdown: 0.23.0
  • @tsdown/css: 0.23.0
  • @tsdown/exe: 0.23.0
  • lightningcss: ^1.33.0
  • @oxc-node/cli: 0.1.0
  • @oxc-node/core: 0.1.0
  • oxlint-tsgolint: 7.0.2001
  • VITEST_VERSION constant: 4.1.11
  • README vitest pins: 4.1.11

Code changes

  • crates/vp_static_config/src/lib.rs: use ParserReturn.fatal_error and test runtime fallback for invalid syntax.
  • packages/cli/src/__tests__/resolve-core.spec.ts: run the missing-dependency test without global Node search paths.
  • crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_dlx_bun/: isolate TMPDIR and update the recorded command headings.
  • Cargo.toml: match the changed Rolldown workspace dependencies.
  • packages/core/package.json: sync the Vite DevTools ranges and bundled versions.
  • pnpm-workspace.yaml: exempt Vite DevTools packages from the minimum release age, as with other bundled upstream packages.
  • packages/cli/binding/index.cjs and packages/cli/binding/index.d.cts: keep the regenerated loader and declarations.

Build status

  • sync-remote-and-build: passed.
  • build-upstream: passed on aarch64-apple-darwin.
  • just build, Rust checks, lint, and unit tests: passed.
  • Full CLI snapshots: passed, with 819 cases and one ignored case.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 11, 2026

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://chore-upgrade-upstream-deps-2026-09-11-viteplus-dev.voidzero-docs.workers.dev (commit 351e4b2)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://51fdd31f-viteplus-dev.voidzero-docs.workers.dev 351e4b2 2026-09-12T03:18:58.209Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://467435b4-viteplus-dev.voidzero-docs.workers.dev e73038a 2026-09-11T14:46:06.759Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://0ed37c3b-viteplus-dev.voidzero-docs.workers.dev 10d15cd 2026-09-11T13:41:14.450Z Visit the dashboard ↗

@socket-security

socket-security Bot commented Sep 11, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​playwright-chromium@​1.62.1 ⏵ 1.63.0901006699100
Updatednpm/​@​vitejs/​devtools@​0.5.2 ⏵ 0.7.398 +110073 +198 +1100
Addednpm/​@​oxc-project/​runtime@​0.149.01001007496100
Addednpm/​@​e18e/​eslint-plugin@​0.8.07710010093100
Updatedcargo/​thiserror@​2.0.19 ⏵ 2.0.208010093100100
Updatedcargo/​reqwest@​0.13.4 ⏵ 0.13.58010093100100
Updatedcargo/​napi@​3.12.2 ⏵ 3.12.38110093100100
Updatedcargo/​rustls@​0.23.42 ⏵ 0.23.448110093100100
Updatednpm/​tsx@​4.23.12 ⏵ 4.23.131001008193100
Updatednpm/​oxfmt@​0.63.0 ⏵ 0.67.086 +110088 +196100
Updatednpm/​@​vitejs/​release-scripts@​1.9.2 ⏵ 1.10.089 +31009394 +1100
Updatednpm/​oxc-parser@​0.143.0 ⏵ 0.149.089100100 +196 +1100
Updatednpm/​remove-unused-vars@​0.0.14 ⏵ 0.0.1599 +810093 +190 -1100
Updatedcargo/​async-trait@​0.1.91 ⏵ 0.1.9210010093100100
Updatedcargo/​bstr@​1.13.0 ⏵ 1.13.19810093100100
Updatedcargo/​clap@​4.6.4 ⏵ 4.6.69910093100100
Updatedcargo/​clap_complete@​4.6.7 ⏵ 4.6.99710093100100
Updatedcargo/​console@​0.16.4 ⏵ 0.16.69710093100100
Updatedcargo/​futures@​0.3.33 ⏵ 0.3.3410010093100100
Updatedcargo/​futures-util@​0.3.33 ⏵ 0.3.3410010093100100
Updatedcargo/​ignore@​0.4.31 ⏵ 0.4.339810093100100
Updatedcargo/​indexmap@​2.14.0 ⏵ 2.14.210010093100100
Updatedcargo/​napi-build@​2.4.1 ⏵ 2.4.29710093100100
Updatedcargo/​napi-derive@​3.6.0 ⏵ 3.6.49910093100100
Updatedcargo/​owo-colors@​4.3.0 ⏵ 4.4.0100 +1910093100100
Updatedcargo/​oxc_allocator@​0.148.0 ⏵ 0.149.010010093100100
Updatedcargo/​oxc_ast@​0.148.0 ⏵ 0.149.010010093100100
Updatedcargo/​oxc_parser@​0.148.0 ⏵ 0.149.010010093100100
Updatedcargo/​oxc_span@​0.148.0 ⏵ 0.149.010010093100100
Updatedcargo/​toml@​1.1.3%2Bspec-1.1.0 ⏵ 1.1.6+spec-1.1.010010093100100
Updatedcargo/​uuid@​1.24.0 ⏵ 1.26.1100 +110093100100
Updatednpm/​sass-embedded@​1.102.0 ⏵ 1.104.09810010094 +3100
See 5 more rows in the dashboard

View full report

@github-actions

github-actions Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

CLI artifact sizes (351e4b2)

Final release artifacts built by the canonical build-upstream and build-windows-cli actions.
The dist rows use the Linux build. The core total excludes .node files to match the release artifact.

Artifact Format Base PR Change
packages/cli/dist Directory total 2.14 MiB 2.14 MiB -3 B (-0.00%)
packages/core/dist Directory total 3.92 MiB 3.94 MiB +21.64 KiB (+0.54%)
Combined package dist Directory total 6.07 MiB 6.09 MiB +21.64 KiB (+0.35%)
vp (Linux x64) Binary 11.14 MiB 11.16 MiB +20.02 KiB (+0.18%)
vp (Linux x64) gzip -9 4.82 MiB 4.83 MiB +8.91 KiB (+0.18%)
NAPI (Linux x64) Binary 32.03 MiB 32.12 MiB +88.20 KiB (+0.27%)
NAPI (Linux x64) gzip -9 12.64 MiB 12.71 MiB +65.70 KiB (+0.51%)
vp (macOS ARM64) Binary 8.30 MiB 8.32 MiB +16.16 KiB (+0.19%)
vp (macOS ARM64) gzip -9 4.20 MiB 4.21 MiB +10.52 KiB (+0.24%)
NAPI (macOS ARM64) Binary 39.61 MiB 39.68 MiB +64.80 KiB (+0.16%)
NAPI (macOS ARM64) gzip -9 16.96 MiB 17.00 MiB +45.66 KiB (+0.26%)
vp (Windows x64) Binary 9.02 MiB 9.04 MiB +20.00 KiB (+0.22%)
vp (Windows x64) gzip -9 3.94 MiB 3.95 MiB +6.51 KiB (+0.16%)
NAPI (Windows x64) Binary 26.92 MiB 27.03 MiB +109.00 KiB (+0.40%)
NAPI (Windows x64) gzip -9 10.74 MiB 10.80 MiB +62.45 KiB (+0.57%)
Trampoline (Windows x64) Binary 13.50 KiB 13.50 KiB 0 B (0.00%)
Trampoline (Windows x64) gzip -9 7.03 KiB 7.03 KiB 0 B (0.00%)
Installer (Windows x64) Binary 4.52 MiB 4.53 MiB +11.50 KiB (+0.25%)
Installer (Windows x64) gzip -9 2.11 MiB 2.12 MiB +3.76 KiB (+0.17%)

@fengmk2 fengmk2 added test: e2e Auto run e2e tests test: install-e2e run vite install e2e test test: create-e2e Run `vp create` e2e tests test: sfw labels Sep 11, 2026
@fengmk2 fengmk2 self-assigned this Sep 11, 2026
@fengmk2
fengmk2 marked this pull request as ready for review September 11, 2026 14:16
@fengmk2 fengmk2 added the preview-build Publish this PR's commits to the registry bridge as preview builds label Sep 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Registry bridge build (10d15cd)

This commit build is published to the registry bridge, which serves these as ordinary npm versions (every other package proxies to npmjs):

Package Version
vite-plus 0.0.0-commit.10d15cd3414184a156c9763663aa41b9dbc20d91
@voidzero-dev/vite-plus-core 0.0.0-commit.10d15cd3414184a156c9763663aa41b9dbc20d91

Install the Vite+ CLI built from this commit, then migrate a project:

# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/voidzero-dev/vite-plus/10d15cd3414184a156c9763663aa41b9dbc20d91/packages/cli/install.sh | VP_PR_VERSION=2670 VP_LEGACY_INSTALLER_URL=https://raw.githubusercontent.com/voidzero-dev/vite-plus/10d15cd3414184a156c9763663aa41b9dbc20d91/packages/cli/install-legacy.sh bash
# Windows (PowerShell)
$env:VP_PR_VERSION="2670"; $env:VP_LEGACY_INSTALLER_URL="https://raw.githubusercontent.com/voidzero-dev/vite-plus/10d15cd3414184a156c9763663aa41b9dbc20d91/packages/cli/install-legacy.ps1"; irm https://raw.githubusercontent.com/voidzero-dev/vite-plus/10d15cd3414184a156c9763663aa41b9dbc20d91/packages/cli/install.ps1 | iex

Or download the standalone Windows installer built from this commit:

Architecture Installer
x64 vp-setup-x86_64-pc-windows-msvc.exe
Arm64 vp-setup-aarch64-pc-windows-msvc.exe

GitHub requires you to sign in and downloads each installer as a ZIP artifact. Extract vp-setup.exe, then run it against this preview build:

.\vp-setup.exe --version "0.0.0-commit.10d15cd3414184a156c9763663aa41b9dbc20d91" --registry "https://registry-bridge.viteplus.dev/"

After installing, upgrade the current project's vite-plus to this test build with:

vp migrate

Or point your package manager at the bridge registry https://registry-bridge.viteplus.dev/:

Package manager Registry config
npm / pnpm / Bun .npmrc: registry=https://registry-bridge.viteplus.dev/
Yarn (v2+) .yarnrc.yml: npmRegistryServer: "https://registry-bridge.viteplus.dev/"

Then pin the build (vite aliases to vite-plus-core; pnpm can use a catalog, npm an overrides entry):

{
  "devDependencies": {
    "vite-plus": "0.0.0-commit.10d15cd3414184a156c9763663aa41b9dbc20d91",
    "vite": "npm:@voidzero-dev/vite-plus-core@0.0.0-commit.10d15cd3414184a156c9763663aa41b9dbc20d91"
  }
}

@fengmk2
fengmk2 force-pushed the chore/upgrade-upstream-deps-2026-09-11 branch from 10d15cd to e73038a Compare September 11, 2026 14:44
@github-actions

Copy link
Copy Markdown
Contributor

🐳 Docker preview image

Built from this PR's registry bridge build:

Image Compressed size
ghcr.io/voidzero-dev/vite-plus:pr-2670 228MB
# remove any stale local copy from a previous run, then pull fresh
docker rmi ghcr.io/voidzero-dev/vite-plus:pr-2670 2>/dev/null; docker pull ghcr.io/voidzero-dev/vite-plus:pr-2670

Quick check:

docker run --rm ghcr.io/voidzero-dev/vite-plus:pr-2670 vp --version

See docs/guide/docker.md for usage.

- rolldown: 26b4c6e -> v1.2.8 (9704b56)
- vite: de1111a -> v8.3.0 (434e8e9)
- oxfmt: 0.66.0 -> 0.67.0
- oxlint: 1.81.0 -> 1.82.0
- @oxc-project/runtime: 0.148.0 -> 0.149.0
- @oxc-project/types: 0.148.0 -> 0.149.0
- oxc-minify: 0.148.0 -> 0.149.0
- oxc-parser: 0.148.0 -> 0.149.0
- oxc-transform: 0.148.0 -> 0.149.0

Code changes:
- crates/vp_static_config/src/lib.rs: adapt to fatal_error and test syntax-error fallback
- Cargo.toml: sync jsonschema and smallvec with Rolldown
- packages/core/package.json: sync Vite DevTools ranges and bundled versions
- packages/cli/binding/index.cjs and index.d.cts: regenerate NAPI artifacts
- packages/cli/src/__tests__/resolve-core.spec.ts: isolate missing dependency from NODE_PATH
- crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_dlx_bun/: isolate bun x cache and update command headings
@fengmk2
fengmk2 force-pushed the chore/upgrade-upstream-deps-2026-09-11 branch from e73038a to 351e4b2 Compare September 12, 2026 03:16
@fengmk2
fengmk2 merged commit 342bebf into main Sep 12, 2026
115 checks passed
@fengmk2
fengmk2 deleted the chore/upgrade-upstream-deps-2026-09-11 branch September 12, 2026 08:08
fengmk2 added a commit that referenced this pull request Sep 14, 2026
…in APIs (#2692)

`vp env use` now sets each package manager's version independently. This
release also adds Oxlint plugin APIs and fixes migration, installation,
and template extraction.

### Breaking Changes

#### Package-manager overrides

Direct package-manager commands no longer use `VP_PACKAGE_MANAGER`. Use
the matching version variable in shell profiles, CI jobs, and
Dockerfiles:

| Previous override for a direct command | New override |
| --- | --- |
| `VP_PACKAGE_MANAGER=npm@<version>` | `VP_NPM_VERSION=<version>` |
| `VP_PACKAGE_MANAGER=pnpm@<version>` | `VP_PNPM_VERSION=<version>` |
| `VP_PACKAGE_MANAGER=yarn@<version>` | `VP_YARN_VERSION=<version>` |
| `VP_PACKAGE_MANAGER=bun@<version>` | `VP_BUN_VERSION=<version>` |

`VP_PACKAGE_MANAGER` still selects the manager and version for `vp
install` and related commands. `vp env use pnpm@10` now changes only the
direct pnpm commands. To override `vp install`, set `VP_PACKAGE_MANAGER`
explicitly.

The old `.session-package-manager` file is no longer read or migrated.
Run `vp env use` again to create the new session files. Projects that
use only project pins or global defaults need no changes. See the
[environment guide](https://viteplus.dev/guide/env)
([#2658](#2658),
[#2659](#2659)), by
@liangmiQwQ.

#### Installer preferences

`VP_NODE_MANAGER` now controls only Node.js. Existing installations
retain saved preferences during upgrades, so `vp upgrade` needs no
configuration changes. For scripted installations, set `VP_PM_MANAGER`
to apply the same choice to package managers:

| Previous combined setting | New combined setting |
| --- | --- |
| `VP_NODE_MANAGER=no` | `VP_NODE_MANAGER=no VP_PM_MANAGER=no` |
| `VP_NODE_MANAGER=yes` | `VP_NODE_MANAGER=yes VP_PM_MANAGER=yes` |

Update installer commands in CI jobs and Dockerfiles. Use
`VP_NPM_MANAGER`, `VP_PNPM_MANAGER`, `VP_YARN_MANAGER`, or
`VP_BUN_MANAGER` for individual preferences. The interactive prompt
retains its combined choice. See the [installer variables
guide](https://viteplus.dev/guide/installer-env-vars)
([#2681](#2681)), by
@liangmiQwQ.

#### Vite DevTools

Projects that install `@vitejs/devtools` must update its dependency
range from `^0.4.0 || ^0.5.0` to `^0.7.1`. Projects without this
optional dependency need no changes. This requirement comes with the
Vite upgrade listed below.

### Highlights

- Installers and `vp upgrade` share setup behavior across platforms,
which simplifies maintenance. The installers retain support for older
releases ([#2611](#2611)),
by @liangmiQwQ.
- Custom Oxlint rules can import their APIs from
`vite-plus/lint/plugins` and `vite-plus/lint/plugins-dev`. `vp migrate`
updates supported existing imports
([#2328](#2328)), by
@fengmk2.
- `vp install` and `vp add` now honor `--ignore-scripts` for named
packages and managed global installations
([#2682](#2682)), by
@jong-kyung.
- `vp create` rejects malformed registry versions that could place
organization template files outside the cache directory
([#2665](#2665)), by
@fengmk2.

### Features

- The bundled tools update from `vite@8.2.2` to `vite@8.3.0` and from
`rolldown@1.2.7` to `rolldown@1.2.8`. They also update from
`oxlint@1.81.0` to `oxlint@1.82.0` and from `oxfmt@0.66.0` to
`oxfmt@0.67.0`. The new linter and formatter can flag code that passed
before. Run `vp fmt` after the upgrade if CI runs `vp check`
([#2670](#2670)), by
@fengmk2.

### Fixes & Enhancements

- `vp env pin` updates an active local `.nvmrc` and preserves its
comments. Use `--target nvmrc` to select this file explicitly
([#2676](#2676)), by
@ywenhao.
- `vp migrate` reports unsupported ESLint rules that it skips, so users
can review the missing checks
([#2689](#2689)), by
@yusuke99.
- `vp migrate` imports leftover tsdown configuration when a project
already uses Vite+
([#2646](#2646)), by
@TheAlexLichter.
- `vp migrate` accepts single-line JSON formatter configuration with a
final newline
([#2643](#2643)), by
@TheAlexLichter.
- `vp migrate` avoids a redundant `playwright` dependency when the
project already declares `@playwright/test`
([#2637](#2637)), by
@yusuke99.
- Newly scaffolded local generators honor `--no-interactive` and report
missing arguments without prompts. Existing generators need the updated
entrypoint
([#2677](#2677)), by
@SaKaNa-Y.
- `vp upgrade` installs its dependencies correctly when the installation
directory is inside a pnpm workspace
([#2644](#2644)), by
@fengmk2.
- Nested package-manager commands retain the selected Node runtime and
package-manager versions
([#2631](#2631)), by
@lyzno1.
- Built-in tools reuse the Node executable that starts the CLI. Editor
lint and format servers work when `node` is absent from `PATH`
([#2673](#2673)), by
@fengmk2.
- The npm command wrapper enables Node's compile cache before it loads
the CLI, which reduces repeated startup work
([#2648](#2648)), by
@pablog12.
- Package-manager commands suppress pnpm, npm, and supported Yarn update
notices. Yarn 4 daily tips are also hidden
([#2649](#2649),
[#2650](#2650),
[#2651](#2651)), by
@fengmk2.
- Invalid `package.json` errors include the affected file's path
([#2683](#2683)), by
@adamaveray.

### Docs

- The README task example uses the supported `env` field
([#2653](#2653)), by
@SaKaNa-Y.
- Migration guidance tells pnpm users to retain the generated `vite` and
`vitest` dependencies
([#2660](#2660)), by
@naokihaba.
- Lint and format guides explain root configuration and overrides for
monorepos. They clarify that nested configuration is not supported
([#2668](#2668)), by
@liangmiQwQ.

### Chore

- The repository removes unused Babel dependencies and the unused hooks
directory setter
([#2634](#2634),
[#2647](#2647)), by
@jong-kyung.
- CLI snapshot tests run across parallel jobs, and the pnpm 11 workspace
pack test excludes generated archives
([#2657](#2657),
[#2655](#2655)), by
@fengmk2.
- CI removes the unused Graphite optimization and adds Solid 2 ecosystem
coverage ([#2678](#2678),
[#2680](#2680)), by
@fengmk2.
- Release guidance clarifies validation and announcement procedures
([#2633](#2633)), by
@fengmk2.
- The runtime manager refreshes the signing keys for Node.js release
verification
([#2687](#2687)), by
@voidzero-guard[bot].

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| `vite` | `8.3.0` |
[`434e8e9`](vitejs/vite@434e8e9)
|
| `rolldown` | `1.2.8` |
[`9704b56`](rolldown/rolldown@9704b56)
|
| `tsdown` | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0)
|
| `vitest` | `4.1.11` | [npm](https://npmx.dev/package/vitest/v/4.1.11)
|
| `oxlint` | `1.82.0` | [npm](https://npmx.dev/package/oxlint/v/1.82.0)
|
| `oxlint-tsgolint` | `7.0.2001` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) |
| `oxfmt` | `0.67.0` | [npm](https://npmx.dev/package/oxfmt/v/0.67.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@yusuke99, @pablog12, @SaKaNa-Y, @ywenhao, @adamaveray

**Full Changelog**:
v0.3.1...v0.3.2

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview-build Publish this PR's commits to the registry bridge as preview builds test: create-e2e Run `vp create` e2e tests test: e2e Auto run e2e tests test: install-e2e run vite install e2e test test: sfw

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants