Skip to content

feat(deps): upgrade upstream dependencies - #2896

Merged
fengmk2 merged 3 commits into
mainfrom
deps/upstream-update
Oct 6, 2026
Merged

fengmk2 merged 3 commits into
mainfrom
deps/upstream-update

Conversation

@voidzero-guard

@voidzero-guard voidzero-guard Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
  • Upgrade oxlint to 1.87.0 and oxfmt to 0.72.0.
  • Upgrade the oxc napi packages (@oxc-project/runtime, @oxc-project/types, oxc-minify, oxc-parser, oxc-transform) to 0.153.0.
  • Merge the rolldown workspace catalog, adding @types/semver to the root catalog.
  • Reformat docs/RFC markdown with oxfmt 0.72.0: new import sort order in embedded code snippets and list continuation indentation fixes.

Dependency updates

Package From To
oxfmt 0.71.0 0.72.0
oxlint 1.86.0 1.87.0
@oxc-project/runtime 0.152.0 0.153.0
@oxc-project/types 0.152.0 0.153.0
oxc-minify 0.152.0 0.153.0
oxc-parser 0.152.0 0.153.0
oxc-transform 0.152.0 0.153.0
Unchanged dependencies
  • rolldown: v1.2.12 (45e407b)
  • vite: v8.3.2 (1003321)
  • vitest: 5.0.3
  • @vitest/browser: 5.0.3
  • @vitest/browser-playwright: 5.0.3
  • @vitest/browser-preview: 5.0.3
  • @vitest/mocker: 5.0.3
  • @vitest/pretty-format: 5.0.3
  • @vitest/snapshot: 5.0.3
  • @vitest/spy: 5.0.3
  • @vitest/utils: 5.0.3
  • tsdown: 0.23.0
  • @tsdown/css: 0.23.0
  • @tsdown/exe: 0.23.0
  • lightningcss: ^1.33.0
  • lint-staged: 17.6.0
  • @oxc-node/cli: 0.1.3
  • @oxc-node/core: 0.1.3
  • oxlint-tsgolint: 7.0.2003
  • VITEST_VERSION constant: 5.0.3

Code changes

  • pnpm-workspace.yaml: rolldown catalog merge added @types/semver: ^7.8.0; verkit entry re-sorted alphabetically.
  • docs/guide/migrate.md, docs/guide/troubleshooting.md, rfcs/code-generator.md, rfcs/global-cli-rust-binary.md: import order in embedded code snippets re-sorted by oxfmt 0.72.0 (including blank lines between import groups in rfcs/code-generator.md).
  • rfcs/create-org-default-templates.md, rfcs/docker-image.md: markdown list continuation-line indentation fixed by the formatter.

Build status

  • sync-remote-and-build: success
  • build-upstream: success

- oxfmt: 0.71.0 -> 0.72.0
- oxlint: 1.86.0 -> 1.87.0
- @oxc-project/runtime: 0.152.0 -> 0.153.0
- @oxc-project/types: 0.152.0 -> 0.153.0
- oxc-minify: 0.152.0 -> 0.153.0
- oxc-parser: 0.152.0 -> 0.153.0
- oxc-transform: 0.152.0 -> 0.153.0

Code changes:
- pnpm-workspace.yaml: merge rolldown catalog (adds `@types/semver`, re-sorts `verkit`)
- Reformat markdown with oxfmt 0.72.0 (import sort order in embedded code snippets, list continuation indentation): docs/guide/migrate.md, docs/guide/troubleshooting.md, rfcs/code-generator.md, rfcs/create-org-default-templates.md, rfcs/docker-image.md, rfcs/global-cli-rust-binary.md
@voidzero-guard

voidzero-guard Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

✅ No upstream CLI help changes detected

Compared normalized --help output for the upstream CLIs mirrored by Vite+.

➖ Vite: no version update (8.3.2)

No version update was detected, so there is no CLI help diff.

➖ Vitest: no version update (5.0.3)

No version update was detected, so there is no CLI help diff.

✅ Oxlint: no CLI help changes (1.86.0 → 1.87.0)

The version was updated, but the normalized CLI help output has no differences.

✅ Oxfmt: no CLI help changes (0.71.0 → 0.72.0)

The version was updated, but the normalized CLI help output has no differences.

➖ tsdown: no version update (0.23.0)

No version update was detected, so there is no CLI help diff.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://deps-upstream-update-viteplus-dev.voidzero-docs.workers.dev (commit f8a6ed4)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://ca34c43e-viteplus-dev.voidzero-docs.workers.dev f8a6ed4 2026-10-06T05:49:01.298Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://e3a27f44-viteplus-dev.voidzero-docs.workers.dev 32ffbb6 2026-10-06T02:50:51.689Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://5a4fd372-viteplus-dev.voidzero-docs.workers.dev 278832d 2026-10-06T01:59:50.566Z Visit the dashboard ↗

@socket-security

socket-security Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​oxc-project/​types@​0.153.01001007295100
Updatednpm/​@​oxc-project/​runtime@​0.152.0 ⏵ 0.153.01001007496100
Updatednpm/​oxfmt@​0.71.0 ⏵ 0.72.094 +110088 +196100
Updatednpm/​oxc-parser@​0.152.0 ⏵ 0.153.08910010096 +2100

View full report

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

✅ Staging deployment successful!

Preview: https://viteplus-staging.void.app/
Commit: f8a6ed4

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

CLI artifact sizes (f8a6ed4)

Final release artifacts built by the canonical build-upstream and build-windows-cli actions.
The dist rows use the Linux build. The core total excludes .node files to match the release artifact.

Artifact Format Base PR Change
packages/cli/dist Directory total 2.28 MiB 2.28 MiB 0 B (0.00%)
packages/core/dist Directory total 3.98 MiB 3.98 MiB 0 B (0.00%)
Combined package dist Directory total 6.26 MiB 6.26 MiB 0 B (0.00%)
vp (Linux x64) Binary 11.35 MiB 11.35 MiB 0 B (0.00%)
vp (Linux x64) gzip -9 4.90 MiB 4.90 MiB 0 B (0.00%)
NAPI (Linux x64) Binary 32.58 MiB 32.58 MiB 0 B (0.00%)
NAPI (Linux x64) gzip -9 12.92 MiB 12.92 MiB 0 B (0.00%)
vp (macOS ARM64) Binary 8.46 MiB 8.46 MiB 0 B (0.00%)
vp (macOS ARM64) gzip -9 4.27 MiB 4.27 MiB 0 B (0.00%)
NAPI (macOS ARM64) Binary 40.10 MiB 40.10 MiB 0 B (0.00%)
NAPI (macOS ARM64) gzip -9 17.20 MiB 17.20 MiB 0 B (0.00%)
vp (Windows x64) Binary 9.23 MiB 9.23 MiB 0 B (0.00%)
vp (Windows x64) gzip -9 4.02 MiB 4.02 MiB -1 B (-0.00%)
NAPI (Windows x64) Binary 27.49 MiB 27.49 MiB 0 B (0.00%)
NAPI (Windows x64) gzip -9 11.02 MiB 11.02 MiB -2 B (-0.00%)
Trampoline (Windows x64) Binary 13.50 KiB 13.50 KiB 0 B (0.00%)
Trampoline (Windows x64) gzip -9 7.09 KiB 7.08 KiB -4 B (-0.06%)
Installer (Windows x64) Binary 4.56 MiB 4.56 MiB 0 B (0.00%)
Installer (Windows x64) gzip -9 2.13 MiB 2.13 MiB -1 B (-0.00%)

Updated import statements for manual migration instructions.

Signed-off-by: MK (fengmk2) <fengmk2@gmail.com>
@fengmk2 fengmk2 self-assigned this Oct 6, 2026
@fengmk2
fengmk2 merged commit 429ecc8 into main Oct 6, 2026
123 checks passed
@fengmk2
fengmk2 deleted the deps/upstream-update branch October 6, 2026 06:08
fengmk2 added a commit that referenced this pull request Oct 7, 2026
…pts (#2907)

Vite+ 1.1 starts `vp dev` faster and makes the interactive prompts
clearer, alongside fixes for `vp migrate`, package-manager commands, and
Windows terminals.

### Highlights

- `vp dev` reaches its local URL about 24% sooner and uses about 30%
less memory in the parent process, because Vite+ no longer loads Vite
and Vitest there before starting the dev server
([#2851](#2851)), by
@camc314.
- Interactive prompts render boxes, logs, and wrapped text consistently,
with clearer hints, validation, and navigation instructions
([#2870](#2870)), by
@cpojer.

### Features

- `vp run` sets `npm_execpath` and `npm_config_user_agent` for npm,
pnpm, and Yarn, so tools such as npm-run-all2 use the project's package
manager instead of falling back to npm
([#2895](#2895)), by
@naokihaba and @tarikermis.
- Upgrade `vite@8.3.1` to `vite@8.3.3`, `rolldown@1.2.11` to
`rolldown@1.2.12`, `vitest@5.0.1` to `vitest@5.0.3`, `oxlint@1.85.0` to
`oxlint@1.87.0`, and `oxfmt@0.70.0` to `oxfmt@0.72.0`. The new lint and
format versions can flag code that passed before, so run `vp fmt` after
upgrading if CI runs `vp check`. `vp migrate` now keeps the React
Refresh `allowCompoundComponents` option because the bundled Oxlint
supports it
([#2871](#2871),
[#2896](#2896),
[#2904](#2904)), by
@voidzero-guard[bot].

### Fixes & Enhancements

- `vp migrate` keeps Oxlint rules written with plugin aliases (such as
`@typescript-eslint/*`, `react-hooks/*`, and `import-x/*`) and removes
rules the bundled Oxlint does not support, listing them in a warning
([#2820](#2820),
[#2906](#2906)), by
@TheAlexLichter and @yusuke99.
- `vp migrate` leaves projects without a declared package manager
unpinned, keeps existing declarations, and points to `vp env pin` when
it infers one
([#2817](#2817)), by
@TheAlexLichter.
- `vp migrate` reports a short error for a directory without
`package.json` instead of an `ENOENT` stack trace
([#2821](#2821)), by
@TheAlexLichter.
- `vp create` in an existing pnpm workspace adds the catalog entries the
new application needs, so installation no longer fails with
`ERR_PNPM_CATALOG_ENTRY_NOT_FOUND_FOR_SPEC`
([#2808](#2808)), by
@SaKaNa-Y.
- On Windows, one Ctrl+C stops `vpr` scripts and managed Bun, pnpm, npm,
and Yarn commands without leaving `cmd.exe` stuck at `Terminate batch
job (Y/N)?`
([#2890](#2890)), by
@fengmk2.
- `vp pack --watch` on Windows rebuilds with the new options after the
config file changes
([#2826](#2826)), by
@liangmiQwQ.
- `vp test doctor` and `vp test complete` run the Vitest subcommands
instead of being treated as test file filters
([#2879](#2879)), by
@liangmiQwQ.
- With isolated dependency layouts such as pnpm's global virtual store,
`vp pack` finds installed Vue language tools and TypeScript Go for
declaration generation, and Playwright browser provider options keep
their types
([#2868](#2868),
[#2865](#2865)), by
@liangmiQwQ.
- Package-manager commands fail when the project's package manager does
not support a named option, instead of silently dropping it and
continuing. Bun 1.4.1+ receives `--offline` and `--prefer-offline`, and
Yarn Classic accepts a single `--filter` for `vp remove`
([#2775](#2775)), by
@jong-kyung.
- `vp pm config` in Bun projects falls back to npm, as its warning says
([#2899](#2899)), by
@jong-kyung.
- `vp pm approve-builds` states that Yarn Berry disables third-party
build scripts by default from 4.14.0, not in every version
([#2902](#2902)), by
@jong-kyung.
- `vp implode` asks you to type `boom` instead of `uninstall` to confirm
([#2901](#2901)), by
@fengmk2.
- Global package installs and updates print a green `+`, and removals a
red `-`, with bold package names in both
([#2828](#2828)), by
@liangmiQwQ.
- Setup headings and command hints keep their colors when the installer
captures stdout
([#2829](#2829)), by
@liangmiQwQ.

### Refactor

- Replace `semver` with `verkit` in the CLI, reducing the bundled CLI
JavaScript by about 26 KB
([#2837](#2837)), by
@liangmiQwQ.
- Share the shim filename logic between setup and `vp env doctor`, and
remove unused config migration metadata
([#2876](#2876),
[#2894](#2894)), by
@jong-kyung.

### Docs

- Announce Vite+ 1.0 on the website and update the homepage `vp pack`
demo ([#2843](#2843),
[#2844](#2844)), by
@TheAlexLichter and @naokihaba.
- Document `vp install -g --node` and explain when `vp env default`
re-resolves versions
([#2885](#2885),
[#2884](#2884)), by
@hyunbinseo.
- Use runnable package examples in the `vpx` guide and `vpx --help`
([#2864](#2864)), by
@SaKaNa-Y.
- Remove the redundant `vp install` step from `setup-vp` CI examples
([#2888](#2888)), by
@yusuke99.
- Explain how to return from a preview build, align manual installation
examples with the installed toolchain, and update the JetBrains Node.js
path and `vp env current --json` example for the split directory layout
([#2886](#2886),
[#2887](#2887),
[#2889](#2889),
[#2891](#2891)), by
@jong-kyung.

### Chore

- Update contributor setup instructions, move the logo files under
`docs/public`, and ignore the root `tmp` directory
([#2832](#2832),
[#2831](#2831),
[#2860](#2860)), by
@liangmiQwQ.
- Stabilize Node API reporter, catalog update, Bun, Yarn, and preview
snapshots ([#2869](#2869),
[#2872](#2872),
[#2893](#2893)), by
@liangmiQwQ and @fengmk2.
- Build the docs with the latest Vite+ and fix flaky CI tests
([#2855](#2855)), by
@fengmk2.
- Remove the unused `set-snapshot-version` action
([#2877](#2877)), by
@jong-kyung.
- Refine the release-manager guidance
([#2827](#2827),
[#2788](#2788)), by
@wan9chi and @fengmk2.

### Bundled Versions

| Tool | Version | Source | Changelog |
| --------------- | ---------- |
-------------------------------------------------------------------------------------------------
|
--------------------------------------------------------------------------------------------------------------------------------------------------
|
| vite | `8.3.3` |
[`fea5b21`](vitejs/vite@fea5b21)
| [8.3.2](https://github.com/vitejs/vite/releases/tag/v8.3.2),
[8.3.3](https://github.com/vitejs/vite/releases/tag/v8.3.3) |
| rolldown | `1.2.12` |
[`45e407b`](rolldown/rolldown@45e407b)
| [1.2.12](https://github.com/rolldown/rolldown/releases/tag/v1.2.12) |
| tsdown | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) |
unchanged |
| vitest | `5.0.3` | [npm](https://npmx.dev/package/vitest/v/5.0.3) |
[5.0.2](https://github.com/vitest-dev/vitest/releases/tag/v5.0.2),
[5.0.3](https://github.com/vitest-dev/vitest/releases/tag/v5.0.3) |
| oxlint | `1.87.0` | [npm](https://npmx.dev/package/oxlint/v/1.87.0) |
[1.86.0](https://github.com/oxc-project/oxc/releases/tag/oxlint_v1.86.0),
[1.87.0](https://github.com/oxc-project/oxc/releases/tag/oxlint_v1.87.0)
|
| oxlint-tsgolint | `7.0.2003` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2003) | unchanged |
| oxfmt | `0.72.0` | [npm](https://npmx.dev/package/oxfmt/v/0.72.0) |
[0.71.0](https://github.com/oxc-project/oxc/releases/tag/oxfmt_v0.71.0),
[0.72.0](https://github.com/oxc-project/oxc/releases/tag/oxfmt_v0.72.0)
|

### Upgrade

```bash
vp upgrade
```

### New Contributors

@hyunbinseo

**Full Changelog**:
v1.0.0...v1.1.0

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant