Skip to content

chore(deps-dev): bump the dev-dependencies group with 2 updates - #74

Merged
karlwaldman merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-03a3299ce5
Aug 25, 2026
Merged

chore(deps-dev): bump the dev-dependencies group with 2 updates#74
karlwaldman merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-03a3299ce5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 2 updates: @vitest/coverage-v8 and vitest.

Updates @vitest/coverage-v8 from 4.1.10 to 4.1.11

Release notes

Sourced from @​vitest/coverage-v8's releases.

v4.1.11

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates vitest from 4.1.10 to 4.1.11

Release notes

Sourced from vitest's releases.

v4.1.11

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • 9bd8d46 chore: release v4.1.11 (#10995)
  • 9851dbc fix(browser): trigger playwright/chromium gc on lower disk availability [back...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dev-dependencies group with 2 updates: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `@vitest/coverage-v8` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/coverage-v8)

Updates `vitest` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026
@karlwaldman

Copy link
Copy Markdown
Member

PARM adversarial review — PASS

Risk: low. Vitest patch update only; diff is limited to package-lock.json, with no SDK runtime source or package version change.

Refutation attempts and proof on head 0dbee2c:

  • Fresh npm ci: PASS.
  • Secret guard and 36-surface storefront claims guard: PASS.
  • Full Vitest suite: PASS — 34 files, 508 passed, 1 skipped.
  • ESM/CJS TypeScript build: PASS.
  • Executable snippet contract: PASS — 6/6 fixtures plus 4 manifest tests.
  • Red-capable guard proof: temporarily changed the exported SDK name; tests/user-agent.test.ts failed 6 assertions including the server-attribution regex (exit 1). Restored source; targeted suite passed 13/13.

Adversarial finding: the runner update did not weaken discovery, attribution, package-shape, or snippet checks. No merge blocker found.

@karlwaldman
karlwaldman merged commit 36f4500 into main Aug 25, 2026
7 checks passed
@karlwaldman
karlwaldman deleted the dependabot/npm_and_yarn/dev-dependencies-03a3299ce5 branch August 25, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant