Skip to content

chore(deps-fe)(deps-dev): bump vite from 8.3.0 to 8.3.1 in /frontend in the frontend-build-tools group - #636

Merged
Opselon merged 4 commits into
mainfrom
dependabot/npm_and_yarn/frontend/frontend-build-tools-1a5240e55e
Oct 5, 2026
Merged

Opselon merged 4 commits into
mainfrom
dependabot/npm_and_yarn/frontend/frontend-build-tools-1a5240e55e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the frontend-build-tools group in /frontend with 1 update: vite.

Updates vite from 8.3.0 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

Commits
  • 39ddf7c release: v8.3.1 (#23573)
  • f68c0d5 fix: handle server.ws: false in mergeConfig (#23511)
  • 6f831f9 fix(server): avoid reinitializing watcher when adding file after server close...
  • 04fc30a fix(sourcemap): skip URL source roots when injecting sources content (#23519)
  • 5f89433 fix(optimizer): resolve pending discovered dep processing on close before ini...
  • 63567c7 chore(optimizer): add debug log when waiting for dep before init (#23566)
  • e8990c4 fix(deps): update all non-major dependencies (#23537)
  • af7cdf6 refactor: replace find with some (#23554)
  • 39330f4 fix(optimizer): don't skip imports whose binding starts with type (#23540)
  • 9abd99b refactor: remove duplicate configurations (#23532)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the frontend-build-tools group in /frontend with 1 update: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).


Updates `vite` from 8.3.0 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-build-tools
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@dependabot
dependabot Bot requested a review from Opselon as a code owner October 4, 2026 04:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@socket-security

socket-security Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​vite@​8.3.0 ⏵ 8.3.199 +110082 +197100

View full report

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

🔴 NSE Evidence Report — #636

Status: FAIL · Branch: dependabot/npm_and_yarn/frontend/frontend-build-tools-1a5240e55e → main · HEAD: 71acfb021bab

🔗 Revision

Source SHA
PR HEAD 71acfb021bab
Local unknown
CI 71acfb021bab

Overall

🔴 FAIL

Required CI checks contain failures.

Primary affected files:

  1. dynamic/agents/github-advanced-security
  2. Processing Request

🧪 Test Matrix

Gate Status Passed Failed Skipped Duration
Aggregate CI Results ⏭️ — 0 — 0s
Heavy CI (${{ matrix.suite }}) ⏭️ — 0 — 0s
Extended Validation (Tier 2) ⏭️ — 0 — 0s
Full Runtime Overall Verdict ✅ — 0 — 10s
DB Fabric Certification (SQLite ↔ PostgreSQL) ✅ — 0 — 3m43s
CodeQL ✅ — 0 — 2s
osv-scanner ✅ — 0 — 3s
Trivy ✅ — 0 — 4s
Deploy GitHub Pages ⏭️ — 0 — 0s
Socket Security: Pull Request Alerts ✅ — 0 — 8s
github-advanced-security ❌ — 1 — 51s
OSV Scanner / osv-scan ✅ — 0 — 27s
Dependency Manifest Diff ✅ — 0 — 8s
CI Integrity and Change Classification ✅ — 0 — 10s
Code Quality & Tests ✅ — 0 — 11m28s
Full NSE Runtime (sqlite) ✅ — 0 — 4m57s
MetaTrader 5 Wine Runtime ✅ — 0 — 8m01s
Py Tests (macos-latest) ✅ — 0 — 20s
Validate documentation ✅ — 0 — 10s
Full NSE Runtime (postgres) ✅ — 0 — 4m47s
Py Tests (windows-latest) ✅ — 0 — 2m41s
Migration safety (fail-loud + version postconditions) ✅ — 0 — 32s
Go API (ubuntu-latest) ✅ — 0 — 26s
React ↔ Go API Contract (Ubuntu) ✅ — 0 — 31s
Trivy Vulnerability Scan ✅ — 0 — 33s
Dependency drift (lock vs pyproject) ✅ — 0 — 9s
Go API (windows-latest) ✅ — 0 — 59s
CodeQL Analysis ✅ — 0 — 1m32s
Frontend JS Unit Tests ✅ — 0 — 22s
Socket Security: Project Report ✅ — 0 — 8s

🔴 Affected Files

Processing Request

  • Processing Request
    • SessionModelError
    • CI: github-advanced-security

dynamic/agents/github-advanced-security

  • dynamic/agents/github-advanced-security
    • CI: github-advanced-security
    • Failed step: Processing Request (Linux)

🔴 What Failed and Why

1. Processing Request (Linux)

Severity: ERROR

Where: dynamic/agents/github-advanced-security

Failed step: Processing Request (Linux)

Kind: SECURITY_FINDING

Result / Why:

Process completed with exit code 1.

CI: github-advanced-security (logs)

Evidence: source github-checks, via github-checks

2. SessionModelError

Where: Processing Request

Kind: CI_FAILURE

Error / rule: SessionModelError

Result / Why:

Error creating PR review request: SessionModelError: You have exceeded your monthly quota (Request ID: 801A:3C272D:2A8645B:2DB8115:6AC41E4E); cause: Error: You have exceeded your monthly quota (Request ID: 801A:3C272D:2A8645B:2DB8115:6AC41E4E) (errorDetails: {"configurationError":false,"stack":"SessionModelError: You have exceeded your monthly quota (Request ID: 801A:3C272D:2A8645B:2DB8115:6AC41E4E)\n    at LI (file:///home/runner/work/_temp/***-action-main/dist-autofind-ts/ts/autofind.js:1114:10116)\n    at runNextTicks (node:internal/process/task_queues:65:5)\n    at process.processImmediate (node:internal/timers:541:9)\n    at async file:///home/runner/work/_temp/***-action-main/dist-auto …

Trace:

Error creating PR review request: SessionModelError: You have exceeded your monthly quota (Request ID: 801A:3C272D:2A8645B:2DB8115:6AC41E4E); cause: Error: You have exceeded your monthly quota (Request ID: 801A:3C272D:2A8645B:2DB8115:6AC41E4E) (errorDetails: {"configurationError":false,"stack":"SessionModelError: You have exceeded your monthly quota (Request ID: 801A:3C272D:2A8645B:2DB8115:6AC41E4E)\n    at LI (file:///home/runner/work/_temp/***-action-main/dist-autofind-ts/ts/autofind.js:1114:10116)\n    at runNextTicks (node:internal/process/task_queues:65:5)\n    at process.processImmediate (node:internal/timers:541:9)\n    at async file:///home/runner/work/_temp/***-action-main/dist-auto …
Reporting error to sweagentd...
Error successfully reported to sweagentd session.
Error successfully reported to sweagentd backend.
eb [SessionModelError]: You have exceeded your monthly quota (Request ID: 801A:3C272D:2A8645B:2DB8115:6AC41E4E)
at LI (file:///home/runner/work/_temp/***-action-main/dist-autofind-ts/ts/autofind.js:1114:10116)
at runNextTicks (node:internal/process/task_queues:65:5)
at process.processImmediate (node:internal/timers:541:9)
at async file:///home/runner/work/_temp/***-action-main/dist-autofind-ts/ts/autofind.js:1003:8471
at async jp (file:///home/runner/work/_temp/***-action-main/dist-autofind-ts/ts/autofind.js:1003:8529)
at async Zn (file:///home/runner/work/_temp/***-action-main/dist-autofind-ts/ts/autofind.js:1114:10473)
at async QR (file:///home/runner/work/_temp/***-action-main/dist-autofind-ts/ts/autofind.js:1600:1365)
at async MF (file:///home/runner/ …

CI: github-advanced-security (logs)

Evidence: source job-logs, via job-logs

⚠️ Warnings

1. Full Runtime Overall Verdict

Severity: WARNING

Where: unknown

Result / Details:

sqlite has warnings; inspect provider_runtime_soak.json

CI: Full Runtime Overall Verdict (logs)

Evidence: source github-checks, via github-checks

2. Full Runtime Overall Verdict

Severity: WARNING

Where: unknown

Result / Details:

postgres has warnings; inspect provider_runtime_soak.json

CI: Full Runtime Overall Verdict (logs)

Evidence: source github-checks, via github-checks

3. Full NSE Runtime (sqlite)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:16.068+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

4. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:12.054+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

5. Full NSE Runtime (sqlite)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:12.045+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

6. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:08.052+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

7. Full NSE Runtime (sqlite)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:08.040+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

8. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:04.038+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

9. Full NSE Runtime (sqlite)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:04.028+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

10. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:01.223+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

11. Full NSE Runtime (sqlite)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:01.213+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

12. Full NSE Runtime (sqlite)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:03:51.791+03:30 [warning  ] [LATENCY_REGRESSION] event=E2E_P95_REGRESSED p95_ms=75.294 budget_p95_ms=75.0 epochs=1 [nexus_scalp.application.live.inference]

CI: Full NSE Runtime (sqlite) (logs)

Evidence: source github-checks, via github-checks

13. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:16.220+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

14. Full NSE Runtime (postgres)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:16.154+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

15. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:12.174+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

16. Full NSE Runtime (postgres)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:12.120+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

17. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:08.151+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

18. Full NSE Runtime (postgres)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:08.099+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

19. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:04.102+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

20. Full NSE Runtime (postgres)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:04.050+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

21. ENTRY_BLOCKED

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:00.784+03:30 [warning  ] [ENTRY_BLOCKED] layer=RISK_ENGINE reason=RISK_EVALUATION_REJECTED action=BUY_LIMIT symbol=XAUUSD [REDACTED_SECRET] [nexus_scalp.application.live.decision_executor]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

22. Full NSE Runtime (postgres)

Severity: WARNING

Where: unknown

Result / Details:

2026-10-05T22:04:00.727+03:30 [warning  ] Proposal rejected: Pending entry price is too close to market (Stops Level violation) [nexus_scalp.risk.risk_engine]

CI: Full NSE Runtime (postgres) (logs)

Evidence: source github-checks, via github-checks

🏗️ CI Jobs

Workflow Job Status Details
CI Aggregate CI Results ⏭️ SKIPPED logs
CI Heavy CI (${{ matrix.suite }}) ⏭️ SKIPPED logs
CI Extended Validation (Tier 2) ⏭️ SKIPPED logs
CI Full Runtime Overall Verdict ✅ SUCCESS logs
CI DB Fabric Certification (SQLite ↔ PostgreSQL) ✅ SUCCESS logs
GitHub Advanced Security CodeQL ✅ SUCCESS logs
GitHub Advanced Security osv-scanner ✅ SUCCESS logs
GitHub Advanced Security Trivy ✅ SUCCESS logs
Docs Deploy GitHub Pages ⏭️ SKIPPED logs
Socket Security Socket Security: Pull Request Alerts ✅ SUCCESS logs
Code scanning AI findings on PR #636 github-advanced-security ❌ FAILURE logs
OSV Dependency Scan OSV Scanner / osv-scan ✅ SUCCESS logs
Lockfile Diff Dependency Manifest Diff ✅ SUCCESS logs
CI CI Integrity and Change Classification ✅ SUCCESS logs
CI Code Quality & Tests ✅ SUCCESS logs
CI Full NSE Runtime (sqlite) ✅ SUCCESS logs
CI MetaTrader 5 Wine Runtime ✅ SUCCESS logs
Tests (OS Matrix) Py Tests (macos-latest) ✅ SUCCESS logs
Docs Validate documentation ✅ SUCCESS logs
CI Full NSE Runtime (postgres) ✅ SUCCESS logs
Tests (OS Matrix) Py Tests (windows-latest) ✅ SUCCESS logs
Dependency Lock & Migration Safety Migration safety (fail-loud + version postconditions) ✅ SUCCESS logs
Go API Go API (ubuntu-latest) ✅ SUCCESS logs
Go API React ↔ Go API Contract (Ubuntu) ✅ SUCCESS logs
Security Trivy Vulnerability Scan ✅ SUCCESS logs
Dependency Lock & Migration Safety Dependency drift (lock vs pyproject) ✅ SUCCESS logs
Go API Go API (windows-latest) ✅ SUCCESS logs
Security CodeQL Analysis ✅ SUCCESS logs
JS Tests Frontend JS Unit Tests ✅ SUCCESS logs
Socket Security Socket Security: Project Report ✅ SUCCESS logs

🟢 Final Verdict — Merge? Yes

Every merge precondition observed is satisfied:

  • 1 check(s) not green: github-advanced-security — the base branch's required list could not be read, so GitHub's own mergeability answer is used instead.
  • Not observed: which checks the base branch requires, required-review count — could not be read.
  • GitHub reports this PR is mergeable, which already accounts for the unreadable rules above.

NSE Evidence Report — generated by nse pr report. Statuses are deterministic: 🟢 PASS · 🟡 IN PROGRESS · 🟠 BLOCKED · 🔴 FAIL · ⚪ UNKNOWN. unknown = the evidence did not determine it. This comment is updated in place; it never duplicates.

Dependabot bumps pyproject.toml ranges but cannot run uv pip compile,
so the compiled artifacts must ship in the same PR (see
.github/dependabot.yml lockfile-safe contract). Regenerated with
uv 0.12.10 --python-version 3.11.
@Opselon
Opselon merged commit 7765ca4 into main Oct 5, 2026
29 of 30 checks passed
@Opselon
Opselon deleted the dependabot/npm_and_yarn/frontend/frontend-build-tools-1a5240e55e branch October 5, 2026 22:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant