Repository navigation
chore(deps-fe)(deps-dev): bump vite from 8.3.0 to 8.3.1 in /frontend in the frontend-build-tools group - #636
Conversation
Bumps the frontend-build-tools group in /frontend with 1 update: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `vite` from 8.3.0 to 8.3.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.3.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-build-tools ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
🔴 NSE Evidence Report — #636Status: FAIL · Branch: 🔗 Revision
Overall🔴 FAIL Required CI checks contain failures. Primary affected files:
🧪 Test Matrix
🔴 Affected Files
|
| Workflow | Job | Status | Details |
|---|---|---|---|
CI |
Aggregate CI Results |
⏭️ SKIPPED | logs |
CI |
Heavy CI (${{ matrix.suite }}) |
⏭️ SKIPPED | logs |
CI |
Extended Validation (Tier 2) |
⏭️ SKIPPED | logs |
CI |
Full Runtime Overall Verdict |
✅ SUCCESS | logs |
CI |
DB Fabric Certification (SQLite ↔ PostgreSQL) |
✅ SUCCESS | logs |
GitHub Advanced Security |
CodeQL |
✅ SUCCESS | logs |
GitHub Advanced Security |
osv-scanner |
✅ SUCCESS | logs |
GitHub Advanced Security |
Trivy |
✅ SUCCESS | logs |
Docs |
Deploy GitHub Pages |
⏭️ SKIPPED | logs |
Socket Security |
Socket Security: Pull Request Alerts |
✅ SUCCESS | logs |
Code scanning AI findings on PR #636 |
github-advanced-security |
❌ FAILURE | logs |
OSV Dependency Scan |
OSV Scanner / osv-scan |
✅ SUCCESS | logs |
Lockfile Diff |
Dependency Manifest Diff |
✅ SUCCESS | logs |
CI |
CI Integrity and Change Classification |
✅ SUCCESS | logs |
CI |
Code Quality & Tests |
✅ SUCCESS | logs |
CI |
Full NSE Runtime (sqlite) |
✅ SUCCESS | logs |
CI |
MetaTrader 5 Wine Runtime |
✅ SUCCESS | logs |
Tests (OS Matrix) |
Py Tests (macos-latest) |
✅ SUCCESS | logs |
Docs |
Validate documentation |
✅ SUCCESS | logs |
CI |
Full NSE Runtime (postgres) |
✅ SUCCESS | logs |
Tests (OS Matrix) |
Py Tests (windows-latest) |
✅ SUCCESS | logs |
Dependency Lock & Migration Safety |
Migration safety (fail-loud + version postconditions) |
✅ SUCCESS | logs |
Go API |
Go API (ubuntu-latest) |
✅ SUCCESS | logs |
Go API |
React ↔ Go API Contract (Ubuntu) |
✅ SUCCESS | logs |
Security |
Trivy Vulnerability Scan |
✅ SUCCESS | logs |
Dependency Lock & Migration Safety |
Dependency drift (lock vs pyproject) |
✅ SUCCESS | logs |
Go API |
Go API (windows-latest) |
✅ SUCCESS | logs |
Security |
CodeQL Analysis |
✅ SUCCESS | logs |
JS Tests |
Frontend JS Unit Tests |
✅ SUCCESS | logs |
Socket Security |
Socket Security: Project Report |
✅ SUCCESS | logs |
🟢 Final Verdict — Merge? Yes
Every merge precondition observed is satisfied:
- 1 check(s) not green:
github-advanced-security— the base branch's required list could not be read, so GitHub's own mergeability answer is used instead. - Not observed: which checks the base branch requires, required-review count — could not be read.
- GitHub reports this PR is mergeable, which already accounts for the unreadable rules above.
NSE Evidence Report — generated by nse pr report. Statuses are deterministic: 🟢 PASS · 🟡 IN PROGRESS · 🟠 BLOCKED · 🔴 FAIL · ⚪ UNKNOWN. unknown = the evidence did not determine it. This comment is updated in place; it never duplicates.
Dependabot bumps pyproject.toml ranges but cannot run uv pip compile, so the compiled artifacts must ship in the same PR (see .github/dependabot.yml lockfile-safe contract). Regenerated with uv 0.12.10 --python-version 3.11.
Bumps the frontend-build-tools group in /frontend with 1 update: vite.
Updates
vitefrom 8.3.0 to 8.3.1Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
Commits
39ddf7crelease: v8.3.1 (#23573)f68c0d5fix: handleserver.ws: falsein mergeConfig (#23511)6f831f9fix(server): avoid reinitializing watcher when adding file after server close...04fc30afix(sourcemap): skip URL source roots when injecting sources content (#23519)5f89433fix(optimizer): resolve pending discovered dep processing on close before ini...63567c7chore(optimizer): add debug log when waiting for dep before init (#23566)e8990c4fix(deps): update all non-major dependencies (#23537)af7cdf6refactor: replacefindwithsome(#23554)39330f4fix(optimizer): don't skip imports whose binding starts with type (#23540)9abd99brefactor: remove duplicate configurations (#23532)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions