Skip to content

[security](deps-dev): bump vitest from 4.1.4 to 4.1.5#51

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.5
Open

[security](deps-dev): bump vitest from 4.1.4 to 4.1.5#51
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 4, 2026

Summary

Updates Vitest from 4.1.4 to 4.1.5 via Dependabot.

This is a security/dependency maintenance PR for the npm package set. The
upstream release contains bug fixes and small test-runner behavior updates.

Checklist

  • Linked an issue or explained why none exists
  • Added/updated tests or explained why not
  • Updated docs where needed
  • Considered backward compatibility / migrations
  • Verified no secrets are committed
  • Confirmed CI is green or explained failures

Testing

  • lint-test: passed in GitHub Actions
  • npm-audit: passed in GitHub Actions
  • security-scan: passed in GitHub Actions
  • CodeQL: passed in GitHub Actions
  • Socket Security: Project Report: passed in GitHub checks
  • Socket Security: Pull Request Alerts: passed in GitHub checks

Review artifacts

Notes

No linked issue. This PR was opened by Dependabot for dependency maintenance.

The previous failing pr-template check was caused by Dependabot's generated
body missing this repository's required PR body sections, not by a code or
dependency validation failure.

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.4 to 4.1.5.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.5/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 4, 2026

Labels

The following labels could not be found: security. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Dependency updates label May 4, 2026
@chatgpt-codex-connector
Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.

@socket-security
Copy link
Copy Markdown

socket-security Bot commented May 4, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedvitest@​4.1.4 ⏵ 4.1.596 +110079 +199100

View full report

@jscraik
Copy link
Copy Markdown
Owner

jscraik commented May 7, 2026

@dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 7, 2026

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Trigger a fresh pull_request synchronize run after updating the Dependabot PR body to satisfy the repository PR template gate.

Co-authored-by: Codex <noreply@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant