Skip to content

chore(deps-dev): bump @vitest/coverage-v8 from 4.1.0 to 4.1.2#225

Merged
urugus merged 1 commit intomainfrom
dependabot/npm_and_yarn/vitest/coverage-v8-4.1.2
Mar 31, 2026
Merged

chore(deps-dev): bump @vitest/coverage-v8 from 4.1.0 to 4.1.2#225
urugus merged 1 commit intomainfrom
dependabot/npm_and_yarn/vitest/coverage-v8-4.1.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 30, 2026

Bumps @vitest/coverage-v8 from 4.1.0 to 4.1.2.

Release notes

Sourced from @​vitest/coverage-v8's releases.

v4.1.2

This release bumps Vitest's flatted version and removes version pinning to resolve flatted's CVE related issues (vitest-dev/vitest#9975).

   🐞 Bug Fixes

    View changes on GitHub

v4.1.1

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Commits

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Mar 30, 2026

Labels

The following labels could not be found: dependencies, npm. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/vitest/coverage-v8-4.1.2 branch from 2e808de to 09c81a5 Compare March 31, 2026 21:21
@urugus
Copy link
Copy Markdown
Owner

urugus commented Mar 31, 2026

@vitest/coverage-v8 4.1.0 → 4.1.2 調査レポート

変更内容

v4.1.1

  • カバレッジプロバイダーの型を簡素化
  • ビルトインプロバイダーをmodule runnerなしでロードするよう修正
  • HTMLレポーター重複時のカバレッジレポート保全

v4.1.2

  • セキュリティ修正: 依存パッケージ flatted のバージョンバンプ — CVE-2026-33228GHSA-rf6f-7fwh-wjgh)への対応
  • coverageConfigDefaults の値と型の修正
  • その他バグ修正

セキュリティ

  • CVE-2026-33228 への対応が含まれるため、アップグレードは積極的に行うべき
  • サプライチェーン攻撃の報告なし

破壊的変更

  • なし(パッチリリース)

CI状況

  • CIは失敗中: @vitest/coverage-v8@4.1.2 は peer dependency として vitest@4.1.2 を要求するが、プロジェクトの vitest4.1.0 のまま
  • 対応: PR chore(deps-dev): bump vitest from 4.1.0 to 4.1.2 #224 (vitest 4.1.0 → 4.1.2) と合わせてマージする必要あり

結論

パッケージ自体は安全。ただし単独マージは不可。PR #224 と統合してマージすること。

@urugus
Copy link
Copy Markdown
Owner

urugus commented Mar 31, 2026

@dependabot rebase

Bumps [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) from 4.1.0 to 4.1.2.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.2/packages/coverage-v8)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/vitest/coverage-v8-4.1.2 branch from 09c81a5 to 7d57e23 Compare March 31, 2026 21:32
@urugus urugus merged commit 9c9fbd6 into main Mar 31, 2026
3 of 4 checks passed
@urugus urugus deleted the dependabot/npm_and_yarn/vitest/coverage-v8-4.1.2 branch March 31, 2026 21:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant