Skip to content

deps: bump @cldmv/vitest-runner from 1.5.1 to 1.5.3 in the patch group across 1 directory - #61

Merged
cldmv-bot[bot] merged 1 commit into
nextfrom
dependabot/npm_and_yarn/next/patch-2e7833d0e2
Oct 7, 2026
Merged

cldmv-bot[bot] merged 1 commit into
nextfrom
dependabot/npm_and_yarn/next/patch-2e7833d0e2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch group with 1 update in the / directory: @cldmv/vitest-runner.

Updates @cldmv/vitest-runner from 1.5.1 to 1.5.3

Release notes

Sourced from @​cldmv/vitest-runner's releases.

v1.5.3

release: v1.5.3 - fail clearly on Node without require(esm)

vitest-runner v1.5.3 Changelog

Release Date: October 2026 Release Type: Patch Branch: release/1.5.3


Overview

This release changes how dist/index.cjs loads the ES module build. The CommonJS entry no longer goes through createRequire, which kept bundlers from seeing the dependency, and it now fails with a clear, actionable error on a Node.js version that cannot require() an ES module. New node:test checks run the built CommonJS entry point on every test and coverage run.

The ES module build, the CLI and the run() API are unchanged, and on Node.js versions with require(esm) (20.19+ and 22.12+), require("@cldmv/vitest-runner") returns the same named exports as before.

It also raises engines.node to >=22.12.0 (#73). The old >=20.19.0 floor was never true: the runtime dependency chalk 6 needs Node.js 22, the current vitest 5 peer needs ^22.12.0, and CI only ever tested 22.12 and later.


💥 Breaking Changes

Node.js 20 is no longer supported (#73, fixes #72)

engines.node moves from >=20.19.0 to >=22.12.0, despite this being a patch release. In practice Node.js 20 already stopped working cleanly in v1.5.2: chalk 6.0.1 declares Node.js 22 or later, so Node.js 20 installs printed an EBADENGINE warning and failed outright under engine-strict, and vitest 5 does not install on Node.js 20 at all. The floor now says what the package actually needs.

🐛 Bug Fixes

The CommonJS entry uses a plain require() (#69)

src/cjs-shim.cjs, which the build copies verbatim to dist/index.cjs, loaded ./index.mjs through createRequire(__filename). A .cjs file already has require, so createRequire added nothing, and it hid the dependency from bundlers such as esbuild and webpack, which detect dependencies from static require("…") calls. The shim now calls require("./index.mjs") directly and exports its result.

require() fails clearly on Node.js without require(esm) (#69)

On a Node.js version without synchronous require(esm) (before 20.19 on the 20.x line, or before 22.12), the shim's require() threw a generic ERR_REQUIRE_ESM that pointed at the package's internals. The shim now checks process.features.require_module first and, when it is missing, throws an error with the same ERR_REQUIRE_ESM code and a message naming the package, the required versions and the running version:

@cldmv/vitest-runner: require() needs Node.js ^20.19.0 or >=22.12.0 (this is v20.18.0). On older Node.js, load the package with import() instead.

Code that catches ERR_REQUIRE_ESM by code keeps working.

🧪 Tests

  • New tests/cjs/entry.test.cjs, run with node --test by a new test:cjs script after a fresh npm run build. It checks that require() of the built package returns the same named exports as import, and that the version check throws the new error when require(esm) is unavailable.
  • npm test, npm run test:coverage and npm run ci:coverage now run test:cjs after Vitest, so CI exercises the published CommonJS entry point.

📄 License

... (truncated)

Commits
  • a554cdb release: v1.5.3 - fail clearly on Node without require(esm)
  • fed1e56 release: v1.5.2 - bump @​types/node from 25.3.0 to 26.6.3
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the patch group with 1 update in the / directory: [@cldmv/vitest-runner](https://github.com/CLDMV/vitest-runner).


Updates `@cldmv/vitest-runner` from 1.5.1 to 1.5.3
- [Release notes](https://github.com/CLDMV/vitest-runner/releases)
- [Commits](CLDMV/vitest-runner@v1.5.1...v1.5.3)

---
updated-dependencies:
- dependency-name: "@cldmv/vitest-runner"
  dependency-version: 1.5.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 7, 2026

@cldmv-bot cldmv-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by CLDMV-bot: patch bump from 1.5.1 to 1.5.3.

@cldmv-bot
cldmv-bot Bot enabled auto-merge October 7, 2026 12:29
@cldmv-bot cldmv-bot Bot added the type: dependencies Relates to dependency updates, version bumps, or package management label Oct 7, 2026
@cldmv-bot
cldmv-bot Bot merged commit 7e6a66b into next Oct 7, 2026
29 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/next/patch-2e7833d0e2 branch October 7, 2026 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code type: dependencies Relates to dependency updates, version bumps, or package management

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants