Skip to content

deps: upgrade the build toolchain to vite 8 / vitest 4 - #10

Merged
jaredcosulich merged 1 commit into
mainfrom
chore/toolchain-upgrade
Jul 30, 2026
Merged

jaredcosulich merged 1 commit into
mainfrom
chore/toolchain-upgrade

Conversation

@jaredcosulich

Copy link
Copy Markdown
Contributor

Dependency-only: git diff --name-only is package.json and package-lock.json. No source changes were needed.

from to
vite 5.4.x 8.1.5
vitest 2.x 4.1.10
@vitejs/plugin-react 4.x 6.0.5
@crxjs/vite-plugin 2.0.0-beta.26 2.7.1 (stable)

The crxjs move off a beta is arguably the bigger win — that plugin is what produces the MV3 package.

Verified beyond CI

  • 691 tests pass (76 files), and the suite got faster: ~18s → ~14s.
  • Build output is structurally identical to the shipped 0.21 package — file-for-file after normalizing content hashes — and 4,360 bytes smaller. Manifest is still MV3 with the service-worker loader, popup, and all six permissions intact.
  • npm run dev works under vite 8 + crx 2.7.1, serving the real app. The local codeyam/vite-plugin-codeyam.mjs virtual modules (codeyam:components, codeyam:component-scenarios) and the ?isolate harness all resolve. CI never exercises the dev path, so this was checked by hand.
  • npm run test:json keeps the shape .codeyam/editor.json parses as vitest-json, so the codeyam test runner is unaffected.

Security impact

Clears the vitest critical and the vite high advisories.

6 high remain, all one root cause: brace-expansion via eslint-plugin-react → minimatch@3. Not fixable today — eslint-plugin-react@7.37.5 is the latest and peers at eslint <=^9.7, so eslint 10 has no compatible plugin.

⚠️ npm audit fix --force "resolves" this by downgrading eslint-plugin-react 7.37.5 → 7.22.0. Don't run it. It's a dev-only DoS in a linter dependency; it waits for upstream, and the Dependabot eslint group will surface it when ready.

Known cosmetic warning

server.hmr.* is deprecated traces into @crxjs/vite-plugin's own config hook, not this repo.

Not covered

No visual or scenario verification — the 167 codeyam scenarios don't run in CI by design. The build is byte-comparable to 0.21, so the risk is low, but a Chrome load is the final word.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QSEwWfLj6ptnrH3DpegxdM

vite 5 -> 8, vitest 2 -> 4, @vitejs/plugin-react 4 -> 6, and
@crxjs/vite-plugin 2.0.0-beta.26 -> 2.7.1 (beta -> stable). Zero source
changes were needed; this is a dependency-only commit.

The blocker I expected did not materialize: @crxjs has a stable 2.7.1
declaring vite ^8 support, so the MV3 packaging path moves off a beta at
the same time.

Clears the vitest critical and the vite high advisories. What remains is
6 high, all one root cause: brace-expansion via eslint-plugin-react ->
minimatch@3. That is NOT fixable today — eslint-plugin-react@7.37.5 is
the latest and peers at eslint <=^9.7, so eslint 10 has no compatible
plugin. `npm audit fix --force` "solves" it by DOWNGRADING
eslint-plugin-react 7.37.5 -> 7.22.0; don't. Dev-only DoS in a linter
dependency, so it waits for upstream.

Verified beyond CI:
- 691 tests pass (76 files); suite got faster, ~18s -> ~14s.
- Build output is structurally identical to the 0.21 package
  (file-for-file after normalizing content hashes) and 4360 bytes
  smaller. Manifest still MV3 with the service-worker loader, popup, and
  all six permissions intact.
- `npm run dev` serves the real app under vite 8 + crx 2.7.1, and the
  local codeyam plugin's virtual modules (codeyam:components,
  codeyam:component-scenarios) plus the ?isolate harness all resolve.
  CI never exercises the dev path, so this was checked by hand.
- `npm run test:json` keeps the shape .codeyam/editor.json parses as
  vitest-json, so the codeyam test runner is unaffected.

The one remaining warning (`server.hmr.*` deprecated) traces into
@crxjs/vite-plugin's own config hook, not this repo.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QSEwWfLj6ptnrH3DpegxdM
@jaredcosulich
jaredcosulich merged commit 2d62f37 into main Jul 30, 2026
3 of 4 checks passed
@jaredcosulich
jaredcosulich deleted the chore/toolchain-upgrade branch July 30, 2026 11:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant