deps: upgrade the build toolchain to vite 8 / vitest 4 - #10
Merged
Merged
Conversation
vite 5 -> 8, vitest 2 -> 4, @vitejs/plugin-react 4 -> 6, and @crxjs/vite-plugin 2.0.0-beta.26 -> 2.7.1 (beta -> stable). Zero source changes were needed; this is a dependency-only commit. The blocker I expected did not materialize: @crxjs has a stable 2.7.1 declaring vite ^8 support, so the MV3 packaging path moves off a beta at the same time. Clears the vitest critical and the vite high advisories. What remains is 6 high, all one root cause: brace-expansion via eslint-plugin-react -> minimatch@3. That is NOT fixable today — eslint-plugin-react@7.37.5 is the latest and peers at eslint <=^9.7, so eslint 10 has no compatible plugin. `npm audit fix --force` "solves" it by DOWNGRADING eslint-plugin-react 7.37.5 -> 7.22.0; don't. Dev-only DoS in a linter dependency, so it waits for upstream. Verified beyond CI: - 691 tests pass (76 files); suite got faster, ~18s -> ~14s. - Build output is structurally identical to the 0.21 package (file-for-file after normalizing content hashes) and 4360 bytes smaller. Manifest still MV3 with the service-worker loader, popup, and all six permissions intact. - `npm run dev` serves the real app under vite 8 + crx 2.7.1, and the local codeyam plugin's virtual modules (codeyam:components, codeyam:component-scenarios) plus the ?isolate harness all resolve. CI never exercises the dev path, so this was checked by hand. - `npm run test:json` keeps the shape .codeyam/editor.json parses as vitest-json, so the codeyam test runner is unaffected. The one remaining warning (`server.hmr.*` deprecated) traces into @crxjs/vite-plugin's own config hook, not this repo. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QSEwWfLj6ptnrH3DpegxdM
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependency-only:
git diff --name-onlyispackage.jsonandpackage-lock.json. No source changes were needed.The crxjs move off a beta is arguably the bigger win — that plugin is what produces the MV3 package.
Verified beyond CI
npm run devworks under vite 8 + crx 2.7.1, serving the real app. The localcodeyam/vite-plugin-codeyam.mjsvirtual modules (codeyam:components,codeyam:component-scenarios) and the?isolateharness all resolve. CI never exercises the dev path, so this was checked by hand.npm run test:jsonkeeps the shape.codeyam/editor.jsonparses asvitest-json, so the codeyam test runner is unaffected.Security impact
Clears the vitest critical and the vite high advisories.
6 high remain, all one root cause:
brace-expansionviaeslint-plugin-react→minimatch@3. Not fixable today —eslint-plugin-react@7.37.5is the latest and peers ateslint <=^9.7, so eslint 10 has no compatible plugin.npm audit fix --force"resolves" this by downgradingeslint-plugin-react7.37.5 → 7.22.0. Don't run it. It's a dev-only DoS in a linter dependency; it waits for upstream, and the Dependaboteslintgroup will surface it when ready.Known cosmetic warning
server.hmr.* is deprecatedtraces into@crxjs/vite-plugin's ownconfighook, not this repo.Not covered
No visual or scenario verification — the 167 codeyam scenarios don't run in CI by design. The build is byte-comparable to 0.21, so the risk is low, but a Chrome load is the final word.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QSEwWfLj6ptnrH3DpegxdM