deps(deps-dev): bump vite from 8.0.9 to 8.1.5 in /viewer - #111
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.9 to 8.1.5. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.5/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.1.5 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Land the security bump that Dependabot #111 could not merge (conflicts). Update the Lane Eleven triage log with merge/close/leave-open outcomes. Co-authored-by: DrunkOnJava <DrunkOnJava@users.noreply.github.com>
|
Lane Eleven triage: Closing as superseded. This Dependabot branch conflicts with |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
## Summary Lane Eleven Dependabot triage: - Document merge/close/leave-open decisions for all 15 open Dependabot PRs in `docs/dependabot-triage-2026-08-29.md`. - Raise viewer `vite` package.json range to `^8.2.2` to match the secure lockfile already on `main` (8.2.2). Dependabot #111 (8.1.5) conflicted and is closed as superseded — 8.2.2 is newer than that target. ### Already merged via Dependabot (this session) - #104 playwright, #69 setup-node, #6 upload-artifact, #4 setup-python, #3 rust-cache, #2 download-artifact ### Closed as obsolete/superseded - #102 / #76 pyo3 (main already on 0.29), #72 quick-xml (main on 0.41), #111 vite (superseded; main lock already 8.2.2) ### Left open for dedicated migrations - #109 TypeScript 7, #108 three.js 0.185, #74 thiserror 2, #71 criterion 0.7, #70 cfb 0.14 ## Test plan - [x] `cd viewer && npm run typecheck` - [x] `cd viewer && npm audit --audit-level=high` → 0 vulnerabilities - [ ] CI on this PR --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: DrunkOnJava <DrunkOnJava@users.noreply.github.com>
## Summary Lane Eleven Dependabot triage: - Document merge/close/leave-open decisions for all 15 open Dependabot PRs in `docs/dependabot-triage-2026-08-29.md`. - Raise viewer `vite` package.json range to `^8.2.2` to match the secure lockfile already on `main` (8.2.2). Dependabot #111 (8.1.5) conflicted and is closed as superseded — 8.2.2 is newer than that target. ### Already merged via Dependabot (this session) - #104 playwright, #69 setup-node, #6 upload-artifact, #4 setup-python, #3 rust-cache, #2 download-artifact ### Closed as obsolete/superseded - #102 / #76 pyo3 (main already on 0.29), #72 quick-xml (main on 0.41), #111 vite (superseded; main lock already 8.2.2) ### Left open for dedicated migrations - #109 TypeScript 7, #108 three.js 0.185, #74 thiserror 2, #71 criterion 0.7, #70 cfb 0.14 ## Test plan - [x] `cd viewer && npm run typecheck` - [x] `cd viewer && npm audit --audit-level=high` → 0 vulnerabilities - [ ] CI on this PR --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: DrunkOnJava <DrunkOnJava@users.noreply.github.com>
Bumps vite from 8.0.9 to 8.1.5.
Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
5e7fe12release: v8.1.56c08c39fix(optimizer): respect importer module format for dynamic import interop wit...5a72b87fix(client): overlay error message format align rolldown (#22869)f8b38e3fix(module-runner): don't crash stack-trace source mapping when globalThis.Bu...8100320fix(bundled-dev): avoid duplicatedbuildEnd(#22931)c88c236docs(build): fix incorrect@defaultfor build.cssMinify (#22948)b59a73ffix(ssr): scope switch-case declarations to the switch, not the function (#22...fef682dfix(deps): update all non-major dependencies (#22921)3c345e4fix(deps): update rolldown-related dependencies (#22922)369ed60docs(build): fix incorrect@defaultfor build.lib.formats (#22911)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)