Skip to content

[codex] Refresh vitest security update lockfile - #201

Merged
biggora merged 3 commits into
masterfrom
codex/ope-592-vitest-lockfile
Jun 3, 2026
Merged

biggora merged 3 commits into
masterfrom
codex/ope-592-vitest-lockfile

Conversation

@nahremenkova1

Copy link
Copy Markdown
Collaborator

Summary

Root cause

PR #200 updated the Vitest manifest entry but the branch state still failed npm ci because the lockfile was not in sync with the declared dependency graph.

Validation

  • npm ci --ignore-scripts
  • npm audit --audit-level=critical --json
  • npm test

Notes

This draft PR is the equivalent fix path for Dependabot PR #200.

@nahremenkova1
nahremenkova1 force-pushed the codex/ope-592-vitest-lockfile branch from bda2e8f to 2e3d419 Compare June 2, 2026 15:15

biggora commented Jun 2, 2026

Copy link
Copy Markdown
Owner

Repaired the branch behind this PR and re-published it on codex/ope-592-vitest-lockfile.

  • Root cause: the branch was based on stale master before origin/master picked up the separate qs security bump, so package.json and package-lock.json drifted into a state that broke npm ci and left the advisory path open.
  • Action taken: rebased onto current origin/master and force-pushed the repaired branch.
  • Verification run locally after the rebase:
  • npm ci -> installed cleanly, found 0 vulnerabilities
  • npm audit --json -> 0 vulnerabilities
  • npm run lint -> exit 0
  • npm run typecheck -> exit 0
  • npm run test:vitest -> 13 files / 187 tests passed

GitHub still reports the critical alert on the default branch until this PR merges, but the branch attached to #201 is now repaired and reviewable.

@nahremenkova1

Copy link
Copy Markdown
Collaborator Author

The previous CI failure is stale relative to the current branch state. Fresh local verification on 2026-06-03 against both the PR head (2e3d419) and GitHub merge ref (eb71e40) succeeded:

  • npm ci --ignore-scripts
  • npm audit --audit-level=critical --json -> critical: 0

Rerunning the GitHub CI workflow now against the current PR head.

@nahremenkova1

Copy link
Copy Markdown
Collaborator Author

Published a follow-up lockfile-only fix for GitHub Actions npm 10 compatibility.

Root cause from this heartbeat:

  • the previous lockfile passed under local npm 11.12.1 but failed under the runner's npm 10.8.2 with missing vitest -> esbuild@0.28.0 optional entries
  • regenerated package-lock.json using npm 10.8.2 semantics so the lock is valid for the CI matrix

Fresh local verification before push:

  • npx -y npm@10.8.2 ci --ignore-scripts
  • npm ci --ignore-scripts
  • npm audit --audit-level=critical --json -> critical: 0
  • npm test -> 13 files / 187 tests passed

Waiting on the new CI run triggered by commit 36c0b75.

@nahremenkova1

Copy link
Copy Markdown
Collaborator Author

Executor follow-up from June 3, 2026:

  • regenerated the lockfile with npm 10 compatibility and pushed commit 36c0b75
  • new CI result: Node 20/22/24 clear install, lint, typecheck, test, and build
  • remaining blocker is the Node 18 leg, where Vitest 4.1.x now crashes during startup because upstream requires Node 20+ (node:util.styleText is missing on Node 18)

This is now waiting on a maintainer policy decision about keeping or dropping Node 18 in CI/support before the PR can merge cleanly.

Co-Authored-By: Paperclip <noreply@paperclip.ing>

biggora commented Jun 3, 2026

Copy link
Copy Markdown
Owner

Published a CI-only follow-up at 809f5c1 to keep Node 18 coverage without trying to boot the unsupported Vitest 4 runner there.

  • upstream evidence: vitest@4.1.8 declares engines: ^20.0.0 || ^22.0.0 || >=24.0.0
  • reproduced locally on Node 18.20.8: Vitest startup fails on node:util.styleText, matching the GitHub runner failure
  • workflow change: keep Node 18 in the matrix for npm ci, lint, typecheck, build, and runtime smoke; run npm run test:vitest only on Node 20/22/24
  • new Node 18 smoke step imports both dist/index.mjs and dist/index.cjs

Fresh verification before push:

  • npm ci -> found 0 vulnerabilities
  • npm run lint -> exit 0
  • npm run typecheck -> exit 0
  • npm run test:vitest -> 13 files / 187 tests passed
  • npx -y -p node@18 -p npm@10.8.2 npm run build -> exit 0
  • npx -y node@18 --input-type=module -e "await import('./dist/index.mjs'); console.log('esm-ok')" -> esm-ok
  • npx -y node@18 -e "require('./dist/index.cjs'); console.log('cjs-ok')" -> cjs-ok

Fresh GitHub CI run is now in progress on this commit: https://github.com/biggora/express-useragent/actions/runs/26869900929

@nahremenkova1
nahremenkova1 marked this pull request as ready for review June 3, 2026 07:22
@biggora
biggora merged commit dc0eeeb into master Jun 3, 2026
7 checks passed
@nahremenkova1
nahremenkova1 deleted the codex/ope-592-vitest-lockfile branch June 5, 2026 11:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants