chore(deps): update github actions#1611
Merged
Merged
Conversation
✅ Deploy Preview for viteplus-preview canceled.
|
cd986ae to
0c0e128
Compare
fengmk2
approved these changes
May 18, 2026
fengmk2
added a commit
that referenced
this pull request
May 19, 2026
Release vite-plus v0.1.22: Security Patch, Parallel Global Install & Scaffold Polish A critical Vitest browser-mode security fix, parallel `vp add -g` installs, a built-in oxlint rule to prefer `vite-plus` imports, and a new `--git` switch for `vp create`. ### Highlights - **Security**: bundled `vitest` bumped to `4.1.6` to address [GHSA-2h32-95rg-cppp](GHSA-2h32-95rg-cppp) (Critical, CVSS 9.6), an XSS to RCE chain via the `otelCarrier` query parameter in Vitest browser mode ([#1633](#1633)) - **Parallel global install**: `vp add/install/update -g` now installs packages concurrently with a progress bar and a `--concurrency` flag (default 5) ([#1597](#1597)) - **Prefer vite-plus imports**: new bundled oxlint rule rewrites `vite`/`vitest` imports to `vite-plus`, enabled by default in generated and migrated `lint` configs ([#1408](#1408)) - **Git init on scaffold**: `vp create` learns `--git`/`--no-git` (interactive prompt; auto-commits "Initial commit from Vite+") ([#1484](#1484)) ### Features - Spawn npm for global installation in parallel with a progress bar and a `--concurrency` option ([#1597](#1597)), by @liangmiQwQ - Add bundled oxlint rule to prefer `vite-plus` imports over `vite`/`vitest` ([#1408](#1408)), by @Han5991 - `vp create`: initialize a git repository and create an initial commit on scaffold ([#1484](#1484)), by @ryohidaka - `vp create`: rename underscore-prefixed files (`_gitignore`, `_npmrc`, `_yarnrc.yml`) to dotfiles for `@org/create` bundled templates ([#1574](#1574)), by @jong-kyung - Add `VP_PR_VERSION` env var to install unreleased PR builds via pkg.pr.new ([#1578](#1578)), by @fengmk2 ### Fixes & Enhancements - Skip merging standalone `.oxfmtrc`/`.oxlintrc` config when the `fmt:`/`lint:` key is already declared in `vite.config.ts` (fixes duplicate-block regression in `vp create fate`) ([#1601](#1601)), by @fengmk2 - Suppress the `VITE+ - The Unified Toolchain for the Web` banner for `vp lint --lsp`, `vp fmt --lsp`, and `vp fmt --stdin-filepath` so stdout stays a pure LSP / formatter stream ([#1619](#1619)), by @fengmk2 - `vp create`: detect output directory when running in the current directory ([#1606](#1606)), by @jong-kyung - `vp update -g`: skip installs when the recorded global package version already matches the npm-resolved version, and tolerate string/array outputs from `npm view ... version --json` ([#1596](#1596)), by @leno23 - `vp create`: preserve single-segment project path in `updateWorkspaceConfig` ([#1582](#1582)), by @jong-kyung - `vp env use`: keep the change session-scoped on Windows ([#1577](#1577)), by @fengmk2 - `vp rebuild`: accept positional package names ([#1564](#1564)), by @fengmk2 - Adopt the new vite-task error formatter; errors now print as `error: <top-level>` plus `* <source>` chain lines, with bold-red highlight on a TTY ([vite-task#390](voidzero-dev/vite-task#390)), by @branchseer - vite-task: forward `LOCALAPPDATA` so Node's compile cache stays outside the workspace on Windows ([vite-task#389](voidzero-dev/vite-task#389)), by @branchseer - Bump vite-task to `c945cc0` ([#1628](#1628)), by @branchseer ### Refactor - Revert `vp pm plugin` command (per discussion in #1038) ([#1623](#1623)), by @jong-kyung ### Docs - Add `vitepress-plugin-llms` to the docs site so the published docs include LLM-friendly outputs (`/llms.txt`) ([#1625](#1625)), by @jong-kyung - Refresh home stats for oxlint, vite, and vitest ([#1512](#1512)), by @nozomee - Mention `vp env doctor` in agent instructions ([#1603](#1603)), by @leno23 ### Chore - Consolidate the upstream build chain into a single `pnpm build` script (justfile recipe now just calls `pnpm build`) ([#1626](#1626)), by @fengmk2 - Fix bootstrap-cli on Windows ([#1583](#1583)), by @fengmk2 - Refresh trusted stack stats ([#1573](#1573), [#1616](#1616)), by @voidzero-guard[bot] - Update GitHub Actions ([#1611](#1611), [#1612](#1612)), by @renovate[bot] - Address zizmor findings in composite actions and the release workflow; drop unused `actions-cool/issues-helper` ([#1630](#1630)), by @Boshen - Switch plain checkouts to `taiki-e/checkout-action` ([#1620](#1620)), by @Boshen - Switch release to a version-bump PR + push trigger flow ([#1575](#1575)), by @Boshen - Gate release publish on environment approval with a Discord notice ([#1571](#1571)), by @Boshen - Enable `cargo clippy` with `-D warnings` ([#1579](#1579)), by @Boshen - Drop unused `setup-node` from the version-check job ([#1600](#1600)), by @fengmk2 - Add Void deploy workflows for the docs site ([#1590](#1590)), by @fengmk2 - Add `--help` case to config snap tests for npm10/yarn1/yarn4 ([#1585](#1585)), by @jong-kyung - Add `--help` case to publish snap tests for npm10/yarn1/yarn4 ([#1584](#1584)), by @jong-kyung - Verify `.gitignore` and `.yarnrc.yml` in the new-vite-monorepo snap ([#1576](#1576)), by @jong-kyung - vite-task: bump pnpm to `11.1.2` ([vite-task#383](voidzero-dev/vite-task#383)), by @branchseer - vite-task: update lint-staged to v17 ([vite-task#385](voidzero-dev/vite-task#385)), by @renovate[bot] ### Bundled Versions | Tool | Version | Source | | --- | --- | --- | | vite | `8.0.11` | [`66f3194`](vitejs/vite@66f3194) | | rolldown | `1.0.0` | [`ac5c710`](rolldown/rolldown@ac5c710) | | tsdown | `0.22.0` | [npm](https://npmx.dev/package/tsdown/v/0.22.0) | | vitest | `4.1.6` | [npm](https://npmx.dev/package/vitest/v/4.1.6) | | oxlint | `1.63.0` | [npm](https://npmx.dev/package/oxlint/v/1.63.0) | | oxlint-tsgolint | `0.22.1` | [npm](https://npmx.dev/package/oxlint-tsgolint/v/0.22.1) | | oxfmt | `0.48.0` | [npm](https://npmx.dev/package/oxfmt/v/0.48.0) | ### New Contributors Welcome to all new contributors! 🎉 @nozomee, @ryohidaka, @leno23 **Full Changelog**: v0.1.21...v0.1.22 --- Merging this PR will trigger the release workflow. --------- Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com> Co-authored-by: MK <fengmk2@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v3.1.1→v3.2.0v6.3.0→v6.4.0v1.0.108→v1.0.123v4.35.2→v4.35.4v4.35.5v4.2.0→v4.4.0v2.75.24→v2.78.0v2.79.0(+3)Release Notes
actions/create-github-app-token (actions/create-github-app-token)
v3.2.0Compare Source
Features
repositoriesinput (#372) (85eb8dd)Bug Fixes
actions/setup-node (actions/setup-node)
v6.4.0Compare Source
anthropics/claude-code-action (anthropics/claude-code-action)
v1.0.123Compare Source
What's Changed
New Contributors
Full Changelog: anthropics/claude-code-action@v1...v1.0.123
v1.0.122Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.122
v1.0.121Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.121
v1.0.120Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.120
v1.0.119Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.119
v1.0.118Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.118
v1.0.117Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.117
v1.0.116Compare Source
What's Changed
Full Changelog: anthropics/claude-code-action@v1...v1.0.116
v1.0.115Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.115
v1.0.114Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.114
v1.0.113Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.113
v1.0.112Compare Source
What's Changed
New Contributors
Full Changelog: anthropics/claude-code-action@v1...v1.0.112
v1.0.111Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.111
v1.0.110Compare Source
Full Changelog: anthropics/claude-code-action@v1...v1.0.110
v1.0.109Compare Source
What's Changed
Full Changelog: anthropics/claude-code-action@v1...v1.0.109
github/codeql-action (github/codeql-action)
v4.35.4Compare Source
v4.35.3Compare Source
GETrequests instead ofHEADfor better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #3853pnpm/action-setup (pnpm/action-setup)
v4.4.0Compare Source
Updated the action to use Node.js 24.
v4.3.0Compare Source
What's Changed
@types/node-fetchdependency by @silverwind in #186New Contributors
Full Changelog: pnpm/action-setup@v4.2.0...v4.3.0
taiki-e/install-action (taiki-e/install-action)
v2.78.0: 2.78.0Compare Source
Support
cargo-mutants. (#1812, thanks @jakewimmer)Update
covgate@latestto 0.2.0.Update
cargo-llvm-cov@latestto 0.8.7.Update
uv@latestto 0.11.14.Update
martin@latestto 1.9.1.Update
tombi@latestto 0.11.4.v2.77.7: 2.77.7Compare Source
Update
mise@latestto 2026.5.6.Update
cargo-deny@latestto 0.19.6.v2.77.6: 2.77.6Compare Source
Fix
wasm-packinstallation failure.Update
mise@latestto 2026.5.5.Update
release-plz@latestto 0.3.158.Update
just@latestto 1.51.0.v2.77.5: 2.77.5Compare Source
Update
biome@latestto 2.4.15.Update
mise@latestto 2026.5.4.Update
cargo-deny@latestto 0.19.5.v2.77.4: 2.77.4Compare Source
Update
tombi@latestto 0.11.1.Update
cargo-llvm-cov@latestto 0.8.6.Update
uv@latestto 0.11.12.v2.77.3: 2.77.3Compare Source
Update
typos@latestto 1.46.1.Update
rclone@latestto 1.74.1.Update
tombi@latestto 0.11.0.Update
osv-scanner@latestto 2.3.8.Update
mise@latestto 2026.5.3.v2.77.2: 2.77.2Compare Source
Update
martin@latestto 1.9.0.Update
wasm-bindgen@latestto 0.2.121.Update
uv@latestto 0.11.11.Update
mise@latestto 2026.5.1.Update
prek@latestto 0.3.13.Update
tombi@latestto 0.10.6.v2.77.1: 2.77.1Compare Source
Support
taiki-e/install-action@rusttag.Update
tombi@latestto 0.10.3.Update
martin@latestto 1.8.2.v2.77.0: 2.77.0Compare Source
Support
rust. (#1779)This installs rust using rustup.
If rustup is not yet installed, this action downloads rustup-init for the current platform using HTTPS with tlsv1.2+, verifies SHA256 checksum, and then installs rustup using it.
This also supports installing additional components at the same time by
+<additional>syntax:Fix issue where x86_64 binary will be installed on AArch64 Windows even when AArch64 Windows binary available.
Update
mise@latestto 2026.5.0.Diagnostic improvements.
v2.76.0: 2.76.0Compare Source
Support
mdbook-d2. (#1737, thanks @nhu)Support
cargo-apple-runner. (#1731, thanks @madsmtm)Support
cargo-binstallon riscv64 Linux.Update
cargo-deb@latestto 3.7.0.Update
tombi@latestto 0.10.2.v2.75.30: 2.75.30Compare Source
Support
cargo-spellcheckon AArch64 Linux/Windows.Update
cargo-spellcheck@latestto 0.15.7.Update
biome@latestto 2.4.14.v2.75.29: 2.75.29Compare Source
Update
syft@latestto 1.44.0.Update
rclone@latestto 1.74.0.Update
osv-scanner@latestto 2.3.6.v2.75.28: 2.75.28Compare Source
Update
wasmtime@latestto 44.0.1.Update
typos@latestto 1.46.0.Update
tombi@latestto 0.10.1.Update
sccache@latestto 0.15.0.Update
mise@latestto 2026.4.28.Update
gungraun-runner@latestto 0.18.2.Update
cyclonedx@latestto 0.31.0.v2.75.27: 2.75.27Compare Source
Update
cargo-udeps@latestto 0.1.61.Update
wasm-tools@latestto 1.248.0.Update
cargo-deb@latestto 3.6.4.v2.75.26: 2.75.26Compare Source
Update
wasm-bindgen@latestto 0.2.120.Update
mise@latestto 2026.4.25.Update
martin@latestto 1.8.0.Update
vacuum@latestto 0.26.4.v2.75.25: 2.75.25Compare Source
Update
uv@latestto 0.11.8.Update
typos@latestto 1.45.2.Update
tombi@latestto 0.9.25.Update
mise@latestto 2026.4.24.Configuration
📅 Schedule: (in timezone Asia/Shanghai)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.