Skip to content

fix(dev-1687): bump vitest to 4.1.11 - #56

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1687
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1687

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

Dependabot opened #55 bumping vitest from 3.2.6 to 4.1.11 (a major version bump) to resolve GHSA-82fw-gwwq-j7x9 (vitest / @vitest/mocker < 4.1.11, medium). The same manifest also carries GHSA-5xrq-8626-4rwp (vitest < 3.2.6, critical) against this pnpm-lock.yaml scope, tracked at DEV-1687.

Because this is a major-version bump, it is not eligible for direct merge-pr under the remediation policy regardless of CI outcome — it must be replayed onto a compliant branch/commit-message and handed to spur-vuln-review for mandatory human sign-off before merge. This PR mechanically replays #55's exact diff (no adaptation code) onto fix/dev-1687.

@vitest/mocker (GHSA-82fw-gwwq-j7x9, tracked at DEV-1697) is vitest's own dependency and is bumped to 4.1.11 in this same pnpm-lock.yaml diff as part of this same change.

Test evidence

CI ran on the original Dependabot PR #55; this PR's diff is byte-identical to #55's (package.json + pnpm-lock.yaml), replayed via git apply with no manual edits. Companion-file scan (companion-scan.sh pnpm-lock.yaml 3.2.6) found no stale companion files (Dockerfiles, .nvmrc, CI workflow pins, etc.) referencing the old version.

Note: pnpm is not available in the remediation runner's sandbox, so the lockfile in this PR is exactly Dependabot's own regenerated content — it was not (and could not be) regenerated locally.

Risk

Medium — major version bump of a devDependency (test runner only, not shipped in any package's runtime output). spur-vuln-review should verify CI passes on this replayed PR before any merge decision; this PR must not be self-merged regardless of outcome (high-scrutiny: major-bump).


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Sep 30, 2026
@spur-vuln-reviewer

Copy link
Copy Markdown

high-scrutiny-major-bump: this PR is flagged high-scrutiny: major-bump in its footer (advisory GHSA-82fw-gwwq-j7x9 / GHSA-5xrq-8626-4rwp, package vitest, pnpm-lock.yaml). Per Gate 1 of the review contract, a major-bump flag is unconditionally escalated regardless of CI state or diff cleanliness — this decision belongs to a human. Not merged. A human must review this. This reviewer will not act on this PR again.
[[spur-vuln-reviewer: escalated high-scrutiny-major-bump]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants