Skip to content

feat(deps): upgrade upstream dependencies - #2613

Merged
fengmk2 merged 6 commits into
mainfrom
deps/upstream-update
Sep 6, 2026
Merged

feat(deps): upgrade upstream dependencies#2613
fengmk2 merged 6 commits into
mainfrom
deps/upstream-update

Conversation

@voidzero-guard

@voidzero-guard voidzero-guard Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Upgrade the upstream dependencies. The largest change is tsdown from 0.22.14 to 0.23.0.

Update vp pack for the new logger and build handle. Remove --public-dir from the command and help snapshots. Align yuku-codegen and yuku-parser with the bundled declaration generator. Regenerate the native binding files.

Convert boolean dts.tsgo and dts.oxc options to dts.generator during migration. This fixes the library template and ecosystem config checks. Update the pinned vinext config to use deps.neverBundle.

Use the bundled tsdown version for tsdown-migrate. Remove TSDOWN_MIGRATE_VERSION and the separate version update logic.

Dependency updates

Package From To
rolldown v1.2.6 (5375362) v1.2.7 (26b4c6e)
tsdown 0.22.14 0.23.0
@tsdown/css 0.22.14 0.23.0
@tsdown/exe 0.22.14 0.23.0
oxfmt 0.65.0 0.66.0
oxlint 1.80.0 1.81.0
@oxc-project/runtime 0.147.0 0.148.0
@oxc-project/types 0.147.0 0.148.0
oxc-minify 0.147.0 0.148.0
oxc-parser 0.147.0 0.148.0
oxc-transform 0.147.0 0.148.0
tsdown-migrate 0.23.0-rc.0 0.23.0, from the bundled tsdown version

Additional dependency updates:

Package From To
Oxc Rust crates (Cargo.toml) 0.147.0 0.148.0
Rolldown Rust crates (Cargo.lock) 1.2.6 1.2.7
remeda (catalog) ^2.42.0 ^2.45.0
rollup (catalog) ^4.60.4 ^4.63.0
unplugin-unused (core peer dependency) ^0.5.0 >=0.5.0
yuku-codegen ^0.5.44 ^0.9.3
yuku-parser ^0.5.44 ^0.9.3
Unchanged dependencies
  • vite: v8.2.2 (de1111a)
  • vitest: 4.1.11
  • @vitest/browser: 4.1.11
  • @vitest/browser-playwright: 4.1.11
  • @vitest/browser-preview: 4.1.11
  • @vitest/browser-webdriverio: 4.1.11
  • @vitest/expect: 4.1.11
  • @vitest/mocker: 4.1.11
  • @vitest/pretty-format: 4.1.11
  • @vitest/runner: 4.1.11
  • @vitest/snapshot: 4.1.11
  • @vitest/spy: 4.1.11
  • @vitest/utils: 4.1.11
  • lightningcss: ^1.33.0
  • @oxc-node/cli: 0.1.0
  • @oxc-node/core: 0.1.0
  • oxlint-tsgolint: 7.0.2001
  • VITEST_VERSION constant: 4.1.11
  • README.md Vitest versions: 4.1.11

@voidzero-guard

voidzero-guard Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Upstream CLI help changes detected

Compared normalized --help output for the upstream CLIs mirrored by Vite+.

➖ Vite: no version update (8.2.2)

No version update was detected, so there is no CLI help diff.

➖ Vitest: no version update (4.1.11)

No version update was detected, so there is no CLI help diff.

✅ Oxlint: no CLI help changes (1.80.0 → 1.81.0)

The version was updated, but the normalized CLI help output has no differences.

✅ Oxfmt: no CLI help changes (0.65.0 → 0.66.0)

The version was updated, but the normalized CLI help output has no differences.

⚠️ tsdown: CLI help changed (0.22.14 → 0.23.0)
--- tsdown@0.22.14
+++ tsdown@0.23.0
@@ -46,7 +46,6 @@ Options:
   --env-prefix <prefix>         Prefix for env variables to inject into the bundle (default: TSDOWN_)
   --on-success <command>        Command to run on success
   --copy <dir>                  Copy files to output dir
-  --public-dir <dir>            Alias for --copy, deprecated
   --tsconfig <tsconfig>         Set tsconfig path
   --unbundle                    Unbundle mode
   --root <dir>                  Root directory of input files

@netlify

netlify Bot commented Sep 5, 2026

Copy link
Copy Markdown

Deploy Preview for viteplus-preview canceled.

Name Link
🔨 Latest commit e984d5f
🔍 Latest deploy log https://app.netlify.com/projects/viteplus-preview/deploys/6a9ccbd7bad9e1000820dbdd

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 5, 2026

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
e984d5f 2026-09-06T02:12:07.420Z View logs ↗
  • Build: Failed ❌

View logs ↗
2d04d86 2026-09-05T17:31:21.578Z View logs ↗
  • Build: Failed ❌

View logs ↗
34ce658 2026-09-05T17:04:09.028Z View logs ↗
  • Build: Failed ❌

View logs ↗
54eaf01 2026-09-05T15:42:49.903Z View logs ↗

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

CLI artifact sizes (e984d5f)

Final release artifacts built by the canonical build-upstream and build-windows-cli actions.
The dist rows use the Linux build. The core total excludes .node files to match the release artifact.

Artifact Format Base PR Change
packages/cli/dist Directory total 2.13 MiB 2.13 MiB +241 B (+0.01%)
packages/core/dist Directory total 3.92 MiB 3.92 MiB +5.47 KiB (+0.14%)
Combined package dist Directory total 6.05 MiB 6.05 MiB +5.71 KiB (+0.09%)
vp (Linux x64) Binary 10.99 MiB 10.99 MiB 0 B (0.00%)
vp (Linux x64) gzip -9 4.76 MiB 4.76 MiB 0 B (0.00%)
NAPI (Linux x64) Binary 31.85 MiB 31.88 MiB +28.00 KiB (+0.09%)
NAPI (Linux x64) gzip -9 12.58 MiB 12.58 MiB +6.00 KiB (+0.05%)
vp (macOS ARM64) Binary 8.19 MiB 8.19 MiB 0 B (0.00%)
vp (macOS ARM64) gzip -9 4.15 MiB 4.15 MiB 0 B (0.00%)
NAPI (macOS ARM64) Binary 39.49 MiB 39.50 MiB +16.17 KiB (+0.04%)
NAPI (macOS ARM64) gzip -9 16.90 MiB 16.91 MiB +7.09 KiB (+0.04%)
vp (Windows x64) Binary 8.86 MiB 8.86 MiB 0 B (0.00%)
vp (Windows x64) gzip -9 3.88 MiB 3.88 MiB +1 B (+0.00%)
NAPI (Windows x64) Binary 26.74 MiB 26.76 MiB +21.50 KiB (+0.08%)
NAPI (Windows x64) gzip -9 10.67 MiB 10.68 MiB +7.94 KiB (+0.07%)
Trampoline (Windows x64) Binary 14.00 KiB 14.00 KiB 0 B (0.00%)
Trampoline (Windows x64) gzip -9 7.09 KiB 7.09 KiB 0 B (0.00%)
Installer (Windows x64) Binary 4.50 MiB 4.50 MiB 0 B (0.00%)
Installer (Windows x64) gzip -9 2.11 MiB 2.11 MiB 0 B (0.00%)

voidzero-guard Bot and others added 6 commits September 6, 2026 10:09
- rolldown: 5375362 -> v1.2.7 (26b4c6e)
- tsdown: 0.22.14 -> 0.23.0
- @tsdown/css: 0.22.14 -> 0.23.0
- @tsdown/exe: 0.22.14 -> 0.23.0
- oxfmt: 0.65.0 -> 0.66.0
- oxlint: 1.80.0 -> 1.81.0
- @oxc-project/runtime: 0.147.0 -> 0.148.0
- @oxc-project/types: 0.147.0 -> 0.148.0
- oxc-minify: 0.147.0 -> 0.148.0
- oxc-parser: 0.147.0 -> 0.148.0
- oxc-transform: 0.147.0 -> 0.148.0
- tsdown-migrate: 0.23.0-rc.0 -> 0.23.0
- oxc Rust crates: 0.147.0 -> 0.148.0 (Cargo.toml)
- rolldown Rust crates: 1.2.6 -> 1.2.7 (Cargo.lock)
- catalog: remeda ^2.42.0 -> ^2.45.0, rollup ^4.60.4 -> ^4.63.0

Code changes:
- packages/cli/src/pack-bin.ts: drop the `--public-dir` option; tsdown 0.23.0
  removed the deprecated `--copy` alias from its CLI, so it is no longer
  forwarded.
- packages/cli/src/help.ts: remove the matching `--public-dir` entry from
  `vp pack` static help.
- packages/core/build.ts: extend the tsdown logger branding patches to handle
  the `node:util` `styleText` proxy that tsdown 0.23 uses in place of ansis;
  patches now declare which ansis identifiers they need and `ensureAnsisImports`
  only runs when an ansis-based patch applied.
- packages/cli/src/utils/constants.ts: `TSDOWN_MIGRATE_VERSION` moves from the
  `0.23.0-rc.0` prerelease to stable `0.23.0`.
- packages/core/package.json: bundled versions bumped (rolldown 1.2.7,
  tsdown 0.23.0) and the `unplugin-unused` peer range widened `^0.5.0` ->
  `>=0.5.0`.
- packages/tools/.upstream-versions.json: repin the rolldown source hash.
@fengmk2
fengmk2 force-pushed the deps/upstream-update branch from 2d04d86 to e984d5f Compare September 6, 2026 02:11
@fengmk2
fengmk2 merged commit 809d8b8 into main Sep 6, 2026
108 of 109 checks passed
@fengmk2
fengmk2 deleted the deps/upstream-update branch September 6, 2026 02:26
fengmk2 added a commit that referenced this pull request Sep 8, 2026
`vp env` now manages Node.js and package-manager versions together. This
release also fixes TanStack Start routing and stale Vitest aliases.

### Breaking Changes

#### Package-manager setup

Vite+ replaces Corepack with managed `npm`, `pnpm`, `yarn`, and `bun`
commands. It removes the `corepack` shim and legacy global
package-manager installations
([#2391](#2391)), by
@liangmiQwQ.

Replace Corepack setup commands in shell profiles, CI jobs, and
Dockerfiles:

| Previous setup | Replacement |
| --- | --- |
| `corepack enable` | `vp env setup` |
| `vp install -g pnpm@<version>` | `vp env default pnpm@<version>` |
| `vp install -g yarn@<version>` | `vp env default yarn@<version>` |
| `vp install -g bun@<version>` | `vp env default bun@<version>` |
| `vp install -g corepack` | Use the managed package-manager commands
directly |

Use `vp env pin <manager>@<version>` to set a project version.

#### `vp env` command scope and JSON output

Unscoped `vp env` commands now operate on Node.js and package managers.
Package managers support independent defaults, project pins, session
overrides, and installation commands
([#2398](#2398)), by
@liangmiQwQ.

Add `node` to limit an operation to Node.js, for example, `vp env off
node` or `vp env unpin node`. Bare versions, such as `vp env default
22.19.0`, still select Node.js.

Update scripts that read JSON output:

| Command | New output structure |
| --- | --- |
| `vp env current --json` | `node` and `package_manager` objects |
| `vp env list --json`, `vp env list-remote --json` | `node` and
`package_managers` groups |

See the [environment guide](https://viteplus.dev/guide/env).

#### `vp pack` migration to `tsdown` `0.23`

`vp pack` now uses `tsdown` `0.23`, which removes deprecated options and
changes defaults
([#2614](#2614)), by
@fengmk2.

1. Run `vp migrate` to update supported static configurations and
package scripts, including projects that already use Vite+.
2. Check migration warnings in `vite.config.*`, `tsdown.config.*`, and
`package.json`.
3. Update dynamic configurations manually. Arrays built with `.map()`
require manual changes, even when migration reports no warning.
4. Run `vp pack` to check the result.

| Previous option | Replacement |
| --- | --- |
| `bundle: false` | `unbundle: true` |
| `outExtension` | `outExtensions` |
| `publicDir` / `--public-dir` | `copy` / `--copy` |
| `removeNodeProtocol: true` | `nodeProtocol: 'strip'` |
| `injectStyle` | `css.inject` |
| `inlineOnly` / `deps.onlyAllowBundle` | `deps.onlyBundle` |
| `noExternal` | `deps.alwaysBundle` |
| `skipNodeModulesBundle: true` / `deps.skipNodeModulesBundle: true` |
`deps.neverBundle: true` |
| `dts.tsgo: true` / `dts.oxc: true` | `dts.generator: 'tsgo'` /
`dts.generator: 'oxc'` |

Migration preserves the previous defaults for dependency resolution and
ATTW.

`tsdown` no longer supports Node.js `25`. Use Node.js `^22.18.0`,
`^24.11.0`, or `>=26.0.0`. The programmatic `build()` API now returns `{
bundles, watch }`.

See the [complete migration
guide](https://github.com/rolldown/tsdown/releases/tag/v0.23.0) for
declaration and TypeScript module-resolution changes.

#### CLI argument validation

`vp staged`, `vp config`, `vp hooks`, `vp migrate`, and `vp create` now
reject unsupported options and extra positional arguments
([#2523](#2523)), by
@fengmk2.

Remove unsupported arguments from scripts. For example, replace `vp
config --hooks-only` with `vp config --no-agent`.

### Highlights

- Fix TanStack Start HTTP `404` responses caused by separate Vite
runtime copies
([#2617](#2617)), by
@fengmk2.
- Reduce the Windows `vp-shim.exe` size from `214 KiB` to `14 KiB`
([#2466](#2466)), by
@fengmk2.
- Add `vp check --quiet` to hide lint warning diagnostics while
retaining errors and summary counts
([#2593](#2593)), by
@RSS1102.

### Features

- Add `vp sync-versions --json` so automation can request dependency
alignment plans from manifest snapshots without changing project files
([#2600](#2600)), by
@afonsojramos.
- Make `vp create --git` suggest an initial commit command after Git
initialization
([#2581](#2581)), by
@fengmk2.
- Make `vp migrate` replace frozen `voidzero-dev/setup-vp@v1` workflow
references with the supported version pin
([#2540](#2540)), by
@fengmk2.
- Upgrade `rolldown` from `1.2.5` to `1.2.7`, `tsdown` from `0.22.14` to
`0.23.0`, and Oxc from `0.146.0` to `0.148.0`. Upgrade `oxlint` from
`1.79.0` to `1.81.0` and `oxfmt` from `0.64.0` to `0.66.0`. These
versions can flag code that passed before. Run `vp fmt` after upgrading
if CI runs `vp check`
([#2580](#2580),
[#2613](#2613)), by
@voidzero-guard[bot].

### Fixes & Enhancements

- Resolve package-manager versions without rewriting `package.json`. Use
`vp env pin` or `vp env unpin` to change project declarations explicitly
([#2399](#2399)), by
@liangmiQwQ.
- Let `vp migrate` repair stale `vitest` aliases that previously
prevented the CLI from starting
([#2605](#2605)), by
@fengmk2.
- Keep Vite DevTools within the version ranges supported by the bundled
Vite ([#2559](#2559)), by
@fengmk2.
- Keep automatic Vitest upgrades on the supported `4.x` major
([#2612](#2612)), by
@fengmk2.
- Remove a deprecated `tsdown` option from the prompts package build
([#2597](#2597)), by
@jong-kyung.

### Refactor

- Use the updated `which` dependency to resolve relative `PATH` entries
([#2583](#2583)), by
@RSS1102.
- Remove the unused `async-trait` annotation from `JsRuntimeProvider`
([#2538](#2538)), by
@jong-kyung.

### Docs

- Add Azure Pipelines setup instructions
([#2553](#2553)), by
@naokihaba.
- Correct Zed Oxc formatter settings and include JSX and TSX
([#2592](#2592)), by
@joschuba.
- Add Wrangler deployment configuration for the documentation site
([#2596](#2596)), by
@mdong1909.
- Explain conflicts between pnpm and Vite+ runtime management, including
the `runtimeOnFail` setting
([#2620](#2620)), by
@liangmiQwQ.

### Chore

- Run CLI snapshots without published release packages
([#2625](#2625)), by
@fengmk2.
- Update the release-manager skill with package-install checks,
changelog guidance, and announcement handling
([#2548](#2548)), by
@fengmk2.
- Wait for npm dependencies to become available before publishing
dependent release packages
([#2601](#2601)), by
@fengmk2.
- Remove old Docker preview images
([#2539](#2539)), by
@fengmk2.
- Stabilize external-tool snapshots and isolate npm network cases
([#2577](#2577),
[#2604](#2604)), by
@fengmk2.
- Avoid unreliable Fish PPA setup in CI
([#2560](#2560)), by
@fengmk2.
- Update the `vinext` fixture to an upstream fix
([#2571](#2571)), by
@jong-kyung.
- Stabilize the pnpm snapshot and Nuxt build in CI
([#2591](#2591)), by
@voidzero-guard[bot].
- Pin pnpm in project-creation build-approval fixtures
([#2616](#2616)), by
@liangmiQwQ.
- Remove unused documentation components, assets, and the typewriter
dependency
([#2550](#2550),
[#2562](#2562)), by
@jong-kyung.
- Remove duplicate `tempfile` dependencies, an unused runtime helper,
and unused error variants. Update the `unit_bindings` lint name
([#2555](#2555),
[#2558](#2558),
[#2566](#2566),
[#2567](#2567)), by
@jong-kyung.
- Update GitHub Actions dependencies, including `actions/setup-node`
`v7` ([#2544](#2544),
[#2545](#2545),
[#2582](#2582),
[#2618](#2618)), by
@renovate[bot].
- Update `crate-ci/typos` through `v1.50.1`
([#2584](#2584),
[#2589](#2589),
[#2609](#2609)), by
@renovate[bot].
- Update repository pnpm to `11.24.0`
([#2590](#2590)), by
@renovate[bot].
- Update `voidzero-dev/setup-vp` to `v1.19.0`
([#2619](#2619)), by
@renovate[bot].

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| `vite` | `8.2.2` |
[`de1111a`](vitejs/vite@de1111a)
|
| `rolldown` | `1.2.7` |
[`26b4c6e`](rolldown/rolldown@26b4c6e)
|
| `tsdown` | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0)
|
| `vitest` | `4.1.11` | [npm](https://npmx.dev/package/vitest/v/4.1.11)
|
| `oxlint` | `1.81.0` | [npm](https://npmx.dev/package/oxlint/v/1.81.0)
|
| `oxlint-tsgolint` | `7.0.2001` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) |
| `oxfmt` | `0.66.0` | [npm](https://npmx.dev/package/oxfmt/v/0.66.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@afonsojramos, @joschuba

**Full Changelog**:
v0.3.0...v0.3.1

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant