Skip to content

feat(migrate): upgrade pack config for tsdown 0.23 - #2614

Merged
fengmk2 merged 7 commits into
mainfrom
feat/migrate-tsdown-023
Sep 7, 2026
Merged

feat(migrate): upgrade pack config for tsdown 0.23#2614
fengmk2 merged 7 commits into
mainfrom
feat/migrate-tsdown-023

Conversation

@fengmk2

@fengmk2 fengmk2 commented Sep 5, 2026

Copy link
Copy Markdown
Member

vp migrate upgrades legacy pack options for tsdown@0.23.0. This includes existing Vite+ projects without --full.

The command renames removed options, updates declaration generators, and replaces --public-dir with --copy. It also moves noExternal to deps.alwaysBundle and preserves matcher expressions and references. It handles concise arrow callbacks and options written as methods. It preserves explicit values and makes the previous defaults for dependency resolution and ATTW checks explicit.

The migration preserves external matching with both forms of skipNodeModulesBundle. Unsupported combinations keep their pack options and show a manual migration warning.

Ecosystem CI now uses migration for the pinned vinext pack config. The core build removes obsolete ansis logger patches.

Tests cover standalone and JSON configs, workspace packages, and repeated migration. Build tests check external imports, separate output files, custom extensions, copied assets, and declarations.

@netlify

netlify Bot commented Sep 5, 2026

Copy link
Copy Markdown

Deploy Preview for viteplus-preview ready!

Name Link
🔨 Latest commit 8443d31
🔍 Latest deploy log https://app.netlify.com/projects/viteplus-preview/deploys/6a9e255e8dd0a2000874c0ee
😎 Deploy Preview https://deploy-preview-2614--viteplus-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 5, 2026

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://feat-migrate-tsdown-023-viteplus-dev.voidzero-docs.workers.dev (commit 8443d31)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://2eed67c8-viteplus-dev.voidzero-docs.workers.dev 8443d31 2026-09-07T02:47:25.140Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://a19bd01a-viteplus-dev.voidzero-docs.workers.dev 8d1aa84 2026-09-07T02:17:27.178Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://d202d7bb-viteplus-dev.voidzero-docs.workers.dev 2d07b6c 2026-09-06T15:34:05.162Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://d18f174b-viteplus-dev.voidzero-docs.workers.dev db2b2f6 2026-09-06T15:25:59.712Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://9f4fd422-viteplus-dev.voidzero-docs.workers.dev 41112b9 2026-09-06T14:58:30.635Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://45582498-viteplus-dev.voidzero-docs.workers.dev b7ce5fc 2026-09-06T14:38:52.735Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://5f9a35db-viteplus-dev.voidzero-docs.workers.dev 3cc7b06 2026-09-06T14:15:00.041Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://df7221fe-viteplus-dev.voidzero-docs.workers.dev 837ad72 2026-09-06T14:08:20.062Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://bb57390b-viteplus-dev.voidzero-docs.workers.dev c0a6466 2026-09-06T03:29:01.617Z Visit the dashboard ↗
  • Build: Failed ❌

View logs ↗
7541748 2026-09-06T02:29:08.462Z View logs ↗

View all previews: View all previews ↗

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

✅ Staging deployment successful!

Preview: https://viteplus-staging.void.app/
Commit: 8443d31

@socket-security

socket-security Bot commented Sep 5, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​vite-plus@​0.2.08010010099100

View full report

@socket-security

socket-security Bot commented Sep 5, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: npm @vitest/browser: Browser Mode provider commands bypass the file-access permission gate

CVE: GHSA-p63j-vcc4-9vmv @vitest/browser: Browser Mode provider commands bypass the file-access permission gate (CRITICAL)

Affected versions: >= 4.0.0 < 4.1.10; < 3.2.7; >= 5.0.0-beta.1 < 5.0.0-beta.6

Patched version: 4.1.10

From: crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/migration_pack_tsdown_023/package.jsonnpm/vite-plus@0.2.0npm/@vitest/browser@4.1.9

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vitest/browser@4.1.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

CLI artifact sizes (8443d31)

Final release artifacts built by the canonical build-upstream and build-windows-cli actions.
The dist rows use the Linux build. The core total excludes .node files to match the release artifact.

Artifact Format Base PR Change
packages/cli/dist Directory total 2.13 MiB 2.13 MiB +119 B (+0.01%)
packages/core/dist Directory total 3.92 MiB 3.92 MiB 0 B (0.00%)
Combined package dist Directory total 6.05 MiB 6.05 MiB +119 B (+0.00%)
vp (Linux x64) Binary 10.99 MiB 10.99 MiB 0 B (0.00%)
vp (Linux x64) gzip -9 4.76 MiB 4.76 MiB 0 B (0.00%)
NAPI (Linux x64) Binary 31.88 MiB 31.93 MiB +56.00 KiB (+0.17%)
NAPI (Linux x64) gzip -9 12.58 MiB 12.61 MiB +24.46 KiB (+0.19%)
vp (macOS ARM64) Binary 8.19 MiB 8.19 MiB 0 B (0.00%)
vp (macOS ARM64) gzip -9 4.15 MiB 4.15 MiB 0 B (0.00%)
NAPI (macOS ARM64) Binary 39.50 MiB 39.55 MiB +48.42 KiB (+0.12%)
NAPI (macOS ARM64) gzip -9 16.91 MiB 16.93 MiB +20.74 KiB (+0.12%)
vp (Windows x64) Binary 8.86 MiB 8.86 MiB 0 B (0.00%)
vp (Windows x64) gzip -9 3.88 MiB 3.88 MiB 0 B (0.00%)
NAPI (Windows x64) Binary 26.76 MiB 26.81 MiB +49.00 KiB (+0.18%)
NAPI (Windows x64) gzip -9 10.68 MiB 10.70 MiB +21.54 KiB (+0.20%)
Trampoline (Windows x64) Binary 14.00 KiB 14.00 KiB 0 B (0.00%)
Trampoline (Windows x64) gzip -9 7.09 KiB 7.09 KiB 0 B (0.00%)
Installer (Windows x64) Binary 4.50 MiB 4.50 MiB 0 B (0.00%)
Installer (Windows x64) gzip -9 2.11 MiB 2.11 MiB 0 B (0.00%)

Base automatically changed from deps/upstream-update to main September 6, 2026 02:26
@fengmk2
fengmk2 force-pushed the feat/migrate-tsdown-023 branch 2 times, most recently from c0a6466 to 837ad72 Compare September 6, 2026 14:06
@fengmk2 fengmk2 self-assigned this Sep 6, 2026
@fengmk2 fengmk2 added test: e2e Auto run e2e tests test: install-e2e run vite install e2e test test: create-e2e Run `vp create` e2e tests test: sfw labels Sep 6, 2026
@fengmk2
fengmk2 marked this pull request as ready for review September 7, 2026 02:14
@fengmk2
fengmk2 force-pushed the feat/migrate-tsdown-023 branch from 2d07b6c to 8d1aa84 Compare September 7, 2026 02:15
@fengmk2
fengmk2 requested a review from cpojer September 7, 2026 02:16
@fengmk2

fengmk2 commented Sep 7, 2026

Copy link
Copy Markdown
Member Author

cc @sxzz

@fengmk2
fengmk2 force-pushed the feat/migrate-tsdown-023 branch from 8d1aa84 to 8443d31 Compare September 7, 2026 02:45
@fengmk2
fengmk2 merged commit 3bbae42 into main Sep 7, 2026
112 checks passed
@fengmk2
fengmk2 deleted the feat/migrate-tsdown-023 branch September 7, 2026 03:06

@sxzz sxzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

fengmk2 added a commit that referenced this pull request Sep 8, 2026
`vp env` now manages Node.js and package-manager versions together. This
release also fixes TanStack Start routing and stale Vitest aliases.

### Breaking Changes

#### Package-manager setup

Vite+ replaces Corepack with managed `npm`, `pnpm`, `yarn`, and `bun`
commands. It removes the `corepack` shim and legacy global
package-manager installations
([#2391](#2391)), by
@liangmiQwQ.

Replace Corepack setup commands in shell profiles, CI jobs, and
Dockerfiles:

| Previous setup | Replacement |
| --- | --- |
| `corepack enable` | `vp env setup` |
| `vp install -g pnpm@<version>` | `vp env default pnpm@<version>` |
| `vp install -g yarn@<version>` | `vp env default yarn@<version>` |
| `vp install -g bun@<version>` | `vp env default bun@<version>` |
| `vp install -g corepack` | Use the managed package-manager commands
directly |

Use `vp env pin <manager>@<version>` to set a project version.

#### `vp env` command scope and JSON output

Unscoped `vp env` commands now operate on Node.js and package managers.
Package managers support independent defaults, project pins, session
overrides, and installation commands
([#2398](#2398)), by
@liangmiQwQ.

Add `node` to limit an operation to Node.js, for example, `vp env off
node` or `vp env unpin node`. Bare versions, such as `vp env default
22.19.0`, still select Node.js.

Update scripts that read JSON output:

| Command | New output structure |
| --- | --- |
| `vp env current --json` | `node` and `package_manager` objects |
| `vp env list --json`, `vp env list-remote --json` | `node` and
`package_managers` groups |

See the [environment guide](https://viteplus.dev/guide/env).

#### `vp pack` migration to `tsdown` `0.23`

`vp pack` now uses `tsdown` `0.23`, which removes deprecated options and
changes defaults
([#2614](#2614)), by
@fengmk2.

1. Run `vp migrate` to update supported static configurations and
package scripts, including projects that already use Vite+.
2. Check migration warnings in `vite.config.*`, `tsdown.config.*`, and
`package.json`.
3. Update dynamic configurations manually. Arrays built with `.map()`
require manual changes, even when migration reports no warning.
4. Run `vp pack` to check the result.

| Previous option | Replacement |
| --- | --- |
| `bundle: false` | `unbundle: true` |
| `outExtension` | `outExtensions` |
| `publicDir` / `--public-dir` | `copy` / `--copy` |
| `removeNodeProtocol: true` | `nodeProtocol: 'strip'` |
| `injectStyle` | `css.inject` |
| `inlineOnly` / `deps.onlyAllowBundle` | `deps.onlyBundle` |
| `noExternal` | `deps.alwaysBundle` |
| `skipNodeModulesBundle: true` / `deps.skipNodeModulesBundle: true` |
`deps.neverBundle: true` |
| `dts.tsgo: true` / `dts.oxc: true` | `dts.generator: 'tsgo'` /
`dts.generator: 'oxc'` |

Migration preserves the previous defaults for dependency resolution and
ATTW.

`tsdown` no longer supports Node.js `25`. Use Node.js `^22.18.0`,
`^24.11.0`, or `>=26.0.0`. The programmatic `build()` API now returns `{
bundles, watch }`.

See the [complete migration
guide](https://github.com/rolldown/tsdown/releases/tag/v0.23.0) for
declaration and TypeScript module-resolution changes.

#### CLI argument validation

`vp staged`, `vp config`, `vp hooks`, `vp migrate`, and `vp create` now
reject unsupported options and extra positional arguments
([#2523](#2523)), by
@fengmk2.

Remove unsupported arguments from scripts. For example, replace `vp
config --hooks-only` with `vp config --no-agent`.

### Highlights

- Fix TanStack Start HTTP `404` responses caused by separate Vite
runtime copies
([#2617](#2617)), by
@fengmk2.
- Reduce the Windows `vp-shim.exe` size from `214 KiB` to `14 KiB`
([#2466](#2466)), by
@fengmk2.
- Add `vp check --quiet` to hide lint warning diagnostics while
retaining errors and summary counts
([#2593](#2593)), by
@RSS1102.

### Features

- Add `vp sync-versions --json` so automation can request dependency
alignment plans from manifest snapshots without changing project files
([#2600](#2600)), by
@afonsojramos.
- Make `vp create --git` suggest an initial commit command after Git
initialization
([#2581](#2581)), by
@fengmk2.
- Make `vp migrate` replace frozen `voidzero-dev/setup-vp@v1` workflow
references with the supported version pin
([#2540](#2540)), by
@fengmk2.
- Upgrade `rolldown` from `1.2.5` to `1.2.7`, `tsdown` from `0.22.14` to
`0.23.0`, and Oxc from `0.146.0` to `0.148.0`. Upgrade `oxlint` from
`1.79.0` to `1.81.0` and `oxfmt` from `0.64.0` to `0.66.0`. These
versions can flag code that passed before. Run `vp fmt` after upgrading
if CI runs `vp check`
([#2580](#2580),
[#2613](#2613)), by
@voidzero-guard[bot].

### Fixes & Enhancements

- Resolve package-manager versions without rewriting `package.json`. Use
`vp env pin` or `vp env unpin` to change project declarations explicitly
([#2399](#2399)), by
@liangmiQwQ.
- Let `vp migrate` repair stale `vitest` aliases that previously
prevented the CLI from starting
([#2605](#2605)), by
@fengmk2.
- Keep Vite DevTools within the version ranges supported by the bundled
Vite ([#2559](#2559)), by
@fengmk2.
- Keep automatic Vitest upgrades on the supported `4.x` major
([#2612](#2612)), by
@fengmk2.
- Remove a deprecated `tsdown` option from the prompts package build
([#2597](#2597)), by
@jong-kyung.

### Refactor

- Use the updated `which` dependency to resolve relative `PATH` entries
([#2583](#2583)), by
@RSS1102.
- Remove the unused `async-trait` annotation from `JsRuntimeProvider`
([#2538](#2538)), by
@jong-kyung.

### Docs

- Add Azure Pipelines setup instructions
([#2553](#2553)), by
@naokihaba.
- Correct Zed Oxc formatter settings and include JSX and TSX
([#2592](#2592)), by
@joschuba.
- Add Wrangler deployment configuration for the documentation site
([#2596](#2596)), by
@mdong1909.
- Explain conflicts between pnpm and Vite+ runtime management, including
the `runtimeOnFail` setting
([#2620](#2620)), by
@liangmiQwQ.

### Chore

- Run CLI snapshots without published release packages
([#2625](#2625)), by
@fengmk2.
- Update the release-manager skill with package-install checks,
changelog guidance, and announcement handling
([#2548](#2548)), by
@fengmk2.
- Wait for npm dependencies to become available before publishing
dependent release packages
([#2601](#2601)), by
@fengmk2.
- Remove old Docker preview images
([#2539](#2539)), by
@fengmk2.
- Stabilize external-tool snapshots and isolate npm network cases
([#2577](#2577),
[#2604](#2604)), by
@fengmk2.
- Avoid unreliable Fish PPA setup in CI
([#2560](#2560)), by
@fengmk2.
- Update the `vinext` fixture to an upstream fix
([#2571](#2571)), by
@jong-kyung.
- Stabilize the pnpm snapshot and Nuxt build in CI
([#2591](#2591)), by
@voidzero-guard[bot].
- Pin pnpm in project-creation build-approval fixtures
([#2616](#2616)), by
@liangmiQwQ.
- Remove unused documentation components, assets, and the typewriter
dependency
([#2550](#2550),
[#2562](#2562)), by
@jong-kyung.
- Remove duplicate `tempfile` dependencies, an unused runtime helper,
and unused error variants. Update the `unit_bindings` lint name
([#2555](#2555),
[#2558](#2558),
[#2566](#2566),
[#2567](#2567)), by
@jong-kyung.
- Update GitHub Actions dependencies, including `actions/setup-node`
`v7` ([#2544](#2544),
[#2545](#2545),
[#2582](#2582),
[#2618](#2618)), by
@renovate[bot].
- Update `crate-ci/typos` through `v1.50.1`
([#2584](#2584),
[#2589](#2589),
[#2609](#2609)), by
@renovate[bot].
- Update repository pnpm to `11.24.0`
([#2590](#2590)), by
@renovate[bot].
- Update `voidzero-dev/setup-vp` to `v1.19.0`
([#2619](#2619)), by
@renovate[bot].

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| `vite` | `8.2.2` |
[`de1111a`](vitejs/vite@de1111a)
|
| `rolldown` | `1.2.7` |
[`26b4c6e`](rolldown/rolldown@26b4c6e)
|
| `tsdown` | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0)
|
| `vitest` | `4.1.11` | [npm](https://npmx.dev/package/vitest/v/4.1.11)
|
| `oxlint` | `1.81.0` | [npm](https://npmx.dev/package/oxlint/v/1.81.0)
|
| `oxlint-tsgolint` | `7.0.2001` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) |
| `oxfmt` | `0.66.0` | [npm](https://npmx.dev/package/oxfmt/v/0.66.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@afonsojramos, @joschuba

**Full Changelog**:
v0.3.0...v0.3.1

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test: create-e2e Run `vp create` e2e tests test: e2e Auto run e2e tests test: install-e2e run vite install e2e test test: sfw

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants