Skip to content

chore(deps): update dependency vite-plus to v0.1.22 - autoclosed#782

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/vite-plus-0.x-lockfile
Closed

chore(deps): update dependency vite-plus to v0.1.22 - autoclosed#782
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/vite-plus-0.x-lockfile

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 20, 2026

This PR contains the following updates:

Package Change Age Confidence
vite-plus (source) 0.1.210.1.22 age confidence

Release Notes

voidzero-dev/vite-plus (vite-plus)

v0.1.22: vite-plus v0.1.22

Compare Source

A critical Vitest browser-mode security fix, parallel vp add -g installs, a built-in oxlint rule to prefer vite-plus imports, and a new --git switch for vp create.

Highlights
  • Security: bundled vitest bumped to 4.1.6 to address GHSA-2h32-95rg-cppp (Critical, CVSS 9.6), an XSS to RCE chain via the otelCarrier query parameter in Vitest browser mode (#​1633)
  • Parallel global install: vp add/install/update -g now installs packages concurrently with a progress bar and a --concurrency flag (default 5) (#​1597)
  • Prefer vite-plus imports: new bundled oxlint rule rewrites vite/vitest imports to vite-plus, enabled by default in generated and migrated lint configs (#​1408)
  • Git init on scaffold: vp create learns --git/--no-git (interactive prompt; auto-commits "Initial commit from Vite+") (#​1484)
Features
  • Spawn npm for global installation in parallel with a progress bar and a --concurrency option (#​1597), by @​liangmiQwQ
  • Add bundled oxlint rule to prefer vite-plus imports over vite/vitest (#​1408), by @​Han5991
  • vp create: initialize a git repository and create an initial commit on scaffold (#​1484), by @​ryohidaka
  • vp create: rename underscore-prefixed files (_gitignore, _npmrc, _yarnrc.yml) to dotfiles for @org/create bundled templates (#​1574), by @​jong-kyung
  • Add VP_PR_VERSION env var to install unreleased PR builds via pkg.pr.new (#​1578), by @​fengmk2
Fixes & Enhancements
  • Skip merging standalone .oxfmtrc/.oxlintrc config when the fmt:/lint: key is already declared in vite.config.ts (fixes duplicate-block regression in vp create fate) (#​1601), by @​fengmk2
  • Suppress the VITE+ - The Unified Toolchain for the Web banner for vp lint --lsp, vp fmt --lsp, and vp fmt --stdin-filepath so stdout stays a pure LSP / formatter stream (#​1619), by @​fengmk2
  • vp create: detect output directory when running in the current directory (#​1606), by @​jong-kyung
  • vp update -g: skip installs when the recorded global package version already matches the npm-resolved version, and tolerate string/array outputs from npm view ... version --json (#​1596), by @​leno23
  • vp create: preserve single-segment project path in updateWorkspaceConfig (#​1582), by @​jong-kyung
  • vp env use: keep the change session-scoped on Windows (#​1577), by @​fengmk2
  • vp rebuild: accept positional package names (#​1564), by @​fengmk2
  • Adopt the new vite-task error formatter; errors now print as error: <top-level> plus * <source> chain lines, with bold-red highlight on a TTY (vite-task#390), by @​branchseer
  • vite-task: forward LOCALAPPDATA so Node's compile cache stays outside the workspace on Windows (vite-task#389), by @​branchseer
  • Bump vite-task to c945cc0 (#​1628), by @​branchseer
Refactor
Docs
Chore
Bundled Versions
Tool Version Source
vite 8.0.11 66f3194
rolldown 1.0.0 ac5c710
tsdown 0.22.0 npm
vitest 4.1.6 npm
oxlint 1.63.0 npm
oxlint-tsgolint 0.22.1 npm
oxfmt 0.48.0 npm
New Contributors

Welcome to all new contributors! 🎉

@​nozomee, @​ryohidaka, @​leno23

Full Changelog: voidzero-dev/vite-plus@v0.1.21...v0.1.22

Published Packages
  • @voidzero-dev/vite-plus-core@0.1.22
  • @voidzero-dev/vite-plus-test@0.1.22
  • vite-plus@0.1.22
Installation

macOS/Linux:

curl -fsSL https://vite.plus | bash

Windows:

irm https://vite.plus/ps1 | iex

Or download and run vp-setup.exe from the assets below.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedvite-plus@​0.1.2281100100100100

View full report

@renovate renovate Bot changed the title chore(deps): update dependency vite-plus to v0.1.22 chore(deps): update dependency vite-plus to v0.1.22 - autoclosed May 20, 2026
@renovate renovate Bot closed this May 20, 2026
@renovate renovate Bot deleted the renovate/vite-plus-0.x-lockfile branch May 20, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants