Skip to content

chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 - #94

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.11
Open

chore(deps-dev): bump vitest from 4.1.10 to 4.1.11#94
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-4.1.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps vitest from 4.1.10 to 4.1.11.

Release notes

Sourced from vitest's releases.

v4.1.11

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • 9bd8d46 chore: release v4.1.11 (#10995)
  • 9851dbc fix(browser): trigger playwright/chromium gc on lower disk availability [back...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.10 to 4.1.11.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 24, 2026
@github-actions

Copy link
Copy Markdown

supply-chain-guard Scan Report

WARNING: Findings were detected.

Canonical JSON report: 3 reportable finding(s).

## 🛡️ supply-chain-guard Scan Report

| Property | Value |
|----------|-------|
| Target | `.` |
| Type | directory |
| Time | 2026-08-24T04:40:50.220Z |
| Duration | 802ms |
| **Risk Score** | **6/100** (LOW) |

### Summary

Scanned 67 of 72 files.

🔵 3 low

### Findings

#### 🔵 [LOW] Action "homeofe/supply-chain-guard&#64;v5" uses a version tag instead of a commit SHA. Tags can be force-pushed to point to different commits.

- **Rule:** `GHA_TAG_NOT_SHA`
- **File:** `.github/workflows/supply-chain-guard.yml:27`
- **Match:** `homeofe/supply-chain-guard&#64;v5`
- **Recommendation:** Consider pinning this action to a full commit SHA for maximum security. Tags can be moved to point to malicious code.

#### 🔵 [LOW] Action "homeofe/supply-chain-guard&#64;v5" is from third-party owner "homeofe". Third-party actions can be compromised.

- **Rule:** `GHA_THIRD_PARTY_ACTION`
- **File:** `.github/workflows/supply-chain-guard.yml:27`
- **Match:** `homeofe/supply-chain-guard&#64;v5`
- **Recommendation:** Pin "homeofe/supply-chain-guard&#64;v5" to a specific commit SHA and audit the action source code before use.

#### 🔵 [LOW] Build workflow found but no signed provenance or attestation detected &amp;#40;SLSA Level 1&amp;#41;. Artifacts cannot be cryptographically verified.

- **Rule:** `SLSA_NO_PROVENANCE`
- **Recommendation:** Add 'slsa-framework/slsa-github-generator' or 'actions/attest-build-provenance' to your release workflow to reach SLSA Level 2. Consider cosign for container signing.

### Recommendations

- Review the listed findings and assess whether they represent legitimate functionality or potential threats.

---
*Generated by [supply-chain-guard](https://github.com/homeofe/supply-chain-guard)*

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants