Skip to content

chore(deps-dev): bump @vitejs/plugin-react from 5.2.0 to 6.0.2 - #58

Merged
forbiddenlink merged 1 commit into
mainfrom
dependabot/npm_and_yarn/vitejs/plugin-react-6.0.2
Jun 9, 2026
Merged

chore(deps-dev): bump @vitejs/plugin-react from 5.2.0 to 6.0.2#58
forbiddenlink merged 1 commit into
mainfrom
dependabot/npm_and_yarn/vitejs/plugin-react-6.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 26, 2026

Copy link
Copy Markdown
Contributor

Bumps @vitejs/plugin-react from 5.2.0 to 6.0.2.

Release notes

Sourced from @​vitejs/plugin-react's releases.

plugin-react@6.0.2

Allow all options in reactCompilerPreset (#1189)

This is a type only change. Only compilationMode and target options were available for reactCompilerPreset.

plugin-react@6.0.1

Expand @rolldown/plugin-babel peer dep range (#1146)

Expanded @rolldown/plugin-babel peer dep range to include ^0.2.0.

plugin-react@6.0.0

Remove Babel Related Features (#1123)

Vite 8+ can handle React Refresh Transform by Oxc and doesn't need Babel for it. With that, there are no transform applied that requires Babel. To reduce the installation size of this plugin, babel is no longer a dependency of this plugin and the related features are removed.

If you are using Babel, you can use @rolldown/plugin-babel together with this plugin:

 import { defineConfig } from 'vite'
 import react from '@vitejs/plugin-react'
+import babel from '@rolldown/plugin-babel'
export default defineConfig({
plugins: [


react({



  babel: {



    plugins: ['@babel/plugin-proposal-throw-expressions'],



  },



}),





react(),



babel({



  plugins: ['@babel/plugin-proposal-throw-expressions'],



}),

]
})

For React compiler users, you can use reactCompilerPreset for easier setup with preconfigured filter to improve build performance:

 import { defineConfig } from 'vite'
-import react from '@vitejs/plugin-react'
+import react, { reactCompilerPreset } from '@vitejs/plugin-react'
+import babel from '@rolldown/plugin-babel'
export default defineConfig({
plugins: [

react({

 babel: {



   plugins: ['babel-plugin-react-compiler'],



</tr></table>

... (truncated)

Changelog

Sourced from @​vitejs/plugin-react's changelog.

6.0.2 (2026-05-14)

Allow all options in reactCompilerPreset (#1189)

This is a type only change. Only compilationMode and target options were available for reactCompilerPreset.

6.0.1 (2026-03-13)

Expand @rolldown/plugin-babel peer dep range (#1146)

Expanded @rolldown/plugin-babel peer dep range to include ^0.2.0.

6.0.0 (2026-03-12)

6.0.0-beta.0 (2026-03-03)

Remove Babel Related Features (#1123)

Vite 8+ can handle React Refresh Transform by Oxc and doesn't need Babel for it. With that, there are no transform applied that requires Babel. To reduce the installation size of this plugin, babel is no longer a dependency of this plugin and the related features are removed.

If you are using Babel, you can use @rolldown/plugin-babel together with this plugin:

 import { defineConfig } from 'vite'
 import react from '@vitejs/plugin-react'
+import babel from '@rolldown/plugin-babel'
export default defineConfig({
plugins: [


react({



  babel: {



    plugins: ['@babel/plugin-proposal-throw-expressions'],



  },



}),





react(),



babel({



  plugins: ['@babel/plugin-proposal-throw-expressions'],



}),

]
})

For React compiler users, you can use reactCompilerPreset for easier setup with preconfigured filter to improve build performance:

 import { defineConfig } from 'vite'
-import react from '@vitejs/plugin-react'
+import react, { reactCompilerPreset } from '@vitejs/plugin-react'
+import babel from '@rolldown/plugin-babel'
</tr></table>

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 26, 2026
@coderabbitai

coderabbitai Bot commented May 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c837cba9-3b13-453a-a67d-206091e477d8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The @vitejs/plugin-react development dependency is updated to version ^6.0.2 from ^5.2.0 in package.json. This is a single-line semver bump to a major version.

Changes

Vite React Plugin Dependency Update

Layer / File(s) Summary
Vite React plugin version bump
package.json
Development dependency @vitejs/plugin-react bumped from ^5.2.0 to ^6.0.2.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Poem

A tiny hop, a version climb,
From five to six, in time,
React plugin shines so bright,
The build flows pure and light. 🐰✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Description check ❓ Inconclusive PR description deviates from template by providing release notes instead of structured sections like Summary, Changes, Type of Change, and Testing. Restructure the description to follow the template: add a brief Summary section, itemize specific Changes, select Type of Change category, confirm Testing steps were completed, and verify all Checklist items.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main change: bumping @vitejs/plugin-react from version 5.2.0 to 6.0.2, which is exactly what the pull request does.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/npm_and_yarn/vitejs/plugin-react-6.0.2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security

socket-security Bot commented May 26, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​vitejs/​plugin-react@​6.0.210010010092100

View full report

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package.json`:
- Line 97: The package.json currently specifies "engines.node" as >=20.0.0 which
is too permissive for the dependency `@vitejs/plugin-react` (plugin name:
`@vitejs/plugin-react`, version referenced: ^6.0.2) that requires node: ^20.19.0
|| >=22.12.0; update package.json's engines.node to match that range (e.g.,
">=20.19.0 || >=22.12.0" or the equivalent consolidated semver range) so CI and
developer environments meet the plugin's Node requirement; modify the
engines.node field in package.json accordingly and run install/lockfile
regeneration to ensure consistency with pnpm-lock.yaml.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c1e8d81e-0bba-40da-85a0-9cb3018c007a

📥 Commits

Reviewing files that changed from the base of the PR and between 0e1168d and 4c12e42.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

Comment thread package.json
"@types/gradient-string": "^1.1.6",
"@types/node": "^22.15.21",
"@vitejs/plugin-react": "^5.2.0",
"@vitejs/plugin-react": "^6.0.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== package engines.node =="
node_engine=$(jq -r '.engines.node' package.json)
echo "$node_engine"

echo "== plugin-react resolved version and engines from lockfile =="
awk '
  /@vitejs\/plugin-react@6\.0\.2:/, /peerDependenciesMeta:/ { print }
' pnpm-lock.yaml

echo "== direct usage of `@vitejs/plugin-react` in config =="
rg -n -C2 "from '`@vitejs/plugin-react`'|plugins:\s*\[react\(\)\]" vitest.config.ts

Repository: forbiddenlink/specter

Length of output: 443


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== package.json engines.node =="
jq -r '.engines.node' package.json

echo "== package.json engines block (context) =="
jq '.engines' package.json

echo "== package.json pnpm overrides (context) =="
jq '.pnpm // empty | (.overrides // empty)' package.json

echo "== pnpm-lock.yaml: locate `@vitejs/plugin-react` 6.0.2 entry =="
rg -n "`@vitejs/plugin-react`@6\\.0\\.2" pnpm-lock.yaml
rg -n "plugin-react\\`@6`\\.0\\.2" pnpm-lock.yaml

echo "== pnpm-lock.yaml: print around the found entry (small context) =="
python3 - <<'PY'
import re
path="pnpm-lock.yaml"
pat=re.compile(r'`@vitejs/plugin-react`@6\.0\.2')
lines=open(path,'r',encoding='utf-8').read().splitlines()
for i,l in enumerate(lines):
    if pat.search(l):
        start=max(0,i-15); end=min(len(lines), i+80)
        print("\n--- match at line", i+1, "---")
        for j in range(start,end):
            print(f"{j+1}:{lines[j]}")
PY

echo "== package.json also contains `@vitejs/plugin-react` version spec =="
jq -r '.devDependencies["`@vitejs/plugin-react`"] // .dependencies["`@vitejs/plugin-react`"] // empty' package.json

Repository: forbiddenlink/specter

Length of output: 1233


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== package.json devDependencies entry (plugin-react version spec) =="
jq -r '.devDependencies["`@vitejs/plugin-react`"] // .dependencies["`@vitejs/plugin-react`"] // empty' package.json

echo "== package.json engines.node =="
jq -r '.engines.node // empty' package.json

echo "== pnpm-lock.yaml excerpt around line 1344 (base `@vitejs/plugin-react`@6.0.2 entry) =="
sed -n '1335,1375p' pnpm-lock.yaml

echo "== pnpm-lock.yaml excerpt around line 4700 (plugin-react@6.0.2 with vite peer) =="
sed -n '4685,4725p' pnpm-lock.yaml

echo "== locate vitest.config.ts plugin-react import/usage (context) =="
rg -n "from '`@vitejs/plugin-react`'|plugins:\s*\[react\(\)\]" vitest.config.ts

Repository: forbiddenlink/specter

Length of output: 3665


Tighten engines.node to match @vitejs/plugin-react’s Node requirement

package.json declares engines.node as >=20.0.0, but pnpm-lock.yaml shows @vitejs/plugin-react@6.0.2 requires engines: { node: ^20.19.0 || >=22.12.0 } (and it’s used in vitest.config.ts via plugins: [react()]). Tighten engines.node to the plugin’s Node range to avoid CI/dev breakage on Node 20.0–20.18.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 97, The package.json currently specifies "engines.node"
as >=20.0.0 which is too permissive for the dependency `@vitejs/plugin-react`
(plugin name: `@vitejs/plugin-react`, version referenced: ^6.0.2) that requires
node: ^20.19.0 || >=22.12.0; update package.json's engines.node to match that
range (e.g., ">=20.19.0 || >=22.12.0" or the equivalent consolidated semver
range) so CI and developer environments meet the plugin's Node requirement;
modify the engines.node field in package.json accordingly and run
install/lockfile regeneration to ensure consistency with pnpm-lock.yaml.

@github-actions

Copy link
Copy Markdown

👻 Specter Analysis

Metric Value
Health Score 0/100 🔴
PR Risk Low 🟢
Files Changed -
Est. Review Time ~5 min

Generated by Specter - Give your codebase a voice

@sentry

sentry Bot commented May 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/vitejs/plugin-react-6.0.2 branch from 4c12e42 to 4b1e014 Compare June 5, 2026 20:18
Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) from 5.2.0 to 6.0.2.
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.2/packages/plugin-react)

---
updated-dependencies:
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/vitejs/plugin-react-6.0.2 branch from 4b1e014 to fe5831e Compare June 8, 2026 07:39
@forbiddenlink
forbiddenlink merged commit 441e1b4 into main Jun 9, 2026
10 checks passed
@forbiddenlink
forbiddenlink deleted the dependabot/npm_and_yarn/vitejs/plugin-react-6.0.2 branch June 9, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant