Skip to content

build(deps-dev): bump the npm_and_yarn group across 1 directory with 1 update - #3

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-c86b58a346
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-c86b58a346

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026 •

Copy link
Copy Markdown

Bumps the npm_and_yarn group with 1 update in the / directory: vitest.

Updates vitest from 4.0.18 to 4.1.0

Release notes

Sourced from vitest's releases.

v4.1.0

Vitest 4.1 is out!

This release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our blog post.

   🚀 Features

... (truncated)

Commits
  • 4150b91 chore: release v4.1.0
  • 1de0aa2 fix: correctly identify concurrent test during static analysis (#9846)
  • c3cac1c fix: use isAgent check, not just TTY, for watch mode (#9841)
  • eab68ba chore(deps): update all non-major dependencies (#9824)
  • 031f02a fix: allow catch/finally for async assertion (#9827)
  • 3e9e096 feat(reporters): add agent reporter to reduce ai agent token usage (#9779)
  • 0c2c013 chore: release v4.1.0-beta.6
  • 8181e06 fix: hideSkippedTests should not hide test.todo (fix #9562) (#9781)
  • a8216b0 fix: manual and redirect mock shouldn't load or transform original module...
  • 689a22a fix(browser): types of getCDPSession and cdp() (#9716)
  • Additional commits viewable in compare view

Updates vitest from 4.0.18 to 4.1.0

Release notes

Sourced from vitest's releases.

v4.1.0

Vitest 4.1 is out!

This release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our blog post.

   🚀 Features

... (truncated)

Commits
  • 4150b91 chore: release v4.1.0
  • 1de0aa2 fix: correctly identify concurrent test during static analysis (#9846)
  • c3cac1c fix: use isAgent check, not just TTY, for watch mode (#9841)
  • eab68ba chore(deps): update all non-major dependencies (#9824)
  • 031f02a fix: allow catch/finally for async assertion (#9827)
  • 3e9e096 feat(reporters): add agent reporter to reduce ai agent token usage (#9779)
  • 0c2c013 chore: release v4.1.0-beta.6
  • 8181e06 fix: hideSkippedTests should not hide test.todo (fix #9562) (#9781)
  • a8216b0 fix: manual and redirect mock shouldn't load or transform original module...
  • 689a22a fix(browser): types of getCDPSession and cdp() (#9716)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-c86b58a346 branch from b4cdef9 to e3e5d79 Compare August 29, 2026 19:59
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedvitest@​4.1.0981007999100

View full report

@socket-security

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. It is recommended to resolve "Warn" alerts too. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Medium
Potential vulnerability: npm es-module-lexer with risk level "medium"

Location: Package overview

From: pnpm-lock.yaml → npm/vitest@4.1.0 → npm/nuxt@4.4.7 → npm/es-module-lexer@2.3.2

ℹ Read more on: This package | This alert | Navigating potential vulnerabilities

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: It is advisable to proceed with caution. Engage in a review of the package's security aspects and consider reaching out to the package maintainer for the latest information or patches.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-module-lexer@2.3.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: npm @jridgewell/sourcemap-codec published 2 days ago

Location: Package overview

From: pnpm-lock.yaml → npm/@tailwindcss/postcss@4.1.18 → npm/@vitest/coverage-v8@4.0.18 → npm/vitest@4.1.0 → npm/workflow@4.2.4 → npm/vue@3.5.34 → npm/svelte@5.55.7 → npm/@vitest/coverage-v8@4.1.8 → npm/nuxt@4.4.7 → npm/workflow@5.0.0-beta.40 → npm/tsup@8.5.1 → npm/fumadocs-mdx@14.0.4 → npm/@vercel/analytics@1.6.1 → npm/@vercel/speed-insights@1.3.1 → npm/@jridgewell/sourcemap-codec@1.6.0

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@jridgewell/sourcemap-codec@1.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Potential security risk (AI signal): npm @vitest/snapshot is 78.0% likely risky

Notes: The module is designed for snapshot testing and correctness, but it evaluates snapshot artifact contents using new Function, effectively treating snapshot files as executable code. This becomes a high-impact security risk under threat models where snapshot files can be modified (e.g., compromised repo/workspace/CI artifacts). Apart from this eval-and-persist behavior, the excerpt shows no explicit malware-like actions such as network exfiltration or process control.

Confidence: 0.78

Severity: 0.72

From: pnpm-lock.yaml → npm/vitest@4.1.0 → npm/@vitest/snapshot@4.1.0

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vitest/snapshot@4.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: npm filename-reserved-regex published yesterday

Location: Package overview

From: pnpm-lock.yaml → npm/workflow@4.2.4 → npm/workflow@5.0.0-beta.40 → npm/filename-reserved-regex@4.0.1

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/filename-reserved-regex@4.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: npm filenamify published yesterday

Location: Package overview

From: pnpm-lock.yaml → npm/workflow@4.2.4 → npm/workflow@5.0.0-beta.40 → npm/filenamify@7.0.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/filenamify@7.0.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: npm piscina published yesterday

Location: Package overview

From: pnpm-lock.yaml → npm/workflow@4.2.4 → npm/workflow@5.0.0-beta.40 → npm/piscina@4.9.4

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/piscina@4.9.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Environment variable access: npm @xhmikosr/downloader reads npm_config_strict_ssl

Env Vars: npm_config_strict_ssl

Location: Package overview

From: pnpm-lock.yaml → npm/workflow@4.2.4 → npm/workflow@5.0.0-beta.40 → npm/@xhmikosr/downloader@16.3.1

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@xhmikosr/downloader@16.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm es-module-lexer is 74.0% likely to have a medium risk anomaly

Notes: A WebAssembly-backed parser wrapper (package/dist/lexer.js) executes substrings extracted from untrusted input using (0, eval) during parsing, enabling arbitrary JavaScript execution if attacker-controlled data reaches the eval path. The threat also includes potential sensitive data leakage through error messages. Disable parse() on untrusted input or sandbox/replace builds to mitigate this risk.

Confidence: 0.74

Severity: 0.78

From: pnpm-lock.yaml → npm/vitest@4.1.0 → npm/nuxt@4.4.7 → npm/es-module-lexer@2.3.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-module-lexer@2.3.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm es-module-lexer is 70.0% likely to have a medium risk anomaly

Notes: A WASM-backed parser wrapper copies caller input into WASM memory and conditionally executes eval() on substrings that resemble quoted literals, creating a potential code-execution risk in the calling process. Error messages may include slices of input, increasing the chance of sensitive data exposure; the embedded WASM payload is opaque and could contain additional, unseen behaviors.

Confidence: 0.70

Severity: 0.70

From: pnpm-lock.yaml → npm/vitest@4.1.0 → npm/nuxt@4.4.7 → npm/es-module-lexer@2.3.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-module-lexer@2.3.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm piscina is 72.0% likely to have a medium risk anomaly

Notes: This module is designed to execute dynamically loaded handler code in a worker thread. The presence of new Function-wrapped dynamic import and the use of message-provided filename/name create a high-impact risk of arbitrary code execution within the worker if those inputs are not strictly constrained/validated by the parent application. No explicit network/data exfiltration or persistence behavior is present in the shown code, but supply-chain-style or runtime code injection risk is significant due to dynamic importing and execution.

Confidence: 0.72

Severity: 0.60

From: pnpm-lock.yaml → npm/workflow@4.2.4 → npm/workflow@5.0.0-beta.40 → npm/piscina@4.9.4

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/piscina@4.9.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm piscina is 80.0% likely to have a medium risk anomaly

Notes: This module is a thin wrapper around Node's vm.Script and runInNewContext that compiles and runs a provided code string in a caller-supplied context. The pattern itself is powerful and legitimate for controlled use, but as implemented it lacks essential safeguards: it accepts unvalidated payloads, uses a caller-provided context that may expose powerful capabilities, and applies no execution limits. If payload or context are derived from untrusted sources, this presents a high security risk (arbitrary code execution, data leakage, DoS). Remediation: only execute trusted payloads; construct a minimal, immutable context exposing no host capabilities (no require/process/fs); deep-clone and freeze context values; run code in a restricted environment or separate process/container; enforce execution time and memory caps; validate or limit allowed operations (e.g., use SES or other hardened sandboxes).

Confidence: 0.80

Severity: 0.75

From: pnpm-lock.yaml → npm/workflow@4.2.4 → npm/workflow@5.0.0-beta.40 → npm/piscina@4.9.4

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/piscina@4.9.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm vitest is 64.0% likely to have a medium risk anomaly

Notes: This file implements legitimate, high-privilege module execution functionality: it dynamically executes inline module source strings in a Node.js VM and dynamically imports external modules based on provided identifiers, while also exposing process.env to evaluated code via an import-meta proxy. There are no explicit indicators of malware (no credential theft/exfiltration/persistence logic shown), but the security risk is elevated if inline code or module IDs are attacker-controlled, because the module provides arbitrary code execution with environment secret access and emits file-path telemetry that may disclose sensitive paths.

Confidence: 0.64

Severity: 0.50

From: packages/adapter-discord/package.json → npm/vitest@4.1.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vitest@4.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants