Skip to content

chore(deps): bump vite-plus to PR #1633 (pkg-pr-new)#4

Draft
fengmk2 wants to merge 1 commit into
mainfrom
update-vite-plus-prerelease-test-pr-1633
Draft

chore(deps): bump vite-plus to PR #1633 (pkg-pr-new)#4
fengmk2 wants to merge 1 commit into
mainfrom
update-vite-plus-prerelease-test-pr-1633

Conversation

@fengmk2
Copy link
Copy Markdown
Owner

@fengmk2 fengmk2 commented May 19, 2026

Summary

Bump vite-plus and related @voidzero-dev/* packages to the pkg-pr-new prerelease for vite-plus PR #1633.

Updated where applicable:

  • vite-plushttps://pkg.pr.new/voidzero-dev/vite-plus@1633
  • vite alias → @voidzero-dev/vite-plus-core pkg-pr-new URL
  • vitest alias → @voidzero-dev/vite-plus-test pkg-pr-new URL
  • overrides / resolutions / pnpm.overrides / pnpm-workspace.yaml catalogs

Also configured minimum-release-age with vite-plus / @voidzero-dev/* excluded for pnpm / bun / npm.

Test plan

  • CI passes

@fengmk2 fengmk2 self-assigned this May 19, 2026
Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the pnpm-workspace.yaml file to use specific PR preview packages from pkg.pr.new for vite, vitest, and vite-plus, while also excluding these packages from the minimum release age requirement. A security concern was raised regarding the global disabling of blockExoticSubdeps, with a recommendation to use allowedExoticSubdeps to explicitly permit only the trusted preview sources instead.

Comment thread pnpm-workspace.yaml
esbuild: true
keytar: false
blockExoticSubdeps: true
blockExoticSubdeps: false
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Disabling blockExoticSubdeps globally is a security risk as it allows any dependency in the tree to pull in code from non-registry sources (like arbitrary URLs). It is recommended to keep this enabled and use allowedExoticSubdeps to explicitly permit only the trusted PR packages from pkg.pr.new.

blockExoticSubdeps: true
allowedExoticSubdeps:
  - vite-plus
  - '@voidzero-dev/*'

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant