Skip to content

chore(deps-dev): bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory - #3

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/client/npm_and_yarn-788cdcced7
Open

chore(deps-dev): bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory#3
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/client/npm_and_yarn-788cdcced7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 22, 2026

Copy link
Copy Markdown

Bumps the npm_and_yarn group with 1 update in the /client directory: vite.

Updates vite from 5.4.21 to 8.2.2

Release notes

Sourced from vite's releases.

plugin-legacy@8.2.2

Please refer to CHANGELOG.md for details.

v8.2.2

Please refer to CHANGELOG.md for details.

plugin-legacy@8.2.1

Please refer to CHANGELOG.md for details.

v8.2.1

Please refer to CHANGELOG.md for details.

create-vite@8.2.0

Please refer to CHANGELOG.md for details.

plugin-legacy@8.2.0

Please refer to CHANGELOG.md for details.

v8.2.0

Please refer to CHANGELOG.md for details.

v8.2.0-beta.0

Please refer to CHANGELOG.md for details.

v8.1.5

Please refer to CHANGELOG.md for details.

v8.1.4

Please refer to CHANGELOG.md for details.

v8.1.3

Please refer to CHANGELOG.md for details.

v8.1.2

Please refer to CHANGELOG.md for details.

v8.1.1

Please refer to CHANGELOG.md for details.

create-vite@8.1.0

Please refer to CHANGELOG.md for details.

plugin-legacy@8.1.0

Please refer to CHANGELOG.md for details.

v8.1.0

Please refer to CHANGELOG.md for details.

plugin-legacy@8.1.0-beta.0

Please refer to CHANGELOG.md for details.

... (truncated)

Changelog

Sourced from vite's changelog.

8.2.2 (2026-08-20)

Features

  • deps: widen @vitejs/devtools peer range to v0.5.0 (#23302) (495d9ff)

Bug Fixes

  • bundled-dev: handle lazy request error (#23291) (3ba026d)
  • bundled-dev: hot update through circular imports instead of reloading (#23259) (3dbddef)
  • config: resolve sourcemap paths against sourcemap location (#23239) (05a003e)
  • css: don't pass empty targets to lightningcss (#23295) (2804636)
  • define: fix match escaped dots to support $-prefixed define keys (#23249) (dcf88bd)
  • deps: update all non-major dependencies (#23217) (ba958bd)
  • deps: update rolldown-related dependencies (#23218) (83ecb2c)
  • module-runner: exclude completed modules from in-flight cycle detection (fix #22999) (#23009) (d9b10a9)
  • optimizer: close custom extension analysis bundles (#23207) (8fb7675)
  • reduce Windows 8.3-short-name detection false-positives (#23066) (02cffa9)
  • respect resolve.preserveSymlinks when resolving root (fix #23197) (#23198) (8413052)
  • ssr: rewrite computed key of destructing parameter (#23307) (9db0b61)
  • vite: update outdated upstream file links in license comments (#23285) (c0f2fc6)

Documentation

Miscellaneous Chores

Code Refactoring

  • use JSON import attributes instead of readFileSync in constants (#23258) (1d9fa39)
  • use named regex constants over inline literals (#22964) (5c1c6c6)

Tests

  • define: close rolldown bundler after generate (#23231) (b4d66fe)
  • module-runner: add TLA circular import case (#23299) (4a261f2)
  • module-runner: simplify server-hmr tests (#23300) (599b44b)
  • ssr: add destructing assignment case for moduleRunnerTransform (#23308) (cb77e2a)

Build System

  • use JSON import attributes instead of readFIleSync in rolldown configs (#23251) (d615bcd)

8.2.1 (2026-08-06)

Bug Fixes

  • build: make client chunkImportMap work with sharedPlugins: true (#23184) (15f0307)
  • bundled-dev: inject client script tag before chunk scripts (#23161) (eac0cc8)

... (truncated)

Commits
  • de1111a release: v8.2.2
  • cb77e2a test(ssr): add destructing assignment case for moduleRunnerTransform (#23308)
  • 9db0b61 fix(ssr): rewrite computed key of destructing parameter (#23307)
  • 8413052 fix: respect resolve.preserveSymlinks when resolving root (fix #23197) (#23...
  • 05a003e fix(config): resolve sourcemap paths against sourcemap location (#23239)
  • 495d9ff feat(deps): widen @vitejs/devtools peer range to v0.5.0 (#23302)
  • 1d9fa39 refactor: use JSON import attributes instead of readFileSync in constants (#2...
  • 2804636 fix(css): don't pass empty targets to lightningcss (#23295)
  • 599b44b test(module-runner): simplify server-hmr tests (#23300)
  • 4a261f2 test(module-runner): add TLA circular import case (#23299)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 22, 2026
@dependabot dependabot Bot changed the title build(deps-dev): bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory chore(deps-dev): bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory Aug 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/client/npm_and_yarn-788cdcced7 branch 2 times, most recently from 07e8437 to 290c7c0 Compare August 24, 2026 09:27
@dependabot dependabot Bot changed the title chore(deps-dev): bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory chore(deps-dev): Bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory Aug 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/client/npm_and_yarn-788cdcced7 branch from 290c7c0 to f1808d5 Compare August 24, 2026 18:17
@dependabot dependabot Bot changed the title chore(deps-dev): Bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory chore(deps-dev): bump vite from 5.4.21 to 8.2.2 in /client in the npm_and_yarn group across 1 directory Aug 25, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/client/npm_and_yarn-788cdcced7 branch from f1808d5 to 18e7ae1 Compare August 25, 2026 13:46
BillyOutlast pushed a commit that referenced this pull request Aug 25, 2026
…iteration 43)

Closes A3 #3/#4: atmosphere AND speech guards no longer trust forgeable
Yjs clientIDs — SETs and DELETEs both gate on the delivering connection's
HMAC-verified role/user. Corrective broadcasts rate-limited per connection
(5/min then close 4008); persistence debounced 1s with flush on shutdown.
Red tests reproduced forged-GM-clientID acceptance before the fix; live
smoke verified eviction+restore, disconnect, zero mid-debounce writes.
66 relay tests passing (20 new).

Co-Authored-By: Claude <noreply@anthropic.com>
BillyOutlast pushed a commit that referenced this pull request Aug 25, 2026
…teration 60)

Closes A4 #2/#3: inspiration grant/revoke is now gm/admin/service-only
(403 INSPIRATION_GM_ONLY) — the per-turn self-grant advantage mint is
dead; new revoke surface. Escape-grapple verifies the named grappler
via a session-level holder map (ledger-fallback for legacy holds),
409 NOT_YOUR_GRAPPLER before any spend; forced escapes respect
attribution too; rewind rebuilds holders from surviving events.
6 tests red-first reproducing both exploits live; cargo 379/19.

Co-Authored-By: Claude <noreply@anthropic.com>
Bumps the npm_and_yarn group with 1 update in the /client directory: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).


Updates `vite` from 5.4.21 to 8.2.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.2.2/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.2.2
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/client/npm_and_yarn-788cdcced7 branch from 18e7ae1 to 7267191 Compare August 25, 2026 23:43
@sonarqubecloud

Copy link
Copy Markdown

BillyOutlast pushed a commit that referenced this pull request Aug 31, 2026
…eration 42)

The condition-ring module (iteration 25) deliberately dropped invisible and petrified as 'engine-only' — but the engine now wires both mechanically (iteration 41: Invisible grants advantage on its own attacks; Petrified is incapacitated, auto-fails STR/DEX saves, grants advantage to attackers). Added both to THEMED_CONDITIONS + CONDITION_RING_THEMES (invisible = cyan-300 ScanEye, 10.5:1; petrified = zinc-300 Gem, 10.3:1 — both WCAG-AA vs --tavern-bg) and to CONDITION_PRIORITY (petrified at #3 after paralyzed, invisible at #7 after blinded). Updated the 4 stale 'engine-only' doc comments (module header, themedConditions, hasThemedCondition, TacticalCanvas ring comment) and the 2 DOM tests that pinned the old drop behavior. 4 new unit tests + 2 new DOM tests — vitest 799 (was 795), tsc clean, build 4.66s.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants