Repository navigation
fix(deps): update dependency @vitejs/plugin-react (6.1.1 → 6.1.2) - #1180
Conversation
There was a problem hiding this comment.
AI Automated Review
Full PR review.
Analysis engine: MiniMax-M3 (anthropic) — primary route · pr-reviewer-action v3.3.0
Recommendation
Approve. This is a lockfile-only patch bump of @vitejs/plugin-react 6.1.1 → 6.1.2, a devDependency used in this repo for Vitest's React transformation. CI is green on every check that ran (typecheck, build, lint, tests, coverage, docker build, npm audit, migrations, smoke).
Change-by-change findings
- package-lock.json (
@vitejs/plugin-react6.1.1 → 6.1.2) — patch release. Two changes in the lockfile: the resolved tarball/integrity, and theoxc-transform-reactpeer-dependency range raised from^0.145.0to^0.152.0. - Release notes (per upstream
plugin-react@6.1.2, 2026-10-05): fixes HMR for compound components (so adding/removing a child now invalidates importers), restorescompiler.logDiagnostics(nowcompiler.reportDiagnostics; requiresoxc-transform-react≥ 0.152 if you use thecompileroption), and disables fast-refresh for non-JSX when the compiler is enabled. All three are bug fixes; none are listed as breaking. - Peer-dep bump on
oxc-transform-react— this is a peer of@vitejs/plugin-react, not a dependency this repo installs directly. The repo does not opt into thecompileroption in Vitest config, so thecompiler.logDiagnosticsdeprecation does not apply here. The raise is informational only; npm does not auto-install peer deps, and the higher floor cannot conflict with anything currently resolved. - No source/config changes.
package.jsonstill declares@vitejs/plugin-reactat^6.0.1; both 6.1.1 and 6.1.2 satisfy that range, so the lockfile-only update is consistent with the manifest.
Standards Compliance
The repository's Renovate/digest-only review conventions (.github/ai-review-rules.md) and the AGENTS.md dependency-update norms are met: package-audit gate is satisfied (CI reports npm audit success); package-overrides remain intact (sharp, postcss, deepmerge-ts, mysql2); the lockfile entry is dev: true and a transitive-only concern. No standards violations.
Tool Harness Findings
Four read-only calls (package.json, package-overrides.test.ts, package-audit.test.ts, .github/ai-review-rules.md) — used to confirm scope of the dependency (devDependency at ^6.0.1, satisfies both old and new pin), confirm the security-audit gate is intact (overrides and audit script unchanged), and that review-tone guidance applies (compact review for a Renovate patch bump).
Unknowns or Needs Verification
None remaining that affect the verdict. The upstream release page and changelog were fetched and match the PR body; the peer-dep raise has no runtime impact here because the repo doesn't use the compiler option.
This PR contains the following updates:
6.1.1→6.1.2Release Notes
vitejs/vite-plugin-react (@vitejs/plugin-react)
v6.1.2Compare Source
Fix HMR for compound components (#1484)
Adding or removing a component from a compound component was not handled, creating stale updates. Doing this now triggers hmr invalidate on the file and propagates the invalidation to importers.
Fix
compiler.logDiagnosticsoption not working (#1483)With
oxc-transform-react>= 0.148, thelogDiagnosticswas not working. This version fixes it and requiresoxc-transform-react>= 0.152 as a peer dependency if you are using thecompileroption.compiler.logDiagnosticsoption is now deprecated and should be swapped for the builtincompiler.reportDiagnostics.Disable refresh for non-jsx with compiler enabled (fix #1478) (#1485)
When the compiler was enabled, TS files could trigger fast refresh which would cause runtime errors. The logic now follows what the builtin oxc plugin in Vite does.
Configuration
📅 Schedule: (in timezone America/Edmonton)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.