Skip to content

feat(migrate): pin setup-vp workflow versions - #2540

Merged
fengmk2 merged 6 commits into
mainfrom
fix/migrate-setup-vp-version
Sep 2, 2026
Merged

feat(migrate): pin setup-vp workflow versions#2540
fengmk2 merged 6 commits into
mainfrom
fix/migrate-setup-vp-version

Conversation

@fengmk2

@fengmk2 fengmk2 commented Aug 23, 2026

Copy link
Copy Markdown
Member

vp migrate now replaces exact voidzero-dev/setup-vp@v1 references in GitHub Actions workflows and composite actions under .github. It replaces the frozen tag with v1.18.0. It keeps exact versions, commit SHAs, comments, quotes, and line endings.

The same version pin applies to new Copilot setup workflows. Renovate keeps the pin current.

This change adds unit tests and a PTY snapshot for existing Vite+ projects. The snapshot also checks repeated migration runs. The documentation now explains this behavior.

@netlify

netlify Bot commented Aug 23, 2026

Copy link
Copy Markdown

Deploy Preview for viteplus-preview ready!

Name Link
🔨 Latest commit e004f85
🔍 Latest deploy log https://app.netlify.com/projects/viteplus-preview/deploys/6a97b7fc1317970009373d61
😎 Deploy Preview https://deploy-preview-2540--viteplus-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@fengmk2 fengmk2 self-assigned this Aug 23, 2026
@github-actions

github-actions Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

✅ Staging deployment successful!

Preview: https://viteplus-staging.void.app/
Commit: e004f85

@socket-security

socket-security Bot commented Aug 23, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​vite-plus@​0.0.0-commit.0c515e3fbf5c140db35280d700df0bd600838617N/AN/AN/AN/AN/A
Addednpm/​@​voidzero-dev/​vite-plus-core@​0.0.0-commit.0c515e3fbf5c140db35280d700df0bd600838617N/AN/AN/AN/AN/A

View full report

@fengmk2
fengmk2 force-pushed the fix/migrate-setup-vp-version branch 5 times, most recently from 2d59d61 to 43ae98f Compare August 25, 2026 03:45
@fengmk2 fengmk2 changed the title fix(migrate): pin setup-vp workflow versions feat(migrate): pin setup-vp workflow versions Aug 25, 2026
@fengmk2
fengmk2 marked this pull request as ready for review August 25, 2026 03:52
@fengmk2
fengmk2 force-pushed the fix/migrate-setup-vp-version branch 2 times, most recently from f785029 to 429cc95 Compare August 30, 2026 03:30
@fengmk2
fengmk2 requested a review from cpojer August 31, 2026 15:19
@fengmk2
fengmk2 force-pushed the fix/migrate-setup-vp-version branch from 429cc95 to 76f1833 Compare August 31, 2026 15:22
@fengmk2
fengmk2 merged commit d3bc20a into main Sep 2, 2026
61 checks passed
@fengmk2
fengmk2 deleted the fix/migrate-setup-vp-version branch September 2, 2026 06:26
fengmk2 added a commit that referenced this pull request Sep 8, 2026
`vp env` now manages Node.js and package-manager versions together. This
release also fixes TanStack Start routing and stale Vitest aliases.

### Breaking Changes

#### Package-manager setup

Vite+ replaces Corepack with managed `npm`, `pnpm`, `yarn`, and `bun`
commands. It removes the `corepack` shim and legacy global
package-manager installations
([#2391](#2391)), by
@liangmiQwQ.

Replace Corepack setup commands in shell profiles, CI jobs, and
Dockerfiles:

| Previous setup | Replacement |
| --- | --- |
| `corepack enable` | `vp env setup` |
| `vp install -g pnpm@<version>` | `vp env default pnpm@<version>` |
| `vp install -g yarn@<version>` | `vp env default yarn@<version>` |
| `vp install -g bun@<version>` | `vp env default bun@<version>` |
| `vp install -g corepack` | Use the managed package-manager commands
directly |

Use `vp env pin <manager>@<version>` to set a project version.

#### `vp env` command scope and JSON output

Unscoped `vp env` commands now operate on Node.js and package managers.
Package managers support independent defaults, project pins, session
overrides, and installation commands
([#2398](#2398)), by
@liangmiQwQ.

Add `node` to limit an operation to Node.js, for example, `vp env off
node` or `vp env unpin node`. Bare versions, such as `vp env default
22.19.0`, still select Node.js.

Update scripts that read JSON output:

| Command | New output structure |
| --- | --- |
| `vp env current --json` | `node` and `package_manager` objects |
| `vp env list --json`, `vp env list-remote --json` | `node` and
`package_managers` groups |

See the [environment guide](https://viteplus.dev/guide/env).

#### `vp pack` migration to `tsdown` `0.23`

`vp pack` now uses `tsdown` `0.23`, which removes deprecated options and
changes defaults
([#2614](#2614)), by
@fengmk2.

1. Run `vp migrate` to update supported static configurations and
package scripts, including projects that already use Vite+.
2. Check migration warnings in `vite.config.*`, `tsdown.config.*`, and
`package.json`.
3. Update dynamic configurations manually. Arrays built with `.map()`
require manual changes, even when migration reports no warning.
4. Run `vp pack` to check the result.

| Previous option | Replacement |
| --- | --- |
| `bundle: false` | `unbundle: true` |
| `outExtension` | `outExtensions` |
| `publicDir` / `--public-dir` | `copy` / `--copy` |
| `removeNodeProtocol: true` | `nodeProtocol: 'strip'` |
| `injectStyle` | `css.inject` |
| `inlineOnly` / `deps.onlyAllowBundle` | `deps.onlyBundle` |
| `noExternal` | `deps.alwaysBundle` |
| `skipNodeModulesBundle: true` / `deps.skipNodeModulesBundle: true` |
`deps.neverBundle: true` |
| `dts.tsgo: true` / `dts.oxc: true` | `dts.generator: 'tsgo'` /
`dts.generator: 'oxc'` |

Migration preserves the previous defaults for dependency resolution and
ATTW.

`tsdown` no longer supports Node.js `25`. Use Node.js `^22.18.0`,
`^24.11.0`, or `>=26.0.0`. The programmatic `build()` API now returns `{
bundles, watch }`.

See the [complete migration
guide](https://github.com/rolldown/tsdown/releases/tag/v0.23.0) for
declaration and TypeScript module-resolution changes.

#### CLI argument validation

`vp staged`, `vp config`, `vp hooks`, `vp migrate`, and `vp create` now
reject unsupported options and extra positional arguments
([#2523](#2523)), by
@fengmk2.

Remove unsupported arguments from scripts. For example, replace `vp
config --hooks-only` with `vp config --no-agent`.

### Highlights

- Fix TanStack Start HTTP `404` responses caused by separate Vite
runtime copies
([#2617](#2617)), by
@fengmk2.
- Reduce the Windows `vp-shim.exe` size from `214 KiB` to `14 KiB`
([#2466](#2466)), by
@fengmk2.
- Add `vp check --quiet` to hide lint warning diagnostics while
retaining errors and summary counts
([#2593](#2593)), by
@RSS1102.

### Features

- Add `vp sync-versions --json` so automation can request dependency
alignment plans from manifest snapshots without changing project files
([#2600](#2600)), by
@afonsojramos.
- Make `vp create --git` suggest an initial commit command after Git
initialization
([#2581](#2581)), by
@fengmk2.
- Make `vp migrate` replace frozen `voidzero-dev/setup-vp@v1` workflow
references with the supported version pin
([#2540](#2540)), by
@fengmk2.
- Upgrade `rolldown` from `1.2.5` to `1.2.7`, `tsdown` from `0.22.14` to
`0.23.0`, and Oxc from `0.146.0` to `0.148.0`. Upgrade `oxlint` from
`1.79.0` to `1.81.0` and `oxfmt` from `0.64.0` to `0.66.0`. These
versions can flag code that passed before. Run `vp fmt` after upgrading
if CI runs `vp check`
([#2580](#2580),
[#2613](#2613)), by
@voidzero-guard[bot].

### Fixes & Enhancements

- Resolve package-manager versions without rewriting `package.json`. Use
`vp env pin` or `vp env unpin` to change project declarations explicitly
([#2399](#2399)), by
@liangmiQwQ.
- Let `vp migrate` repair stale `vitest` aliases that previously
prevented the CLI from starting
([#2605](#2605)), by
@fengmk2.
- Keep Vite DevTools within the version ranges supported by the bundled
Vite ([#2559](#2559)), by
@fengmk2.
- Keep automatic Vitest upgrades on the supported `4.x` major
([#2612](#2612)), by
@fengmk2.
- Remove a deprecated `tsdown` option from the prompts package build
([#2597](#2597)), by
@jong-kyung.

### Refactor

- Use the updated `which` dependency to resolve relative `PATH` entries
([#2583](#2583)), by
@RSS1102.
- Remove the unused `async-trait` annotation from `JsRuntimeProvider`
([#2538](#2538)), by
@jong-kyung.

### Docs

- Add Azure Pipelines setup instructions
([#2553](#2553)), by
@naokihaba.
- Correct Zed Oxc formatter settings and include JSX and TSX
([#2592](#2592)), by
@joschuba.
- Add Wrangler deployment configuration for the documentation site
([#2596](#2596)), by
@mdong1909.
- Explain conflicts between pnpm and Vite+ runtime management, including
the `runtimeOnFail` setting
([#2620](#2620)), by
@liangmiQwQ.

### Chore

- Run CLI snapshots without published release packages
([#2625](#2625)), by
@fengmk2.
- Update the release-manager skill with package-install checks,
changelog guidance, and announcement handling
([#2548](#2548)), by
@fengmk2.
- Wait for npm dependencies to become available before publishing
dependent release packages
([#2601](#2601)), by
@fengmk2.
- Remove old Docker preview images
([#2539](#2539)), by
@fengmk2.
- Stabilize external-tool snapshots and isolate npm network cases
([#2577](#2577),
[#2604](#2604)), by
@fengmk2.
- Avoid unreliable Fish PPA setup in CI
([#2560](#2560)), by
@fengmk2.
- Update the `vinext` fixture to an upstream fix
([#2571](#2571)), by
@jong-kyung.
- Stabilize the pnpm snapshot and Nuxt build in CI
([#2591](#2591)), by
@voidzero-guard[bot].
- Pin pnpm in project-creation build-approval fixtures
([#2616](#2616)), by
@liangmiQwQ.
- Remove unused documentation components, assets, and the typewriter
dependency
([#2550](#2550),
[#2562](#2562)), by
@jong-kyung.
- Remove duplicate `tempfile` dependencies, an unused runtime helper,
and unused error variants. Update the `unit_bindings` lint name
([#2555](#2555),
[#2558](#2558),
[#2566](#2566),
[#2567](#2567)), by
@jong-kyung.
- Update GitHub Actions dependencies, including `actions/setup-node`
`v7` ([#2544](#2544),
[#2545](#2545),
[#2582](#2582),
[#2618](#2618)), by
@renovate[bot].
- Update `crate-ci/typos` through `v1.50.1`
([#2584](#2584),
[#2589](#2589),
[#2609](#2609)), by
@renovate[bot].
- Update repository pnpm to `11.24.0`
([#2590](#2590)), by
@renovate[bot].
- Update `voidzero-dev/setup-vp` to `v1.19.0`
([#2619](#2619)), by
@renovate[bot].

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| `vite` | `8.2.2` |
[`de1111a`](vitejs/vite@de1111a)
|
| `rolldown` | `1.2.7` |
[`26b4c6e`](rolldown/rolldown@26b4c6e)
|
| `tsdown` | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0)
|
| `vitest` | `4.1.11` | [npm](https://npmx.dev/package/vitest/v/4.1.11)
|
| `oxlint` | `1.81.0` | [npm](https://npmx.dev/package/oxlint/v/1.81.0)
|
| `oxlint-tsgolint` | `7.0.2001` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) |
| `oxfmt` | `0.66.0` | [npm](https://npmx.dev/package/oxfmt/v/0.66.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@afonsojramos, @joschuba

**Full Changelog**:
v0.3.0...v0.3.1

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants