This is an automated email from the ASF dual-hosted git repository.

github-merge-queue[bot] pushed a commit to branch 
gh-readonly-queue/main/pr-8454-9ead3ac13a3f11a70457f0159c8f7a11cb2c4535
in repository https://gitbox.apache.org/repos/asf/texera.git

commit e67ba7e04526e1d17ef48d9b6969bb51914a3c18
Author: Mend Renovate <[email protected]>
AuthorDate: Fri Sep 25 21:06:35 2026 +0000

    fix(deps, frontend): update dependency vitest to v4.1.11 (#8454)
    
    This PR contains the following updates:
    
    | Package | Change |
    [Age](https://docs.renovatebot.com/merge-confidence/) |
    [Confidence](https://docs.renovatebot.com/merge-confidence/) |
    |---|---|---|---|
    | [vitest](https://vitest.dev)
    
([source](https://redirect.github.com/vitest-dev/vitest/tree/HEAD/packages/vitest))
    | [`4.1.10` →
    `4.1.11`](https://renovatebot.com/diffs/npm/vitest/4.1.10/4.1.11) |
    
![age](https://developer.mend.io/api/mc/badges/age/npm/vitest/4.1.11?slim=true)
    |
    
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vitest/4.1.10/4.1.11?slim=true)
    |
    
    ---
    
    ### Vitest: Path Traversal / Arbitrary File Read via
    @&#8203;vitest/mocker Redirect Mock
    [CVE-2026-84373](https://nvd.nist.gov/vuln/detail/CVE-2026-84373) /
    
[GHSA-82fw-gwwq-j7x9](https://redirect.github.com/advisories/GHSA-82fw-gwwq-j7x9)
    
    <details>
    <summary>More information</summary>
    
    #### Details
    ##### Summary
    `@vitest/mocker` registers a redirect mock's target path without
    validating it
    against the dev server's file-serving allowlist. An attacker who can
    reach the
    dev server's WebSocket can register a redirect mock pointing outside the
    project
    root; when the mocked module is requested, the plugin's `load` hook
    returns
    `readFile(<attacker path>)` as the module source, disclosing local
    files.
    
    This is exploitable **without authentication** only through the public
    `mockerPlugin` / standalone `interceptorPlugin` exports (used by
    third-party dev
    servers), which register the handler on Vite's unauthenticated HMR
    socket.
    Vitest's own browser mode registers mocks over a **token-authenticated**
    RPC and
    is not remotely reachable by default (see Scope).
    
    ##### Affected code
    `packages/mocker/src/node/interceptorPlugin.ts`.
    
    The `load` hook is the file-read sink:
    
    ```ts
    if (mock.type === 'redirect') {
      return readFile(mock.redirect, 'utf-8')
    }
    ```
    
    `mock.redirect` is derived from client input at registration time with
    no
    boundary check:
    
    ```ts
    if (event.type === 'redirect') {
      const redirectUrl = new URL(event.redirect)
      event.redirect = join(server.config.root, redirectUrl.pathname)
    }
    registry.register(event)
    ```
    
    There is no `server.fs.allow` / `server.fs.deny` check and no assertion
    that the
    resolved path stays within the project root.
    
    ##### Registration paths and trust boundaries
    - **Public `mockerPlugin` / `interceptorPlugin` (unauthenticated).** In
    `configureServer`, the plugin registers
    `server.ws.on('vitest:interceptor:register', …)`
    on Vite's HMR WebSocket. That socket performs no token, Origin, or
    same-origin
    check, so any client that can reach it can register a redirect mock.
    This is
      the path the "unauthenticated" impact applies to.
    - **Vitest browser mode (authenticated).** Mocks register over the
    browser RPC
    (`registerMock`), which sits behind a per-run token
    (`isValidApiRequest`, a
    random `api.token`). The interceptor's `configureServer` socket is not
    used for
    registration here (in v5 it does not run at all, as the plugin is
    injected per
    environment). The same missing boundary check exists on the
    authenticated RPC
    path, but reaching it requires the token, so it is not a
    remote-unauthenticated
      read.
    
    ##### Path handling
    `new URL(redirect).pathname` combined with `join(root, pathname)` does
    **not**
    confine reads to the root:
    
    - Special/hierarchical schemes (`file:`, `http:`) are normalized by
    WHATWG URL,
    so `..` segments are collapsed and the result stays under the root.
    Payloads of
      the form `file:///../../etc/passwd` do **not** escape.
    - A non-special (opaque) scheme preserves `..` in `pathname`, so
    `join(root, "../../…/etc/passwd")` resolves outside the root and reads
    an
      arbitrary file.
    
    Even without escaping the root, the missing `server.fs` check allows
    reading any
    in-root file the dev server would otherwise refuse to serve (for example
    an
    in-root `.env` or source that is denied by `server.fs.deny`).
    
    ##### Scope / preconditions
    - This is a **development-server** issue. The dev server binds to
    `localhost` by
    default and is not reachable from the network unless the developer
    exposes it
      (`server.host` / `0.0.0.0`, a LAN bind, or a proxy).
    - A raw (non-browser) client against a reachable server bypasses browser
    origin
    and CORS protections entirely and can both register the mock and read
    the
      response.
    - A browser-based drive-by against a localhost server is substantially
    mitigated
    by Vite defaults: the default CORS origin allowlist is limited to
    `localhost`
    origins, and `server.allowedHosts` blocks DNS-rebinding, so a
    cross-origin page
      cannot read the file contents back.
    
    ##### Impact
    Disclosure of local files readable by the dev-server process (source,
    in-root
    `.env`/secrets, and, via the opaque-scheme payload, files outside the
    project
    root). No integrity or availability impact.
    
    ##### Affected versions
    Present since `@vitest/mocker` was introduced.
    
    - **Affected: `@vitest/mocker` >= 2.1.0** (shipped in `vitest` and
      `@vitest/browser` >= 2.1.0), through 4.1.x and the 5.0.0 pre-releases.
    - **Fixed:** Vitest 4.1.11 and 5.0.0. Older majors (2.1.x, 3.x) are not
      maintained and are not planned to receive the fix.
    
    ##### Fix
    Validate the resolved redirect target against Vite's file-serving
    allowlist
    (`isFileLoadingAllowed`) before registering it, at every registration
    site, and
    stop registering the interceptor WebSocket events in Vitest's browser
    mode
    (mocks there flow through the authenticated RPC).
    
    #### Severity
    - CVSS Score: 5.9 / 10 (Medium)
    - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N`
    
    #### References
    -
    
[https://github.com/vitest-dev/vitest/security/advisories/GHSA-82fw-gwwq-j7x9](https://redirect.github.com/vitest-dev/vitest/security/advisories/GHSA-82fw-gwwq-j7x9)
    -
    
[https://nvd.nist.gov/vuln/detail/CVE-2026-84373](https://nvd.nist.gov/vuln/detail/CVE-2026-84373)
    -
    
[https://github.com/vitest-dev/vitest/pull/10972](https://redirect.github.com/vitest-dev/vitest/pull/10972)
    -
    
[https://github.com/vitest-dev/vitest/pull/10974](https://redirect.github.com/vitest-dev/vitest/pull/10974)
    -
    
[https://github.com/vitest-dev/vitest/commit/51edf2b072902aec6d30c90ebaafd8f121c6f9d8](https://redirect.github.com/vitest-dev/vitest/commit/51edf2b072902aec6d30c90ebaafd8f121c6f9d8)
    -
    
[https://github.com/vitest-dev/vitest/commit/8ff9b9a9efca7c6cfd5243569440de8d7a33aec4](https://redirect.github.com/vitest-dev/vitest/commit/8ff9b9a9efca7c6cfd5243569440de8d7a33aec4)
    -
    
[https://github.com/vitest-dev/vitest/commit/fe5a11d3ceac5ec10d6d7d21a46d4caca132c48f](https://redirect.github.com/vitest-dev/vitest/commit/fe5a11d3ceac5ec10d6d7d21a46d4caca132c48f)
    -
    
[https://github.com/vitest-dev/vitest/releases/tag/v4.1.11](https://redirect.github.com/vitest-dev/vitest/releases/tag/v4.1.11)
    -
    
[https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-rc.2](https://redirect.github.com/vitest-dev/vitest/releases/tag/v5.0.0-rc.2)
    -
    
[https://github.com/advisories/GHSA-82fw-gwwq-j7x9](https://redirect.github.com/advisories/GHSA-82fw-gwwq-j7x9)
    
    This data is provided by the [GitHub Advisory
    Database](https://redirect.github.com/advisories/GHSA-82fw-gwwq-j7x9)
    ([CC-BY
    
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
    </details>
    
    ---
    
    ### Vitest: Path Traversal / Arbitrary File Read via
    @&#8203;vitest/mocker Redirect Mock
    [CVE-2026-84373](https://nvd.nist.gov/vuln/detail/CVE-2026-84373) /
    
[GHSA-82fw-gwwq-j7x9](https://redirect.github.com/advisories/GHSA-82fw-gwwq-j7x9)
    
    <details>
    <summary>More information</summary>
    
    #### Details
    ##### Summary
    `@vitest/mocker` registers a redirect mock's target path without
    validating it
    against the dev server's file-serving allowlist. An attacker who can
    reach the
    dev server's WebSocket can register a redirect mock pointing outside the
    project
    root; when the mocked module is requested, the plugin's `load` hook
    returns
    `readFile(<attacker path>)` as the module source, disclosing local
    files.
    
    This is exploitable **without authentication** only through the public
    `mockerPlugin` / standalone `interceptorPlugin` exports (used by
    third-party dev
    servers), which register the handler on Vite's unauthenticated HMR
    socket.
    Vitest's own browser mode registers mocks over a **token-authenticated**
    RPC and
    is not remotely reachable by default (see Scope).
    
    ##### Affected code
    `packages/mocker/src/node/interceptorPlugin.ts`.
    
    The `load` hook is the file-read sink:
    
    ```ts
    if (mock.type === 'redirect') {
      return readFile(mock.redirect, 'utf-8')
    }
    ```
    
    `mock.redirect` is derived from client input at registration time with
    no
    boundary check:
    
    ```ts
    if (event.type === 'redirect') {
      const redirectUrl = new URL(event.redirect)
      event.redirect = join(server.config.root, redirectUrl.pathname)
    }
    registry.register(event)
    ```
    
    There is no `server.fs.allow` / `server.fs.deny` check and no assertion
    that the
    resolved path stays within the project root.
    
    ##### Registration paths and trust boundaries
    - **Public `mockerPlugin` / `interceptorPlugin` (unauthenticated).** In
    `configureServer`, the plugin registers
    `server.ws.on('vitest:interceptor:register', …)`
    on Vite's HMR WebSocket. That socket performs no token, Origin, or
    same-origin
    check, so any client that can reach it can register a redirect mock.
    This is
      the path the "unauthenticated" impact applies to.
    - **Vitest browser mode (authenticated).** Mocks register over the
    browser RPC
    (`registerMock`), which sits behind a per-run token
    (`isValidApiRequest`, a
    random `api.token`). The interceptor's `configureServer` socket is not
    used for
    registration here (in v5 it does not run at all, as the plugin is
    injected per
    environment). The same missing boundary check exists on the
    authenticated RPC
    path, but reaching it requires the token, so it is not a
    remote-unauthenticated
      read.
    
    ##### Path handling
    `new URL(redirect).pathname` combined with `join(root, pathname)` does
    **not**
    confine reads to the root:
    
    - Special/hierarchical schemes (`file:`, `http:`) are normalized by
    WHATWG URL,
    so `..` segments are collapsed and the result stays under the root.
    Payloads of
      the form `file:///../../etc/passwd` do **not** escape.
    - A non-special (opaque) scheme preserves `..` in `pathname`, so
    `join(root, "../../…/etc/passwd")` resolves outside the root and reads
    an
      arbitrary file.
    
    Even without escaping the root, the missing `server.fs` check allows
    reading any
    in-root file the dev server would otherwise refuse to serve (for example
    an
    in-root `.env` or source that is denied by `server.fs.deny`).
    
    ##### Scope / preconditions
    - This is a **development-server** issue. The dev server binds to
    `localhost` by
    default and is not reachable from the network unless the developer
    exposes it
      (`server.host` / `0.0.0.0`, a LAN bind, or a proxy).
    - A raw (non-browser) client against a reachable server bypasses browser
    origin
    and CORS protections entirely and can both register the mock and read
    the
      response.
    - A browser-based drive-by against a localhost server is substantially
    mitigated
    by Vite defaults: the default CORS origin allowlist is limited to
    `localhost`
    origins, and `server.allowedHosts` blocks DNS-rebinding, so a
    cross-origin page
      cannot read the file contents back.
    
    ##### Impact
    Disclosure of local files readable by the dev-server process (source,
    in-root
    `.env`/secrets, and, via the opaque-scheme payload, files outside the
    project
    root). No integrity or availability impact.
    
    ##### Affected versions
    Present since `@vitest/mocker` was introduced.
    
    - **Affected: `@vitest/mocker` >= 2.1.0** (shipped in `vitest` and
      `@vitest/browser` >= 2.1.0), through 4.1.x and the 5.0.0 pre-releases.
    - **Fixed:** Vitest 4.1.11 and 5.0.0. Older majors (2.1.x, 3.x) are not
      maintained and are not planned to receive the fix.
    
    ##### Fix
    Validate the resolved redirect target against Vite's file-serving
    allowlist
    (`isFileLoadingAllowed`) before registering it, at every registration
    site, and
    stop registering the interceptor WebSocket events in Vitest's browser
    mode
    (mocks there flow through the authenticated RPC).
    
    #### Severity
    - CVSS Score: 5.9 / 10 (Medium)
    - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N`
    
    #### References
    -
    
[https://github.com/vitest-dev/vitest/security/advisories/GHSA-82fw-gwwq-j7x9](https://redirect.github.com/vitest-dev/vitest/security/advisories/GHSA-82fw-gwwq-j7x9)
    -
    
[https://nvd.nist.gov/vuln/detail/CVE-2026-84373](https://nvd.nist.gov/vuln/detail/CVE-2026-84373)
    -
    
[https://github.com/vitest-dev/vitest/pull/10972](https://redirect.github.com/vitest-dev/vitest/pull/10972)
    -
    
[https://github.com/vitest-dev/vitest/pull/10974](https://redirect.github.com/vitest-dev/vitest/pull/10974)
    -
    
[https://github.com/vitest-dev/vitest/commit/51edf2b072902aec6d30c90ebaafd8f121c6f9d8](https://redirect.github.com/vitest-dev/vitest/commit/51edf2b072902aec6d30c90ebaafd8f121c6f9d8)
    -
    
[https://github.com/vitest-dev/vitest/commit/8ff9b9a9efca7c6cfd5243569440de8d7a33aec4](https://redirect.github.com/vitest-dev/vitest/commit/8ff9b9a9efca7c6cfd5243569440de8d7a33aec4)
    -
    
[https://github.com/vitest-dev/vitest/commit/fe5a11d3ceac5ec10d6d7d21a46d4caca132c48f](https://redirect.github.com/vitest-dev/vitest/commit/fe5a11d3ceac5ec10d6d7d21a46d4caca132c48f)
    -
    
[https://github.com/vitest-dev/vitest](https://redirect.github.com/vitest-dev/vitest)
    -
    
[https://github.com/vitest-dev/vitest/releases/tag/v4.1.11](https://redirect.github.com/vitest-dev/vitest/releases/tag/v4.1.11)
    -
    
[https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-rc.2](https://redirect.github.com/vitest-dev/vitest/releases/tag/v5.0.0-rc.2)
    
    This data is provided by
    [OSV](https://osv.dev/vulnerability/GHSA-82fw-gwwq-j7x9) and the [GitHub
    Advisory Database](https://redirect.github.com/github/advisory-database)
    ([CC-BY
    
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
    </details>
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>vitest-dev/vitest (vitest)</summary>
    
    ###
    
[`v4.1.11`](https://redirect.github.com/vitest-dev/vitest/releases/tag/v4.1.11)
    
    [Compare
    
Source](https://redirect.github.com/vitest-dev/vitest/compare/v4.1.10...v4.1.11)
    
    #####    🐞 Bug Fixes
    
    - Revive global concurrency limit for test lifecycle \[backport to v4]
     -  by [@&#8203;sheremet-va](https://redirect.github.com/sheremet-va)
    and [@&#8203;hi-ogawa](https://redirect.github.com/hi-ogawa) in
    [#&#8203;10992](https://redirect.github.com/vitest-dev/vitest/issues/10992)
    
[<samp>(5146d)</samp>](https://redirect.github.com/vitest-dev/vitest/commit/5146df80b)
    - **browser**:
    - Encode iframeId in tester iframe URL \[backport to v4]  -  by
    [@&#8203;sheremet-va](https://redirect.github.com/sheremet-va),
    **Pduhard** and **Claude Opus 4.8** in
    [#&#8203;10955](https://redirect.github.com/vitest-dev/vitest/issues/10955)
    
[<samp>(10b2c)</samp>](https://redirect.github.com/vitest-dev/vitest/commit/10b2cd201)
    - Trigger playwright/chromium gc on lower disk availability \[backport
    to v4]  -  by [@&#8203;hi-ogawa](https://redirect.github.com/hi-ogawa),
    **Hiroshi Ogawa** and **OpenCode** in
    [#&#8203;10951](https://redirect.github.com/vitest-dev/vitest/issues/10951)
    
[<samp>(9851d)</samp>](https://redirect.github.com/vitest-dev/vitest/commit/9851dbc41)
    - **mocker**:
    - Restrict redirect mocks to the fs allowlist \[backport to v4]  -  by
    [@&#8203;sheremet-va](https://redirect.github.com/sheremet-va) in
    [#&#8203;10974](https://redirect.github.com/vitest-dev/vitest/issues/10974)
    
[<samp>(fe5a1)</samp>](https://redirect.github.com/vitest-dev/vitest/commit/fe5a11d3c)
    
    #####     [View changes on
    
GitHub](https://redirect.github.com/vitest-dev/vitest/compare/v4.1.10...v4.1.11)
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (in timezone Etc/UTC)
    
    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Disabled by config. Please merge this manually once you
    are satisfied.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/apache/texera).
    
    
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC42OS4xIiwidXBkYXRlZEluVmVyIjoiNDQuNjkuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwicmVsZWFzZS92MS4yIiwic2VjdXJpdHkiXX0=-->
    
    ---------
    
    Co-authored-by: Meng Wang <[email protected]>
    Co-authored-by: mengw15 <[email protected]>
---
 frontend/package.json |   8 +--
 frontend/yarn.lock    | 156 +++++++++++++++++++++++++-------------------------
 2 files changed, 82 insertions(+), 82 deletions(-)

diff --git a/frontend/package.json b/frontend/package.json
index b0721f2c51..a8c9b3dd6a 100644
--- a/frontend/package.json
+++ b/frontend/package.json
@@ -115,9 +115,9 @@
     "@typescript-eslint/parser": "8.62.1",
     "@typescript-eslint/types": "8.59.0",
     "@typescript-eslint/utils": "8.59.0",
-    "@vitest/browser": "4.1.10",
-    "@vitest/browser-playwright": "4.1.10",
-    "@vitest/coverage-v8": "4.1.10",
+    "@vitest/browser": "4.1.11",
+    "@vitest/browser-playwright": "4.1.11",
+    "@vitest/coverage-v8": "4.1.11",
     "buffer": "5.7.1",
     "build-number-generator": "3.1.0",
     "concurrently": "10.0.3",
@@ -134,7 +134,7 @@
     "sass": "1.71.1",
     "ts-proto": "2.2.0",
     "typescript": "5.9.3",
-    "vitest": "4.1.10"
+    "vitest": "4.1.11"
   },
   "browserslist": [
     "defaults",
diff --git a/frontend/yarn.lock b/frontend/yarn.lock
index d7a767961f..f7a1ed183f 100644
--- a/frontend/yarn.lock
+++ b/frontend/yarn.lock
@@ -6847,47 +6847,47 @@ __metadata:
   languageName: node
   linkType: hard
 
-"@vitest/browser-playwright@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/browser-playwright@npm:4.1.10"
+"@vitest/browser-playwright@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/browser-playwright@npm:4.1.11"
   dependencies:
-    "@vitest/browser": "npm:4.1.10"
-    "@vitest/mocker": "npm:4.1.10"
+    "@vitest/browser": "npm:4.1.11"
+    "@vitest/mocker": "npm:4.1.11"
     tinyrainbow: "npm:^3.1.0"
   peerDependencies:
     playwright: "*"
-    vitest: 4.1.10
+    vitest: 4.1.11
   peerDependenciesMeta:
     playwright:
       optional: false
-  checksum: 
10c0/161530da4da9c061875c0e80c2c94e93658bf92514f2e5173c04299e17a6021feb209ef8fb5e14e880c8c8b2b9e7fc4f3ec7a346c8c4a77831864597331257fc
+  checksum: 
10c0/1275e3b7a0a65700c46e309b3afd8a9d98ef36a8478c10a9ae6cb839963ed4fa661d24fe814ed7c32b09b390cc9045d0db54fc805834830af4a642e72d9e0f76
   languageName: node
   linkType: hard
 
-"@vitest/browser@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/browser@npm:4.1.10"
+"@vitest/browser@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/browser@npm:4.1.11"
   dependencies:
     "@blazediff/core": "npm:1.9.1"
-    "@vitest/mocker": "npm:4.1.10"
-    "@vitest/utils": "npm:4.1.10"
+    "@vitest/mocker": "npm:4.1.11"
+    "@vitest/utils": "npm:4.1.11"
     magic-string: "npm:^0.30.21"
     pngjs: "npm:^7.0.0"
     sirv: "npm:^3.0.2"
     tinyrainbow: "npm:^3.1.0"
     ws: "npm:^8.19.0"
   peerDependencies:
-    vitest: 4.1.10
-  checksum: 
10c0/61c86b8c0fcc78bd01de559914525e768dc16d565ee8a40a41d51ef6d99595c3c5e976defe32d090b3dda5f77a980caa11a2072e9c4d279cfb8d55d31c565fc7
+    vitest: 4.1.11
+  checksum: 
10c0/a16b95d043650e82e0706131454d259e660e11fca01d2ce9e336320a482626b2175051e12a93ea18efaf9a794f6cce221919fe59fe27fba04bd9f0e253e6957e
   languageName: node
   linkType: hard
 
-"@vitest/coverage-v8@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/coverage-v8@npm:4.1.10"
+"@vitest/coverage-v8@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/coverage-v8@npm:4.1.11"
   dependencies:
     "@bcoe/v8-coverage": "npm:^1.0.2"
-    "@vitest/utils": "npm:4.1.10"
+    "@vitest/utils": "npm:4.1.11"
     ast-v8-to-istanbul: "npm:^1.0.0"
     istanbul-lib-coverage: "npm:^3.2.2"
     istanbul-lib-report: "npm:^3.0.1"
@@ -6897,34 +6897,34 @@ __metadata:
     std-env: "npm:^4.0.0-rc.1"
     tinyrainbow: "npm:^3.1.0"
   peerDependencies:
-    "@vitest/browser": 4.1.10
-    vitest: 4.1.10
+    "@vitest/browser": 4.1.11
+    vitest: 4.1.11
   peerDependenciesMeta:
     "@vitest/browser":
       optional: true
-  checksum: 
10c0/f607ab5610ba93ff586d1680bc6d574ee42606ddafd33d5dca14d568e1ff110bf7aea0c82d87b69003b10604d78ccdb535948704e26bbdbfdda6b27edf524486
+  checksum: 
10c0/91127fd40f445b506cc661c54e26defd75d970fa1983cb83442856dd7f295542f0378e0bca847036a7a5be871b3b17c27167d21f277e47368cf7409eafaa1b40
   languageName: node
   linkType: hard
 
-"@vitest/expect@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/expect@npm:4.1.10"
+"@vitest/expect@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/expect@npm:4.1.11"
   dependencies:
     "@standard-schema/spec": "npm:^1.1.0"
     "@types/chai": "npm:^5.2.2"
-    "@vitest/spy": "npm:4.1.10"
-    "@vitest/utils": "npm:4.1.10"
+    "@vitest/spy": "npm:4.1.11"
+    "@vitest/utils": "npm:4.1.11"
     chai: "npm:^6.2.2"
     tinyrainbow: "npm:^3.1.0"
-  checksum: 
10c0/a817ad0d9bd6a039776a7228d54fb8319c17e4af15917407f5566ac61781a8511f591d302519d6999217399915bc3c0290028189fc73f5c38f80cb01b6f19c8d
+  checksum: 
10c0/0aa5e0973aca93a58cbdc3041c6bfed5897e976124965203b96a23b811f4ca403590c7eb15802c8d8366ec27a1db0682451e8a91c4d06617636de262baf86e4b
   languageName: node
   linkType: hard
 
-"@vitest/mocker@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/mocker@npm:4.1.10"
+"@vitest/mocker@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/mocker@npm:4.1.11"
   dependencies:
-    "@vitest/spy": "npm:4.1.10"
+    "@vitest/spy": "npm:4.1.11"
     estree-walker: "npm:^3.0.3"
     magic-string: "npm:^0.30.21"
   peerDependencies:
@@ -6935,56 +6935,56 @@ __metadata:
       optional: true
     vite:
       optional: true
-  checksum: 
10c0/4aa70b0df58681652e2e28093437fb2e8f4d02a6d03f5619abc266ac1c5ae5f43326148061d13ae6e071e0f6cfcf7634659af63644de8ce098a7c98949a3d1ad
+  checksum: 
10c0/3111ea34bd5046f6c70bbd67cf8b89608ee8c41cb27ab2bd61d42f4b68810e9ea16a9a757a71bc254c105f73b407d00ebb6bab1ab0f7f5cdcc9d7d16602a3933
   languageName: node
   linkType: hard
 
-"@vitest/pretty-format@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/pretty-format@npm:4.1.10"
+"@vitest/pretty-format@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/pretty-format@npm:4.1.11"
   dependencies:
     tinyrainbow: "npm:^3.1.0"
-  checksum: 
10c0/1a5daba730ffe23f2000bff484b4b2842f3b178d93663cb487b215516b8d3b62caa3e2bb2a3c63307b61a9fe58fb9bfff38559bc0c5e49d8aa403d6803a1d918
+  checksum: 
10c0/ad32525c73807c0b72f38dc29bc51fd5a17879dc650f37995a9c5adbb8526e15f787691f76aa8768448ec7ed5bf5ba2b12329eac8fda1428b4d6b8c036390f71
   languageName: node
   linkType: hard
 
-"@vitest/runner@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/runner@npm:4.1.10"
+"@vitest/runner@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/runner@npm:4.1.11"
   dependencies:
-    "@vitest/utils": "npm:4.1.10"
+    "@vitest/utils": "npm:4.1.11"
     pathe: "npm:^2.0.3"
-  checksum: 
10c0/554b72639de9694271b99be8ae273fe12ec793093ec91cce143816cd1187d40b7138a4d9d4de4f456cfca9567de986825bff97e107c05b9eb4abc130e854286d
+  checksum: 
10c0/3c782b055e9e688e1785f7c8937bd1669bad1b0e5758cb8b844f918f30a324b1d21e174d46c941ce80ebf37f2b89b55b6d619a675025914a1ece6377b95909e2
   languageName: node
   linkType: hard
 
-"@vitest/snapshot@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/snapshot@npm:4.1.10"
+"@vitest/snapshot@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/snapshot@npm:4.1.11"
   dependencies:
-    "@vitest/pretty-format": "npm:4.1.10"
-    "@vitest/utils": "npm:4.1.10"
+    "@vitest/pretty-format": "npm:4.1.11"
+    "@vitest/utils": "npm:4.1.11"
     magic-string: "npm:^0.30.21"
     pathe: "npm:^2.0.3"
-  checksum: 
10c0/e71398725f51af5fd0c07bb4b957d0f987daf9b4c564ac24cb2a4d1afde1a6939f535ac17761a32dcc41b0a1e6d4088af66dc44df89fdebebb92aabed1a92b5f
+  checksum: 
10c0/35d82a7c2a3e4b57529c30387d568d9106b6bf960189214e5d8cb1f5288cb042305c2e5c7b0b2f8cb56a2c814973de0310bc56d72deb79427bea272b6224190c
   languageName: node
   linkType: hard
 
-"@vitest/spy@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/spy@npm:4.1.10"
-  checksum: 
10c0/e5c08012560af6727fd66741c5cda25560d7c5442103d0c83e4276a9b0dd90b9da6cdf823a461195229a16c6ff87768ce788a68d0fa29dea73ee285618668178
+"@vitest/spy@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/spy@npm:4.1.11"
+  checksum: 
10c0/06c68247a8efd21006abe7532fee17f30ba83c8cda3e0b952ef89e278d58058f4b1de69b6bbaa2ed614c568bf4f5769fcc76be42802dedf2bcdd9c0aae601740
   languageName: node
   linkType: hard
 
-"@vitest/utils@npm:4.1.10":
-  version: 4.1.10
-  resolution: "@vitest/utils@npm:4.1.10"
+"@vitest/utils@npm:4.1.11":
+  version: 4.1.11
+  resolution: "@vitest/utils@npm:4.1.11"
   dependencies:
-    "@vitest/pretty-format": "npm:4.1.10"
+    "@vitest/pretty-format": "npm:4.1.11"
     convert-source-map: "npm:^2.0.0"
     tinyrainbow: "npm:^3.1.0"
-  checksum: 
10c0/05b0ecec6997ec22fc08377e57dbd8fa37992e05961f3a7a916d98b1ab56d15c2a87dbd83d392b628242bdc156b1705e7fa60a3bf0c54bdb51158c153e05fc5d
+  checksum: 
10c0/a2c1ddc64333458c3e031465c1ee0440a7660fd1b298c54ccbf865ef1e5cf3ebdd6c5c75a5ea235d8a672498b394e7121f992b096f021f45014ab25e9abd1b52
   languageName: node
   linkType: hard
 
@@ -10753,9 +10753,9 @@ __metadata:
     "@typescript-eslint/parser": "npm:8.62.1"
     "@typescript-eslint/types": "npm:8.59.0"
     "@typescript-eslint/utils": "npm:8.59.0"
-    "@vitest/browser": "npm:4.1.10"
-    "@vitest/browser-playwright": "npm:4.1.10"
-    "@vitest/coverage-v8": "npm:4.1.10"
+    "@vitest/browser": "npm:4.1.11"
+    "@vitest/browser-playwright": "npm:4.1.11"
+    "@vitest/coverage-v8": "npm:4.1.11"
     ai: "npm:5.0.93"
     ajv: "npm:8.18.0"
     buffer: "npm:5.7.1"
@@ -10803,7 +10803,7 @@ __metadata:
     tslib: "npm:2.3.1"
     typescript: "npm:5.9.3"
     uuid: "npm:14.0.1"
-    vitest: "npm:4.1.10"
+    vitest: "npm:4.1.11"
     y-monaco: "npm:0.1.6"
     y-protocols: "npm:1.0.7"
     y-quill: "npm:1.0.0"
@@ -17491,17 +17491,17 @@ __metadata:
   languageName: node
   linkType: hard
 
-"vitest@npm:4.1.10":
-  version: 4.1.10
-  resolution: "vitest@npm:4.1.10"
-  dependencies:
-    "@vitest/expect": "npm:4.1.10"
-    "@vitest/mocker": "npm:4.1.10"
-    "@vitest/pretty-format": "npm:4.1.10"
-    "@vitest/runner": "npm:4.1.10"
-    "@vitest/snapshot": "npm:4.1.10"
-    "@vitest/spy": "npm:4.1.10"
-    "@vitest/utils": "npm:4.1.10"
+"vitest@npm:4.1.11":
+  version: 4.1.11
+  resolution: "vitest@npm:4.1.11"
+  dependencies:
+    "@vitest/expect": "npm:4.1.11"
+    "@vitest/mocker": "npm:4.1.11"
+    "@vitest/pretty-format": "npm:4.1.11"
+    "@vitest/runner": "npm:4.1.11"
+    "@vitest/snapshot": "npm:4.1.11"
+    "@vitest/spy": "npm:4.1.11"
+    "@vitest/utils": "npm:4.1.11"
     es-module-lexer: "npm:^2.0.0"
     expect-type: "npm:^1.3.0"
     magic-string: "npm:^0.30.21"
@@ -17519,12 +17519,12 @@ __metadata:
     "@edge-runtime/vm": "*"
     "@opentelemetry/api": ^1.9.0
     "@types/node": ^20.0.0 || ^22.0.0 || >=24.0.0
-    "@vitest/browser-playwright": 4.1.10
-    "@vitest/browser-preview": 4.1.10
-    "@vitest/browser-webdriverio": 4.1.10
-    "@vitest/coverage-istanbul": 4.1.10
-    "@vitest/coverage-v8": 4.1.10
-    "@vitest/ui": 4.1.10
+    "@vitest/browser-playwright": 4.1.11
+    "@vitest/browser-preview": 4.1.11
+    "@vitest/browser-webdriverio": 4.1.11
+    "@vitest/coverage-istanbul": 4.1.11
+    "@vitest/coverage-v8": 4.1.11
+    "@vitest/ui": 4.1.11
     happy-dom: "*"
     jsdom: "*"
     vite: ^6.0.0 || ^7.0.0 || ^8.0.0
@@ -17555,7 +17555,7 @@ __metadata:
       optional: false
   bin:
     vitest: ./vitest.mjs
-  checksum: 
10c0/ff07294a57f9c62f3b503f7cf88a52ee0753ed26389a49cda430387a3898f39d80af47180b0af19e27acab5bd11ae95706bd4b44ce8befc97d3ae49af6ca4fc1
+  checksum: 
10c0/3fa0948cf74adcccc8cbcdb4e6d30ada6933bdfb1816ff99200f3d3b689325b37dc483b22535b57b6d911f7a7b64eaa6a5f8da1606cfe7f2466f48000c21e296
   languageName: node
   linkType: hard
 

Reply via email to