Skip to content

fix(cli): default unpinned npm to Node's bundled version - #2742

Merged
fengmk2 merged 10 commits into
voidzero-dev:mainfrom
liangmiQwQ:liang/codex/fix-bundled-npm-default
Sep 19, 2026
Merged

fengmk2 merged 10 commits into
voidzero-dev:mainfrom
liangmiQwQ:liang/codex/fix-bundled-npm-default

Conversation

@liangmiQwQ

@liangmiQwQ liangmiQwQ commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Close #2726

An npm lockfile now selects npm without requesting its latest release. When no npm version is pinned or configured as the default, vp commands and npm/npx shims use the npm bundled with the selected Node.js runtime. Explicit npm versions and configured defaults keep their precedence.

Direct shims and vp commands share default-version resolution after selecting the package-manager family, while keeping their independent environment overrides.

vp env current reports the bundled npm version and source. Explicit standalone installation with vp env install npm keeps its registry fallback.

🤖 Generated with Codex

@liangmiQwQ

This comment was marked as outdated.

1 similar comment
@liangmiQwQ

This comment was marked as outdated.

@liangmiQwQ
liangmiQwQ marked this pull request as ready for review September 18, 2026 14:51
@voidzero-dev voidzero-dev deleted a comment from fengmk2 Sep 18, 2026
@Brooooooklyn

Copy link
Copy Markdown
Member

@codex review

@liangmiQwQ

Copy link
Copy Markdown
Collaborator Author

Codex review seems broken.

@fengmk2

fengmk2 commented Sep 19, 2026

Copy link
Copy Markdown
Member

I try to use codex app review from now on.

Comment thread crates/vp_global_cli/src/commands/env/current.rs Outdated
Comment thread crates/vp_pm_cli/src/package_manager.rs Outdated
Comment thread crates/vp_pm_cli/src/package_manager.rs
Comment thread crates/vp_pm_cli/src/package_manager.rs
@liangmiQwQ
liangmiQwQ marked this pull request as draft September 19, 2026 02:36
@liangmiQwQ
liangmiQwQ marked this pull request as ready for review September 19, 2026 05:13
@liangmiQwQ
liangmiQwQ requested a review from fengmk2 September 19, 2026 05:13
Comment thread crates/vp_global_cli/src/commands/env/mod.rs
@fengmk2
fengmk2 merged commit d239360 into voidzero-dev:main Sep 19, 2026
78 checks passed
@liangmiQwQ
liangmiQwQ deleted the liang/codex/fix-bundled-npm-default branch September 19, 2026 05:36
fengmk2 pushed a commit that referenced this pull request Sep 19, 2026
After #2742, `vp migrate` fails in npm projects with only a package-lock
because the internal `bundled` marker reaches package-manager version
resolution, which treats it as a semver range. This broke the decoders
Ecosystem CI job.

Package-manager detection now returns `default` for every manager
inferred from lockfiles or configuration, leaving version policy to the
shared resolver. It resolves npm's default from the prepared PATH and
pnpm/yarn/bun defaults from the registry's latest release. Explicit
versions and explicit `latest` requests keep their existing behavior.

🤖 Generated with Codex
fengmk2 added a commit that referenced this pull request Sep 22, 2026
…2780)

Vite+ now uses Vitest 5, and `vp migrate` helps Vitest 4 projects adopt
the new APIs and defaults. Standalone installs and upgrades now require
verified npm provenance for release binaries.

### Breaking Changes

#### Vitest 5

`vp test` and the public `vite-plus/test*` exports now use
`vitest@5.0.1`
([#2551](#2551)), by
@fengmk2.

| Area | Old | New |
| --- | --- | --- |
| Test runner | `vitest@4.1.11` | `vitest@5.0.1` |
| CLI Node.js range | `^20.19.0 \|\| ^22.18.0 \|\| >=24.11.0` |
`^22.18.0 \|\| ^24.11.0 \|\| >=26.0.0` |
| `vite-plus/test/runners` and `vite-plus/test/suite` | Vite+
compatibility exports | Use supported APIs from `vite-plus/test`; review
unsupported runner and expect plugins |
| `vite-plus/test/browser-webdriverio` | Bundled export | Use the
community `@vitest/browser-webdriverio` package |

Run `vp migrate` from the workspace root before you install the new
dependencies. The migrator updates supported config, source, benchmark,
command, and import changes. It reports manual work as `BLOCK` or
`REVIEW` items. See the [Vitest 5 migration
guide](https://viteplus.dev/guide/vitest-v5) for the full process.
Projects can stay on the prior release until their runtimes and tests
are ready.

#### `vp staged` runtime requirements

`vp staged` now uses `lint-staged@17.5.1`
([#2754](#2754)), by
@fengmk2.

| Requirement | Old | New |
| --- | --- | --- |
| Node.js for `vp staged` | The Vite+ CLI runtime range | `^22.22.1 \|\|
^24.11.0 \|\| >=26.0.0` |
| Git | No separate documented minimum | `>=2.32.0` |

Update Node.js and Git on developer machines and CI runners that execute
`vp staged` or its pre-commit hook. Other workflows do not use these
extra requirements.

### Highlights

- Standalone installers, `vp upgrade`, and `vp-setup.exe` now reject
release binaries without supported SLSA provenance
([#2440](#2440)), by
@kazupon.
- Installers now show progress and the exact shell activation command.
Download progress preserves earlier terminal output
([#2744](#2744),
[#2741](#2741)), by
@fengmk2.
- System-first runtime and package-manager shims now use a fallback
directory at the end of `PATH`. Setup restores missing package-manager
preferences
([#2758](#2758),
[#2763](#2763)), by
@liangmiQwQ and @fengmk2.
- `vp run` now finishes when background processes remain. Large file
traces run without caching instead of killing the task
([#2767](#2767),
[vite-task#675](voidzero-dev/vite-task#675)), by
@wan9chi.

### Features

- `vp add` now supports shared install options such as `--offline`,
`--frozen-lockfile`, and `--lockfile-only`
([#2722](#2722)), by
@jong-kyung.
- `vp pm patch` and `vp pm patch-commit` now use the native commands in
npm 12 and later
([#2736](#2736)), by
@jong-kyung.
- `vp rebuild` now supports Yarn Berry and forwards package names and
extra arguments
([#2761](#2761)), by
@jong-kyung.
- The bundled tools update `oxlint` `1.83.0` -> `1.85.0`,
`oxlint-tsgolint` `7.0.2001` -> `7.0.2002`, and `oxfmt` `0.68.0` ->
`0.70.0` ([#2745](#2745),
[#2773](#2773),
[#2778](#2778)), by
@voidzero-guard[bot]. These versions can flag or format code that passed
before. Run `vp fmt` after upgrading if CI runs `vp check`.

### Fixes & Enhancements

- `oxlint` and `oxfmt` no longer expose bin wrappers that conflict with
upstream packages. Editors must use `vp lint --lsp`, `vp fmt --lsp`, or
`vp fmt --stdin-filepath`
([#2672](#2672)), by
@fengmk2.
- `vp create vite:generator` now replaces catalog references for package
managers that do not support catalogs
([#2720](#2720)), by
@SaKaNa-Y.
- Unpinned npm projects now use the npm version bundled with the
selected Node.js runtime. The same policy works during migration
([#2742](#2742),
[#2748](#2748)), by
@liangmiQwQ.
- The CLI now loads its local versions module through a file URL,
including on Windows paths
([#2749](#2749)), by
@YanChenBai.
- Package-manager commands now use pnpm when the project has no detected
package manager
([#2750](#2750)), by
@liangmiQwQ.
- `vp migrate` now removes unused `@oxlint/plugins` dependencies after
it rewrites plugin imports
([#2751](#2751)), by
@fengmk2.
- `vp update --no-save` now warns that Yarn Classic and Yarn Berry do
not support the option
([#2762](#2762)), by
@jong-kyung.
- `vp migrate` now explains its `tsdown@0.23` compatibility settings and
links to removal guidance
([#2769](#2769)), by
@fengmk2.
- Environment setup now installs and diagnoses the official `pn` and
`pnx` aliases for pnpm
([#2770](#2770)), by
@iruoy.
- Cached tasks now receive GitHub Actions OIDC variables, so npm Trusted
Publishing works through `vp run`
([vite-task#691](voidzero-dev/vite-task#691)),
by @naokihaba.
- Automatic task input tracking now records file access from signal
handlers
([vite-task#687](voidzero-dev/vite-task#687)),
by @wan9chi.

### Refactor

- `vp lint`, `vp fmt`, and `vp check` now use native config discovery.
Package commands keep matching workspace-root settings, while explicit
config flags take precedence
([#2731](#2731)), by
@fengmk2.

### Chore

- Generated workflows and `vp migrate` now use `setup-vp@v1.21.1`,
including its installation fixes
([#2760](#2760),
[#2772](#2772)), by
@renovate[bot] and @fengmk2.

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| vite | `8.3.0` |
[`434e8e9`](vitejs/vite@434e8e9)
|
| rolldown | `1.2.9` |
[`5b4746e`](rolldown/rolldown@5b4746e)
|
| tsdown | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) |
| vitest | `5.0.1` | [npm](https://npmx.dev/package/vitest/v/5.0.1) |
| oxlint | `1.85.0` | [npm](https://npmx.dev/package/oxlint/v/1.85.0) |
| oxlint-tsgolint | `7.0.2002` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2002) |
| oxfmt | `0.70.0` | [npm](https://npmx.dev/package/oxfmt/v/0.70.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@YanChenBai, @iruoy

**Full Changelog**:
v0.3.3...v1.0.0-rc.0

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Use the npm version bundled with node

3 participants