From aeb4b73dd560a822a7ec4873cb624f5faaae359c Mon Sep 17 00:00:00 2001 From: JongKyung Lee Date: Fri, 21 Aug 2026 00:54:29 +0900 Subject: [PATCH 1/2] test(cli): redact bun build hash in snapshots bun banners append the build's short commit hash after the version ("bun pm trust v1.4.0 (34cbb9a40)"), and the hash changes with every bun release. The version was already masked, but the hash was recorded verbatim, so snapshots of fixtures that follow the latest bun broke whenever bun shipped a release, as create_approve_builds_bun did when bun 1.4.0 came out. Mask the hash as , anchored on the already-masked token so parenthesized hex elsewhere stays assertable, and re-record the eight bun snapshots that embedded a hash. A full-suite re-record confirmed no other snapshot is affected. --- .../command_add_bun/snapshots/command_add_bun.md | 8 ++++---- .../command_list_bun/snapshots/command_list_bun.md | 2 +- .../snapshots/command_outdated_bun.md | 6 +++--- .../snapshots/command_pm_approve_builds_bun.md | 2 +- .../snapshots/command_remove_bun.md | 12 ++++++------ .../snapshots/command_update_bun.md | 4 ++-- .../command_why_bun/snapshots/command_why_bun.md | 2 +- .../snapshots/create_approve_builds_bun.md | 2 +- .../vp_cli_snapshots/tests/cli_snapshots/redact.rs | 10 ++++++++++ crates/vp_cli_snapshots/tests/redact_unit.rs | 11 +++++++++++ 10 files changed, 40 insertions(+), 19 deletions(-) diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_add_bun/snapshots/command_add_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_add_bun/snapshots/command_add_bun.md index 5a2087b241..1aba1cd24b 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_add_bun/snapshots/command_add_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_add_bun/snapshots/command_add_bun.md @@ -55,7 +55,7 @@ For more information, try '--help'. should add package as dev dependencies ``` -bun add (af24e281) +bun add () installed testnpm2@1.0.1 @@ -80,7 +80,7 @@ installed testnpm2@1.0.1 should add packages to dependencies ``` -bun add (af24e281) +bun add () installed testnpm2@1.0.1 installed test-vite-plus-install@1.0.0 @@ -111,7 +111,7 @@ should install package alias for add ``` VITE+ - The Unified Toolchain for the Web -bun add (af24e281) +bun add () installed test-vite-plus-package@1.0.0 @@ -142,7 +142,7 @@ installed test-vite-plus-package@1.0.0 should add package as optional dependencies ``` -bun add (af24e281) +bun add () installed test-vite-plus-package-optional@1.0.0 diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_list_bun/snapshots/command_list_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_list_bun/snapshots/command_list_bun.md index a59bb79636..8b007b85dd 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_list_bun/snapshots/command_list_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_list_bun/snapshots/command_list_bun.md @@ -7,7 +7,7 @@ should install packages first ``` VITE+ - The Unified Toolchain for the Web -bun install (af24e281) +bun install () test-vite-plus-package@1.0.0 test-vite-plus-package-optional@1.0.0 diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_outdated_bun/snapshots/command_outdated_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_outdated_bun/snapshots/command_outdated_bun.md index 747dd1264c..567f340b76 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_outdated_bun/snapshots/command_outdated_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_outdated_bun/snapshots/command_outdated_bun.md @@ -40,7 +40,7 @@ should install packages first ``` VITE+ - The Unified Toolchain for the Web -bun install (af24e281) +bun install () test-vite-plus-top-package@1.0.0 ( available) test-vite-plus-other-optional@1.0.0 ( available) @@ -54,7 +54,7 @@ bun install (af24e281) should show outdated package ``` -bun outdated (af24e281) +bun outdated () ┌──────────┬─────────┬────────┬────────┐ │ Package │ Current │ Update │ Latest │ ├──────────┼─────────┼────────┼────────┤ @@ -67,7 +67,7 @@ bun outdated (af24e281) should support recursive output ``` -bun outdated (af24e281) +bun outdated () ┌──────────────────────────────────────────┬─────────┬────────┬────────┬──────────────────────┐ │ Package │ Current │ Update │ Latest │ Workspace │ ├──────────────────────────────────────────┼─────────┼────────┼────────┼──────────────────────┤ diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_pm_approve_builds_bun/snapshots/command_pm_approve_builds_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_pm_approve_builds_bun/snapshots/command_pm_approve_builds_bun.md index 5184ea0a2b..cf713612be 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_pm_approve_builds_bun/snapshots/command_pm_approve_builds_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_pm_approve_builds_bun/snapshots/command_pm_approve_builds_bun.md @@ -45,6 +45,6 @@ forwards bun pm trust --all (errors on empty project — no lockfile) **Exit code:** 1 ``` -bun pm trust (af24e281) +bun pm trust () error: Lockfile not found ``` diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_remove_bun/snapshots/command_remove_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_remove_bun/snapshots/command_remove_bun.md index 9ecfa64fc1..cce8eb5047 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_remove_bun/snapshots/command_remove_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_remove_bun/snapshots/command_remove_bun.md @@ -49,7 +49,7 @@ For more information, try '--help'. should error when remove not exists package from dev dependencies ``` -bun remove (af24e281) +bun remove () package.json doesn't have dependencies, there's nothing to remove! ``` @@ -68,7 +68,7 @@ package.json doesn't have dependencies, there's nothing to remove! should add packages to dependencies ``` -bun add (af24e281) +bun add () installed testnpm2@1.0.1 @@ -78,7 +78,7 @@ installed testnpm2@1.0.1 ## `vp add -D test-vite-plus-install` ``` -bun add (af24e281) +bun add () installed test-vite-plus-install@1.0.0 @@ -88,7 +88,7 @@ installed test-vite-plus-install@1.0.0 ## `vp add -O test-vite-plus-package-optional` ``` -bun add (af24e281) +bun add () installed test-vite-plus-package-optional@1.0.0 @@ -119,7 +119,7 @@ installed test-vite-plus-package-optional@1.0.0 should remove packages from dependencies ``` -bun remove (af24e281) +bun remove () - testnpm2 - test-vite-plus-install @@ -144,7 +144,7 @@ bun remove (af24e281) should remove package from optional dependencies ``` -bun remove (af24e281) +bun remove () package.json has no dependencies! Deleted empty lockfile diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_update_bun/snapshots/command_update_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_update_bun/snapshots/command_update_bun.md index 4b733b6256..a6477b323a 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_update_bun/snapshots/command_update_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_update_bun/snapshots/command_update_bun.md @@ -40,7 +40,7 @@ Documentation: https://viteplus.dev/guide/install should update package within semver range ``` -bun update (af24e281) +bun update () test-vite-plus-package@1.0.0 test-vite-plus-package-optional@1.0.0 @@ -74,7 +74,7 @@ installed testnpm2@1.0.1 should update to absolute latest version ``` -bun update (af24e281) +bun update () installed testnpm2@1.0.1 diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_why_bun/snapshots/command_why_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_why_bun/snapshots/command_why_bun.md index d212533fda..657cbda28b 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_why_bun/snapshots/command_why_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/command_why_bun/snapshots/command_why_bun.md @@ -40,7 +40,7 @@ should install packages first ``` VITE+ - The Unified Toolchain for the Web -bun install (af24e281) +bun install () test-vite-plus-package@1.0.0 test-vite-plus-package-optional@1.0.0 diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/create_approve_builds_bun/snapshots/create_approve_builds_bun.md b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/create_approve_builds_bun/snapshots/create_approve_builds_bun.md index 1827b2bc1d..af130828a1 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/create_approve_builds_bun/snapshots/create_approve_builds_bun.md +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/fixtures/create_approve_builds_bun/snapshots/create_approve_builds_bun.md @@ -98,7 +98,7 @@ no trustedDependencies, the build was not run the guidance's `vp pm approve-builds` command approves the gated build ``` -bun pm trust (0d9b296a) +bun pm trust () ./node_modules/core-js @3.39.0 ✓ [postinstall]: node -e "try{require('./postinstall')}catch(e){}" diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs b/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs index a678df60fd..d0a2683278 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs @@ -49,6 +49,12 @@ static TOOL_VERSION_RE: LazyLock = LazyLock::new(|| { ) .unwrap() }); +// bun banners append the build's short commit hash after the version +// ("bun pm trust v1.4.0 (34cbb9a40)"), which changes with every bun release. +// The version is already masked to `` by the passes above; anchor on +// that token so parenthesized hex elsewhere stays assertable. +static BUN_BUILD_HASH_RE: LazyLock = + LazyLock::new(|| regex::Regex::new(r"( )\([0-9a-f]{6,12}\)").unwrap()); // The workspace's own vite-plus / @voidzero-dev/vite-plus-core version is // written verbatim into scaffolded catalogs and manifests (`vite-plus: 0.2.3`, // `"vite-plus": "0.2.3"`, `npm:@voidzero-dev/vite-plus-core@0.2.3`). Unlike @@ -429,6 +435,10 @@ pub fn redact_output( // Redact bare runtime-tool versions by name context (see TOOL_VERSION_RE) output = TOOL_VERSION_RE.replace_all(&output, "$1$2").into_owned(); + // Redact bun's build hash next to an already-masked version + // (see BUN_BUILD_HASH_RE), which changes with every bun release. + output = BUN_BUILD_HASH_RE.replace_all(&output, "$1()").into_owned(); + // Redact the workspace's own vite-plus/core version by package context // (see VP_VERSION_RE), which bumps on every release. output = VP_VERSION_RE.replace_all(&output, "${1}").into_owned(); diff --git a/crates/vp_cli_snapshots/tests/redact_unit.rs b/crates/vp_cli_snapshots/tests/redact_unit.rs index 10a3ff1575..dedaf81dc7 100644 --- a/crates/vp_cli_snapshots/tests/redact_unit.rs +++ b/crates/vp_cli_snapshots/tests/redact_unit.rs @@ -76,6 +76,17 @@ fn masks_bare_runtime_tool_versions_by_name_context() { ); } +#[test] +fn masks_bun_build_hash_after_masked_version() { + // bun banners append the build's short commit hash after the version, + // which changes with every bun release. + let input = "bun pm trust v1.4.0 (34cbb9a40)\n".to_owned(); + assert_eq!(redact_output(input, &[], true), "bun pm trust ()\n"); + // Parenthesized hex without a preceding masked version stays verbatim. + let unrelated = "commit (deadbeef1) applied\n".to_owned(); + assert_eq!(redact_output(unrelated.clone(), &[], true), unrelated); +} + #[test] fn masks_managed_node_versions_in_environment_output() { let input = concat!( From 4620ed051d50a4cf91613cd716b70fb3e3bf8645 Mon Sep 17 00:00:00 2001 From: JongKyung Lee Date: Fri, 21 Aug 2026 01:04:28 +0900 Subject: [PATCH 2/2] test(cli): require bun banner context for build hash redaction Anchoring only on the masked version token would also mask a version-plus-hash line printed by any other tool; require the leading bun subcommand context so those stay assertable. --- crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs | 10 ++++++---- crates/vp_cli_snapshots/tests/redact_unit.rs | 2 +- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs b/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs index d0a2683278..9cdf1b6034 100644 --- a/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs +++ b/crates/vp_cli_snapshots/tests/cli_snapshots/redact.rs @@ -51,10 +51,12 @@ static TOOL_VERSION_RE: LazyLock = LazyLock::new(|| { }); // bun banners append the build's short commit hash after the version // ("bun pm trust v1.4.0 (34cbb9a40)"), which changes with every bun release. -// The version is already masked to `` by the passes above; anchor on -// that token so parenthesized hex elsewhere stays assertable. -static BUN_BUILD_HASH_RE: LazyLock = - LazyLock::new(|| regex::Regex::new(r"( )\([0-9a-f]{6,12}\)").unwrap()); +// The version is already masked to `` by the passes above; require +// the leading `bun ` context so version-plus-hash lines from +// other tools stay assertable. +static BUN_BUILD_HASH_RE: LazyLock = LazyLock::new(|| { + regex::Regex::new(r"(\bbun(?: [a-z-]+)* )\([0-9a-f]{6,12}\)").unwrap() +}); // The workspace's own vite-plus / @voidzero-dev/vite-plus-core version is // written verbatim into scaffolded catalogs and manifests (`vite-plus: 0.2.3`, // `"vite-plus": "0.2.3"`, `npm:@voidzero-dev/vite-plus-core@0.2.3`). Unlike diff --git a/crates/vp_cli_snapshots/tests/redact_unit.rs b/crates/vp_cli_snapshots/tests/redact_unit.rs index dedaf81dc7..c67c707599 100644 --- a/crates/vp_cli_snapshots/tests/redact_unit.rs +++ b/crates/vp_cli_snapshots/tests/redact_unit.rs @@ -77,7 +77,7 @@ fn masks_bare_runtime_tool_versions_by_name_context() { } #[test] -fn masks_bun_build_hash_after_masked_version() { +fn masks_bun_build_hash_only_in_bun_banners() { // bun banners append the build's short commit hash after the version, // which changes with every bun release. let input = "bun pm trust v1.4.0 (34cbb9a40)\n".to_owned();