fix(deps): bump the minorandpatch group with 8 updates - #1862
Conversation
@types/node 26.4.0, lint-staged 17.4.1, nx 23.1.2, vue 3.5.42, zod 4.5.1, @vue/test-utils 2.5.0, happy-dom 20.11.13, vue-router 5.3.0. Excludes tar-stream 3.2.0 -> 3.2.1 from the group. It is a types-only release — `npm diff` against 3.2.0 lists exactly package.json and a new index.d.ts, and the runtime JS is byte-identical — so it offers nothing at runtime, while its bundled declarations shadow @types/tar-stream and model tar-stream on `streamx` instead of node:stream. Taking it costs five structural assertions in production code, two of which claim a streamx stream satisfies NodeJS.ReadableStream when it genuinely lacks isPaused, unpipe and wrap. The new declarations also regress on Header.type: 8 required non-nullable literals, where headers.js toType() additionally returns 'pax-header', 'pax-global-header', 'gnu-long-link-path', 'gnu-long-path' and null. The DefinitelyTyped model had all 13. No pin, override or dependabot ignore: the manifests keep ^3.2.0 and the lock keeps 3.2.0, which npm ci and npm install both respect. Revisit when upstream's declarations describe their own runtime.
|
Warning Review limit reachedNext included review available in 17 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Team Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (13)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Updates a curated set of minor/patch dependencies across the monorepo while intentionally not taking the tar-stream 3.2.1 types-only release that previously broke builds due to Node stream vs streamx type incompatibilities.
Changes:
- Bump
zodto^4.5.1across apps and kits. - Bump tooling/framework deps:
@types/node→ 26.4.0,lint-staged→ 17.4.1,nx→ 23.1.2,vue→ 3.5.42,@vue/test-utils→ 2.5.0,happy-dom→ 20.11.13,vue-router→ 5.3.0. - Refresh
package-lock.jsonto reflect the above updates while keepingtar-streamresolved at 3.2.0.
Reviewed changes
Copilot reviewed 13 out of 14 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| packages/telemetry-kit/package.json | Bumps zod dependency. |
| packages/storage-kit/package.json | Bumps zod dependency. |
| packages/messenger-kit/package.json | Bumps zod dependency. |
| packages/core-kit/package.json | Bumps zod dependency. |
| packages/client-vue/package.json | Updates Vue ecosystem/test deps (vue, vue-router, @vue/test-utils, happy-dom) plus @types/node and zod. |
| package.json | Updates root dev tooling deps (@types/node, lint-staged, nx). |
| package-lock.json | Lockfile refresh for the selected dependency bumps (while retaining tar-stream 3.2.0). |
| docs/package.json | Bumps vue used by VitePress docs site. |
| apps/server-telemetry/package.json | Bumps zod dependency. |
| apps/server-storage/package.json | Bumps zod dependency. |
| apps/server-messenger/package.json | Bumps zod dependency. |
| apps/server-core/package.json | Bumps zod dependency. |
| apps/server-core-worker/package.json | Bumps zod dependency; retains tar-stream at ^3.2.0. |
| apps/client-ui/package.json | Bumps vue and zod dependencies. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Follow-up from auditing this decision — the "revisit when upstream's declarations describe their own runtime" line above now has a concrete timeline, and it is shorter than expected. streamx 2.28.1 already fixed most of it. mafintosh/streamx#125 (merged 2026-08-25) corrected four divergences between streamx's declarations and its runtime — Measured against this repo, with tar-stream 3.2.1 and streamx bumped to 2.28.1, four of the five assertions #1861 needed become unnecessary:
The one survivor is not a typing bug: streamx genuinely has no Two upstream PRs opened for what is still genuinely wrong:
Nothing to change in this PR. With those merged and a streamx bump, adopting tar-stream 3.2.1 later costs one assertion instead of five, against an accurate |
Replaces #1858 (build fails) and supersedes #1861 (builds, but at a price not worth paying — see below).
@types/nodelint-stagednxvuezod@vue/test-utilshappy-domvue-routerNot included:
tar-stream3.2.0 → 3.2.1, the ninth member of dependabot's group and the sole cause of #1858's build failure.Why tar-stream is held back
tar-stream3.2.1 is a types-only release.npm diff --diff=tar-stream@3.2.0 --diff=tar-stream@3.2.1 --diff-name-onlylists exactly two files,package.jsonand a newindex.d.ts; adiff -rof the two installed copies excluding those reports no differences. There is nothing to gain at runtime.What it changes is type resolution. 3.2.1 declares
exports["."].types, which shadows@types/tar-stream@3.1.4. DefinitelyTyped modelled tar-stream onnode:stream; the bundled declarations model it onstreamx. Nine compile errors follow, acrossserver-storageandserver-core-worker— in code whose emitted JavaScript would not change by one byte.Accepting the bump means paying for that with five structural assertions in production code. Two of them are not merely awkward, they are false:
pack as unknown as NodeJS.ReadableStreamclaims the object satisfies an interface declaringisPaused,unpipeandwrap, and a streamx stream has none of them. That call works only becausedocker-modemhappens to touch neither — a bet on a third party's internals, written into our source.The new declarations are also, in at least one place, worse than the ones they displace.
Header.typeis 8 required non-nullable literals, whileheaders.jstoType()additionally returns'pax-header','pax-global-header','gnu-long-link-path','gnu-long-path', andnullfor an unrecognised typeflag. The DT model declared all 13, optional and nullable. Adopting the bundled types narrows an exported callback signature into something that misdescribes its own runtime, and makesentry.type === 'pax-header'a compile error for any future consumer.Two of the five assertions exist purely because of upstream declaration bugs that would be better fixed upstream than papered over here:
streamxdeclareswrite(data: unknown): unknown, but the runtime returns a real boolean (_writableState.push(data)). Thatunknownreturn is the whole reasonpipeline(source, entry)andreadable.pipe(extract)fail to typecheck.streamxdeclaresend(data: unknown): thiswith the argument required, whileWritableState.endexplicitly no-ops on bothundefinedandnulland never readsarguments.length.How it is held back
No pin, no
overridesentry, no dependabot ignore rule. The manifests keep^3.2.0and the lockfile keeps 3.2.0 — a range npm has no reason to re-resolve, so bothnpm ciand an ordinarynpm installleave it alone. Verified: everytar-streamcopy in the resolved tree is at or below 3.2.0, and@types/tar-stream@3.1.4stays authoritative.This is a deferral, stated as one. When tar-stream ships a release with actual runtime value the mismatch returns and has to be answered properly — ideally by then upstream, where the two declaration bugs above belong.
Verification
Run locally against this branch:
npm run buildnpm run testnpm run linttsc -p apps/server-{storage,core-worker}/tsconfig.jsonmaster— no new errors, and none removed by working around a bump we did not takeThe diff touches no TypeScript file at all — 13 manifests and the lockfile, nothing else.
Two checks worth recording because they are easy to get wrong:
npm install, never--package-lock-only. All 126 platform-specific optional entries (@esbuild/*,@node-rs/*,@tailwindcss/oxide-*,@rollup/rollup-*,@swc/core-*) are still present, matchingmasterexactly — dropping them would breaknpm cion Linux CI while passing locally on macOS.apps/server-core-worker/test/unit/docker/pack.spec.ts— the end-to-end Docker test coveringputArchivewith a tar-stream pack — was confirmed to genuinely execute and assert, not silently pass: mutating its expected file size makes it exit 1.Worth knowing about the eight that are included
zod 4.5.0 changed string
.min()/.max()/.length()from counting UTF-16 code units to counting Unicode code points..max()only loosens, but.min()strictly tightens for astral-plane input:z.string().min(3)accepted"😀😀"(4 code units, 2 code points) under 4.4.3 and rejects it under 4.5.1. This reaches every free-form string field without a charset guard —node.name, plus registry, analysis and project fields. It is upstream behaving more correctly and no test asserts on it, but a user who could previously name something with two emoji now cannot.Also checked against real usage rather than release notes alone:
@vue/test-utils2.5.0's breaking change is dropping class-component support (none here), and its stub matching — which the client-vue happy-dom harness depends on forVCIcon— is byte-unchanged;vue-router5.3.0's route-codegen fixes are all inert for this route tree;@types/node26.4.0 did not change the stream typings at all, which is what confirms thepipelineerror was attributable to tar-stream alone.