Skip to content

fix(deps): bump the minorandpatch group with 8 updates - #1862

Merged
tada5hi merged 1 commit into
masterfrom
chore/deps-minorandpatch-alt
Sep 1, 2026
Merged

tada5hi merged 1 commit into
masterfrom
chore/deps-minorandpatch-alt

Conversation

@tada5hi

@tada5hi tada5hi commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Replaces #1858 (build fails) and supersedes #1861 (builds, but at a price not worth paying — see below).

Package From To
@types/node 26.3.0 26.4.0
lint-staged 17.3.0 17.4.1
nx 23.1.1 23.1.2
vue 3.5.41 3.5.42
zod 4.4.3 4.5.1
@vue/test-utils 2.4.11 2.5.0
happy-dom 20.11.6 20.11.13
vue-router 5.2.0 5.3.0

Not included: tar-stream 3.2.0 → 3.2.1, the ninth member of dependabot's group and the sole cause of #1858's build failure.

Why tar-stream is held back

tar-stream 3.2.1 is a types-only release. npm diff --diff=tar-stream@3.2.0 --diff=tar-stream@3.2.1 --diff-name-only lists exactly two files, package.json and a new index.d.ts; a diff -r of the two installed copies excluding those reports no differences. There is nothing to gain at runtime.

What it changes is type resolution. 3.2.1 declares exports["."].types, which shadows @types/tar-stream@3.1.4. DefinitelyTyped modelled tar-stream on node:stream; the bundled declarations model it on streamx. Nine compile errors follow, across server-storage and server-core-worker — in code whose emitted JavaScript would not change by one byte.

Accepting the bump means paying for that with five structural assertions in production code. Two of them are not merely awkward, they are false: pack as unknown as NodeJS.ReadableStream claims the object satisfies an interface declaring isPaused, unpipe and wrap, and a streamx stream has none of them. That call works only because docker-modem happens to touch neither — a bet on a third party's internals, written into our source.

The new declarations are also, in at least one place, worse than the ones they displace. Header.type is 8 required non-nullable literals, while headers.js toType() additionally returns 'pax-header', 'pax-global-header', 'gnu-long-link-path', 'gnu-long-path', and null for an unrecognised typeflag. The DT model declared all 13, optional and nullable. Adopting the bundled types narrows an exported callback signature into something that misdescribes its own runtime, and makes entry.type === 'pax-header' a compile error for any future consumer.

Two of the five assertions exist purely because of upstream declaration bugs that would be better fixed upstream than papered over here:

  • streamx declares write(data: unknown): unknown, but the runtime returns a real boolean (_writableState.push(data)). That unknown return is the whole reason pipeline(source, entry) and readable.pipe(extract) fail to typecheck.
  • streamx declares end(data: unknown): this with the argument required, while WritableState.end explicitly no-ops on both undefined and null and never reads arguments.length.

How it is held back

No pin, no overrides entry, no dependabot ignore rule. The manifests keep ^3.2.0 and the lockfile keeps 3.2.0 — a range npm has no reason to re-resolve, so both npm ci and an ordinary npm install leave it alone. Verified: every tar-stream copy in the resolved tree is at or below 3.2.0, and @types/tar-stream@3.1.4 stays authoritative.

This is a deferral, stated as one. When tar-stream ships a release with actual runtime value the mismatch returns and has to be answered properly — ideally by then upstream, where the two declaration bugs above belong.

Verification

Run locally against this branch:

Gate Result
npm run build 26/26 projects
npm run test 18 projects, full suite green — real Authup + PostgreSQL via testcontainers
npm run lint 0 errors (15 pre-existing warnings, none in touched files)
tsc -p apps/server-{storage,core-worker}/tsconfig.json identical error set to master — no new errors, and none removed by working around a bump we did not take

The diff touches no TypeScript file at all — 13 manifests and the lockfile, nothing else.

Two checks worth recording because they are easy to get wrong:

  • The lockfile was synced with a plain npm install, never --package-lock-only. All 126 platform-specific optional entries (@esbuild/*, @node-rs/*, @tailwindcss/oxide-*, @rollup/rollup-*, @swc/core-*) are still present, matching master exactly — dropping them would break npm ci on Linux CI while passing locally on macOS.
  • apps/server-core-worker/test/unit/docker/pack.spec.ts — the end-to-end Docker test covering putArchive with a tar-stream pack — was confirmed to genuinely execute and assert, not silently pass: mutating its expected file size makes it exit 1.

Worth knowing about the eight that are included

zod 4.5.0 changed string .min()/.max()/.length() from counting UTF-16 code units to counting Unicode code points. .max() only loosens, but .min() strictly tightens for astral-plane input: z.string().min(3) accepted "😀😀" (4 code units, 2 code points) under 4.4.3 and rejects it under 4.5.1. This reaches every free-form string field without a charset guard — node.name, plus registry, analysis and project fields. It is upstream behaving more correctly and no test asserts on it, but a user who could previously name something with two emoji now cannot.

Also checked against real usage rather than release notes alone: @vue/test-utils 2.5.0's breaking change is dropping class-component support (none here), and its stub matching — which the client-vue happy-dom harness depends on for VCIcon — is byte-unchanged; vue-router 5.3.0's route-codegen fixes are all inert for this route tree; @types/node 26.4.0 did not change the stream typings at all, which is what confirms the pipeline error was attributable to tar-stream alone.

@types/node 26.4.0, lint-staged 17.4.1, nx 23.1.2, vue 3.5.42, zod 4.5.1,
@vue/test-utils 2.5.0, happy-dom 20.11.13, vue-router 5.3.0.

Excludes tar-stream 3.2.0 -> 3.2.1 from the group. It is a types-only
release — `npm diff` against 3.2.0 lists exactly package.json and a new
index.d.ts, and the runtime JS is byte-identical — so it offers nothing at
runtime, while its bundled declarations shadow @types/tar-stream and model
tar-stream on `streamx` instead of node:stream. Taking it costs five
structural assertions in production code, two of which claim a streamx
stream satisfies NodeJS.ReadableStream when it genuinely lacks isPaused,
unpipe and wrap.

The new declarations also regress on Header.type: 8 required non-nullable
literals, where headers.js toType() additionally returns 'pax-header',
'pax-global-header', 'gnu-long-link-path', 'gnu-long-path' and null. The
DefinitelyTyped model had all 13.

No pin, override or dependabot ignore: the manifests keep ^3.2.0 and the
lock keeps 3.2.0, which npm ci and npm install both respect. Revisit when
upstream's declarations describe their own runtime.
Copilot AI lite review requested due to automatic review settings September 1, 2026 11:25
@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 17 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: eea00186-29eb-4a1c-af7b-697dccf5c649

📥 Commits

Reviewing files that changed from the base of the PR and between 0be5ce6 and 0acd5a7.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (13)
  • apps/client-ui/package.json
  • apps/server-core-worker/package.json
  • apps/server-core/package.json
  • apps/server-messenger/package.json
  • apps/server-storage/package.json
  • apps/server-telemetry/package.json
  • docs/package.json
  • package.json
  • packages/client-vue/package.json
  • packages/core-kit/package.json
  • packages/messenger-kit/package.json
  • packages/storage-kit/package.json
  • packages/telemetry-kit/package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates a curated set of minor/patch dependencies across the monorepo while intentionally not taking the tar-stream 3.2.1 types-only release that previously broke builds due to Node stream vs streamx type incompatibilities.

Changes:

  • Bump zod to ^4.5.1 across apps and kits.
  • Bump tooling/framework deps: @types/node → 26.4.0, lint-staged → 17.4.1, nx → 23.1.2, vue → 3.5.42, @vue/test-utils → 2.5.0, happy-dom → 20.11.13, vue-router → 5.3.0.
  • Refresh package-lock.json to reflect the above updates while keeping tar-stream resolved at 3.2.0.

Reviewed changes

Copilot reviewed 13 out of 14 changed files in this pull request and generated no comments.

Show a summary per file
File Description
packages/telemetry-kit/package.json Bumps zod dependency.
packages/storage-kit/package.json Bumps zod dependency.
packages/messenger-kit/package.json Bumps zod dependency.
packages/core-kit/package.json Bumps zod dependency.
packages/client-vue/package.json Updates Vue ecosystem/test deps (vue, vue-router, @vue/test-utils, happy-dom) plus @types/node and zod.
package.json Updates root dev tooling deps (@types/node, lint-staged, nx).
package-lock.json Lockfile refresh for the selected dependency bumps (while retaining tar-stream 3.2.0).
docs/package.json Bumps vue used by VitePress docs site.
apps/server-telemetry/package.json Bumps zod dependency.
apps/server-storage/package.json Bumps zod dependency.
apps/server-messenger/package.json Bumps zod dependency.
apps/server-core/package.json Bumps zod dependency.
apps/server-core-worker/package.json Bumps zod dependency; retains tar-stream at ^3.2.0.
apps/client-ui/package.json Bumps vue and zod dependencies.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@tada5hi

tada5hi commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Follow-up from auditing this decision — the "revisit when upstream's declarations describe their own runtime" line above now has a concrete timeline, and it is shorter than expected.

streamx 2.28.1 already fixed most of it. mafintosh/streamx#125 (merged 2026-08-25) corrected four divergences between streamx's declarations and its runtime — write()'s return type, listeners(), eventNames(), setMaxListeners() — and relaxed pipe<S extends Writable> to pipe<S>. Hub currently resolves streamx 2.28.0, one patch behind.

Measured against this repo, with tar-stream 3.2.1 and streamx bumped to 2.28.1, four of the five assertions #1861 needed become unnecessary:

Call site streamx 2.28.0 streamx 2.28.1
pipeline(source, entry) — storage cast compiles
readable.pipe(extract) — worker cast compiles
data.pipe(extract) — storage spec cast compiles
pack.pipe(createGzip()) — worker cast compiles
container.putArchive(pack, …) cast still fails

The one survivor is not a typing bug: streamx genuinely has no isPaused, unpipe or wrap, which NodeJS.ReadableStream declares and dockerode therefore demands. That is the same unsoundness already sitting uncast at master-image-builder/handlers/execute/module.ts:129 — see #1863.

Two upstream PRs opened for what is still genuinely wrong:

  • mafintosh/streamx#126 — Writable#end()'s argument is declared required, but the runtime short-circuits on undefined/null and streamx's own tests call .end() with no arguments. This is what forces entry.end(undefined).
  • mafintosh/tar-stream#181 — Header disagrees with headers.decode() in three places: type omits four values toType() returns and cannot be null; linkname cannot be null; byteOffset is missing entirely. This is the Header.type regression described above.

Nothing to change in this PR. With those merged and a streamx bump, adopting tar-stream 3.2.1 later costs one assertion instead of five, against an accurate Header — a much easier trade than the one being declined here. Recording it so the next person meeting this bump does not have to re-derive it.

@tada5hi
tada5hi merged commit 450bc71 into master Sep 1, 2026
21 checks passed
@github-actions github-actions Bot mentioned this pull request Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants