Four majors are behind as of v1.6.0. They were held back deliberately during the release rather than bumped blind — each needs its own verification.
| Package |
Current |
Latest |
Risk |
@octokit/graphql |
8.2.2 |
9.0.4 |
High — every tool calls through it |
typescript |
5.9.3 |
7.0.2 |
Medium — Go-based compiler rewrite |
vitest |
3.2.7 |
4.1.10 |
Medium — test runner migration |
@types/node |
22.20.1 |
26.2.0 |
See note below |
Why @octokit/graphql 9 is the one that matters
It's the client every tool in this server calls through, and the injected GraphQLFn type flows into all of src/tools/*. A major there can change:
So this one wants the error-handling paths exercised against the live API, not just a green unit suite.
@types/node should stay on ^22
Not part of this upgrade, and deliberately so: engines declares node >=22, so the types should match the oldest supported runtime. Bumping to 26 would let Node 26-only APIs typecheck clean and then fail at runtime for users on 22.
Worth revisiting only if the minimum supported Node moves.
Done when
Follows the v1.6.0 release (#27).
Four majors are behind as of v1.6.0. They were held back deliberately during the release rather than bumped blind — each needs its own verification.
@octokit/graphqltypescriptvitest@types/nodeWhy
@octokit/graphql9 is the one that mattersIt's the client every tool in this server calls through, and the injected
GraphQLFntype flows into all ofsrc/tools/*. A major there can change:isDuplicateNameErrorinsrc/tools/iterations.tsmatches onerror.messagetext (/name has already been taken/i). If v9 restructures errors, thecreate_iteration_fieldadoption fallback silently stops recognising duplicates and starts rethrowing — the exact path create_iteration_field and add_iteration fail with GraphQL input-type errors #21/add_iteration & create_iteration_field send outdated payload (GitHub schema mismatch) #22 were about.GraphQLFntype surface, which is the seam every unit test mocks. Mocks that no longer match the real signature would still pass while the real client diverges — this repo has been bitten by exactly that before (the pre-fix(iterations): correct GraphQL schema misuse and preserve item assignments #26 tests mocked a fabricated schema and passed against broken code).So this one wants the error-handling paths exercised against the live API, not just a green unit suite.
@types/nodeshould stay on ^22Not part of this upgrade, and deliberately so:
enginesdeclaresnode >=22, so the types should match the oldest supported runtime. Bumping to 26 would let Node 26-only APIs typecheck clean and then fail at runtime for users on 22.Worth revisiting only if the minimum supported Node moves.
Done when
pnpm run build,pnpm run typecheck,pnpm testgreen on Node 22 and 24isDuplicateNameErrorand the iteration error paths verified against the live GraphQL API, not just mocksFollows the v1.6.0 release (#27).