Skip to content

chore(server): remove jest from runtime dependencies - #32

Merged
tkislan merged 2 commits into
releasefrom
chore/remove-jest-runtime-dependency-2026-10-06
Oct 7, 2026
Merged

tkislan merged 2 commits into
releasefrom
chore/remove-jest-runtime-dependency-2026-10-06

Conversation

@tkislan

@tkislan tkislan commented Oct 6, 2026 •

Copy link
Copy Markdown

Removes jest from the runtime dependencies of @deepnote/sql-language-server (packages/server) and bumps the package to 3.0.1. jest stays in devDependencies, where it already was.

   "name": "@deepnote/sql-language-server",
-  "version": "3.0.0",
+  "version": "3.0.1",
 ...
   "dependencies": {
     ...
     "cardinal": "^2.1.1",
-    "jest": "^26.0.1",
     "mysql2": "^3.9.8",

Why

  • jest has been listed in both sections since upstream commit f5b085b ("migrate testing tool to jest", 2020-05-16).
  • Nothing in src/, bin/ or npm_bin/ loads it. It is only the test runner ("test": "jest").
  • As a runtime dependency, it made every consumer install the whole jest 26 tree in production. That tree includes packages with open advisories that have no patched release, such as braces and sprintf-js.

Effect on a production install

Measured with npm install --omit=dev of the packed tarball vs the published 3.0.0, each in a clean directory:

3.0.0 this branch
packages installed 688 240
node_modules size 109 MB 51 MB
jest / @jest/* present absent

Verification

  • yarn install --frozen-lockfile passes and yarn.lock is unchanged. The devDependencies entry keeps the same jest@^26.0.1 resolution.
  • I ran the CI steps locally on Node 22, and these pass:
    • yarn npm:prepublish
    • yarn lint
    • yarn vsc-compile:client
    • yarn vsc-compile:server
    • yarn test:server: 8 suites, 135 passed, 3 skipped
  • Not run locally: test:parser and test:sqlint, since those packages are untouched.
  • Runtime check on a production-only install of the packed tarball (no jest present):
    • dist/src/index.js loads.
    • Forked over node-ipc, dist/bin/vscodeExtensionServer.js answers an LSP initialize request with the same capabilities as 3.0.0: textDocumentSync, completionProvider, renameProvider, codeActionProvider and executeCommandProvider.

Release

  • Only packages/server is bumped. sql-parser and sqlint are unchanged and stay at 3.0.0.
  • publish.yaml sets the version from the v* tag, so the release tag should be v3.0.1.

🤖 Generated with Claude Code

https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ

tkislan and others added 2 commits October 6, 2026 13:43
jest ^26.0.1 has been listed under both `dependencies` and
`devDependencies` of packages/server since f5b085b ("migrate testing tool
to jest", 2020-05-16). Nothing under src/, bin/ or npm_bin/ loads it at
runtime. It is only the test runner, and the devDependencies entry stays.

Because it was a runtime dependency, every consumer of
@deepnote/sql-language-server installed the whole jest 26 tree in
production. In vscode-deepnote that put jest, @jest/*, micromatch, braces
and sprintf-js into `npm audit --omit=dev`, so their advisories failed
the production audit gate.

yarn.lock is unchanged: `yarn install --frozen-lockfile` accepts it, since
the devDependencies entry keeps the same `jest@^26.0.1` resolution.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: f4f8d15c-cfc9-452e-a3b8-9b82c1ac5cf5
📥 Commits

Reviewing files that changed from the base of the PR and between 61e8afe and 2a8356b.

📒 Files selected for processing (1)
  • packages/server/package.json

Included review availability: This review used your included allowance. 3 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The server package version changes from 3.0.0 to 3.0.1. The production Jest dependency is removed. The development Jest dependency remains.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 2a835

The package's published runtime does not depend on Jest, while its test workflow still has Jest available. No merge-blocking risk is identified.

🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Updates Docs ✅ Passed This PR does not implement a feature. The reviewed diff changes only packages/server/package.json: it removes Jest from runtime dependencies and bumps the package version. The documentation-update c…
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: removing Jest from the server's runtime dependencies.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@tkislan
tkislan marked this pull request as ready for review October 7, 2026 08:09
@tkislan
tkislan requested review from m1so and mfranczel October 7, 2026 08:09
@tkislan
tkislan merged commit 5eb181f into release Oct 7, 2026
2 checks passed
@tkislan
tkislan deleted the chore/remove-jest-runtime-dependency-2026-10-06 branch October 7, 2026 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants