Skip to content

chore(deps): bump @deepnote/sql-language-server to 3.0.1 - #556

Draft
tkislan wants to merge 1 commit into
mainfrom
tk/bump-sql-language-server-3.0.1
Draft

tkislan wants to merge 1 commit into
mainfrom
tk/bump-sql-language-server-3.0.1

Conversation

@tkislan

@tkislan tkislan commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

@deepnote/sql-language-server@3.0.1 no longer lists jest@^26.0.1 under dependencies. The published tarball differs from 3.0.0 only in package.json (version and the jest line), and dist/ is byte-identical.

  • package.json: ^3.0.0 → ^3.0.1.
  • Dead override removed: overrides["@deepnote/sql-language-server"].ws pinned jsdom/node_modules/ws, which jest 26 pulled in through jsdom. That copy is gone, so the override no longer has a target.
  • .nsprc notes corrected: the braces (GHSA-vfj7-8cjw-p6xm) and sprintf-js (GHSA-hp3w-g68c-fv3c) notes said these packages were in the production tree because of sql-language-server's jest. Now braces reaches production only through @jupyterlab/filebrowser → jest-environment-jsdom, and sprintf-js is dev-only (nyc). Both exceptions are still needed by Audit - All, so the entries and expiries are unchanged.

Size impact

Before (3.0.0) After (3.0.1) Δ
package-lock.json entries 2,909 2,637 −272 (0 added, only sql-language-server changed version)
Packages installed by npm ci 2,827 2,555 −272
node_modules (apparent size) 1,099.2 MB 1,076.9 MB −22.3 MB (−2.0%)
node_modules (disk usage) 1,374 MiB 1,342 MiB −32 MiB
npm audit findings (full tree) 59 (47 high) 32 (21 high) −27 (−26 high, −1 moderate)
VSIX — — no change

The VSIX doesn't change because jest never shipped in it. vsce package --no-dependencies and .vscodeignore (node_modules/**) keep node_modules out. dist/sqlLanguageServer.cjs is an esbuild bundle of the server entry point, and it comes out byte-identical when built from either version (compared after normalizing the build path). dist/sql-lsp-modules installs a fixed list of drivers that doesn't include this package. So the savings are on developer and CI installs, not on users' downloads.

Measured with clean npm ci --ignore-scripts installs of the before and after lockfiles side by side.

Reviewing the lockfile

GitHub's default (Myers) diff shows about +32k/−38k lines for package-lock.json because the lockfile v2 legacy dependencies section gets re-nested. With git diff --histogram the real change is +280/−6,367. That is the 272 removed entries, plus 95 packages that now get "dev": true because jest was their only production consumer.

Verification

  • npm install on a fresh copy with the pinned npm 10.9.4 leaves the lock unchanged (same lock-drift check as CI). A control run on main's lock is also clean.
  • npx better-npm-audit audit --production and npx better-npm-audit audit both pass.
  • npm run lint, npm run typecheck, npm run format, npm run esbuild-all: all pass.
  • rm -rf out && npm run compile-tsc && npm test: 2,879 passing, 0 failing.

🤖 Generated with Claude Code

https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ

Summary by CodeRabbit

  • Chores
    • Updated package maintenance settings and clarified security advisory notes.
    • No user-facing behavior changes are included in this update.

3.0.1 drops jest from its runtime dependencies, removing 272 packages
from the install tree. The nested ws override only targeted jsdom's ws
under jest, so it is dead and removed. The braces and sprintf-js audit
exception notes no longer attribute their production paths to jest.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 4f11b5f3-fe00-4b35-aff4-cce734911a57
📥 Commits

Reviewing files that changed from the base of the PR and between 595792c and 004cbc2.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • .nsprc
  • package.json

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The manifest upgrades @deepnote/sql-language-server to ^3.0.1 and removes its ws override. The .nsprc notes revise the stated dependency paths and production classification for braces and sprintf-js.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested reviewers: jamesbhobbs

Merge Risk: ⚪ Minimal · up to 004cb

No actionable risk from the dependency update or revised audit notes remains; the change is mergeable after normal checks.

🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: upgrading @deepnote/sql-language-server to version 3.0.1.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Updates Docs ✅ Passed This pull request only updates a dependency, its lockfile, an obsolete override, and audit notes. It does not implement a feature, so the documentation-update condition is not applicable.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 38%. Comparing base (595792c) to head (004cbc2).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@          Coverage Diff          @@
##            main    #556   +/-   ##
=====================================
  Coverage     38%     38%           
=====================================
  Files        822     822           
  Lines      41098   41098           
  Branches    9044    9044           
=====================================
  Hits       15620   15620           
  Misses     23405   23405           
  Partials    2073    2073           
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant