Skip to content

feat(core): restore EmDash 0.38 compatibility - #28

Open
cavewebs wants to merge 3 commits into
mainfrom
cursor/emdash-0.38-compat-a696
Open

cavewebs wants to merge 3 commits into
mainfrom
cursor/emdash-0.38-compat-a696

Conversation

@cavewebs

@cavewebs cavewebs commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Widens @dashcommerce/core peer dependency range to restore day-one compatibility with EmDash 0.38.x while keeping 0.37.x installs unbroken. EmDash 0.38.0 was released 2026-09-15 ~05:30Z; the existing peer constraint >=0.37.0 <0.38.0 caused new installs to fail peer checks.

Changes

Peer & dev dependency updates

  • packages/core/package.json: Widen emdash peer to >=0.37.0 <0.39.0
  • packages/core/package.json: Upgrade dev dependencies to emdash@^0.38.0 and @emdash-cms/admin@^0.38.0
  • packages/starter/package.json: Upgrade emdash@^0.38.0 and @emdash-cms/cloudflare@^0.38.0
  • patches/emdash@0.38.0.patch: New patch preserving DashCommerce's raw Response handling and request cloning fixes

CI compatibility fixes

  • package.json: Register both emdash@0.37.0 and emdash@0.38.0 patches for dual-version support
  • packages/starter/.emdash/migrations.json: Revert to 0.37.0 baseline (was incorrectly updated to 0.38.0 with 0.38-only migrations 075-077)
  • patches/README.md: Document dual-version patch support
  • .github/workflows/ci.yml: Downgrade packages/core devDeps in compatibility matrix (build was failing because core's ^0.38.0 devDep caused bun to resolve 0.38 which imports 0.38-only modules from downgraded 0.37 admin package)

Changeset

Added patch changeset documenting EmDash 0.38 compatibility and plugin-author considerations.

EmDash 0.38.0 release notes scan

Changes that may affect DashCommerce

  1. Entry edit locks (#2919)

    • New lock per content entry; admin takes lock on open, holds for 7 minutes with 2-minute renewal
    • Scripts/API/CLI updating/publishing content while editor has entry open → 409 ENTRY_LOCKED
    • Response includes error.details with userId, userName, acquiredAt, expiresAt
    • Bypass: pass overrideLock: true in request body or ?overrideLock=true on DELETE
    • DashCommerce impact: Any code that programmatically updates EmDash content entries (product metadata sync, order notes via API) will need lock handling or docs
    • Migration: 075_entry_edit_locks (auto-applies on default runtime migration mode)
  2. ctx.storage.<collection>.updateIf() (#2169)

    • Atomic conditional updates for plugin storage: updateIf(id, { where, set?, delta? })
    • Returns { applied: true, data } or { applied: false }
    • PostgreSQL serialization failures expose retryable: true
    • DashCommerce opportunity: Current inventory decrements are likely read-modify-write; switching to updateIf with where: { stock: { gte: quantity } } and delta: { stock: -quantity } would prevent race conditions on concurrent checkouts. Not included in this PR; safe to adopt in follow-up when we confirm benefit vs. risk.
  3. SEO <EmDashHead> overlay (#1963)

    • <EmDashHead> now auto-applies entry SEO panel values (title, description, image, canonical, noindex) on server-rendered pages fetched via getEmDashEntry()
    • DashCommerce impact: Likely transparent unless DashCommerce overrides SEO manually via getSeoMeta() — no known conflicts
  4. Collection group setting (#3062)

    • Collections sharing a group render as one collapsible folder in admin sidebar
    • DashCommerce impact: None (cosmetic admin change)
  5. Portable Text tables (#2934)

    • Enhanced table support with merge/split, column widths, keyboard navigation
    • portableTextToProsemirror() now returns real table nodes
    • DashCommerce impact: None unless custom ProseMirror schemas consume that output
  6. Other notable fixes

    • Visual editing on list pages now works (#2970)
    • Non-translatable field publishing propagates to other translations (#3090)
    • Plugin HTTP SSRF validation tightened (#3050)

Testing

  • ✅ Typecheck: bun run typecheck passes on all packages (0.37 and 0.38)
  • ✅ Tests: All 85 tests pass (inventory, webhooks, cart, money, tokens, etc.)
  • ✅ Build: packages/core builds successfully with 0.37.0 and 0.38.0
  • ✅ CI Simulation: Frozen lockfile → downgrade → typecheck → build all pass on 0.37.0

CI failure investigation

The initial CI run failed on the EmDash Compatibility (0.37.0) matrix job. Root causes:

  1. Missing 0.37 patch registration: package.json only registered emdash@0.38.0 patch. When CI downgraded to 0.37, bun couldn't apply the required fixes. Fixed: registered both patches.

  2. 0.38-only migrations in starter: packages/starter/.emdash/migrations.json was accidentally updated to 0.38.0 with migrations 075-077 that don't exist in 0.37. Fixed: reverted to 0.37.0 baseline.

  3. Core devDeps not downgraded: CI downgraded root and starter, but packages/core still had emdash@^0.38.0 devDep. Bun resolved 0.38.0 for builds, which tried to import portable-text-table from downgraded @emdash-cms/admin@0.37.0 (doesn't exist). Fixed: CI now downgrades core devDeps too.

Build error was:

Could not load @emdash-cms/admin@0.37.0/dist/portable-text-table
(imported by emdash@0.38.0/dist/menus-*.mjs)

Follow-up opportunities (not in this PR)

  1. Atomic inventory with updateIf: Consider replacing read-modify-write stock decrements with ctx.storage.products.updateIf(id, { where: { stock: { gte: qty } }, delta: { stock: -qty } }) to prevent overselling during concurrent checkouts. Requires testing to ensure it doesn't break existing fulfillment flows.

  2. Entry lock handling: Document or implement overrideLock for any DashCommerce workflows that update content entries programmatically (admin sync, bulk imports). Low urgency unless those workflows exist.

  3. Lock overrides for order notes: If DashCommerce writes order notes/status to EmDash content entries via API, those may now encounter locks. Defer until confirmed needed.

Release notes

This is a patch bump for @dashcommerce/core (0.2.0 → 0.2.1 after merge + publish). Consumers on EmDash 0.37.x are unaffected; 0.38.x installs now pass peer checks. Manual migration projects should run emdash migrate before deploying to apply migration 075_entry_edit_locks.


Ready for review. Timchosen should review before publish. Do not merge open PR #27 (Version Packages bot) until this is approved and merged.

Open in Web Open in Cursor 

- Update peerDependencies to allow emdash >=0.37.0 <0.39.0
- Upgrade devDependencies to emdash@^0.38.0 and @emdash-cms/admin@^0.38.0 in core
- Upgrade dependencies to emdash@^0.38.0 and @emdash-cms/cloudflare@^0.38.0 in starter
- Create new patch for emdash@0.38.0 preserving raw Response handling and request cloning
- Add changeset documenting compatibility with EmDash 0.38 features (entry locks, updateIf, SEO overlay)

EmDash 0.38.0 introduces entry edit locks with migration 075_entry_edit_locks,
atomic ctx.storage.<collection>.updateIf() for conditional updates, automatic
SEO <EmDashHead> overlay, collection grouping, and Portable Text tables.

All typecheck and tests pass on 0.38.0.

Co-authored-by: Timchosen Uzua <timchosen@gmail.com>
cursoragent and others added 2 commits September 15, 2026 13:14
- Register both emdash@0.37.0 and emdash@0.38.0 patches in package.json
- Revert packages/starter/.emdash/migrations.json to 0.37.0 baseline (was incorrectly updated to 0.38.0 with 0.38-only migrations 075-077)
- Update patches/README.md to document dual-version patch support

The compatibility matrix job installs with frozen lockfile (0.38) then downgrades
to 0.37. Without the 0.37 patch registered, bun fails to apply the required fixes.
The migrations.json with 0.38-only migrations broke 0.37 typecheck/build.

Co-authored-by: Timchosen Uzua <timchosen@gmail.com>
The compatibility matrix job must downgrade packages/core devDependencies
in addition to root and starter. Without this, bun resolves emdash@0.38.0
from core's ^0.38.0 devDep, causing the build to import 0.38-only modules
(portable-text-table) from @emdash-cms/admin@0.37.0 which doesn't have them.

Build error:
  Could not load @emdash-cms/admin/dist/portable-text-table
  (imported by emdash@0.38.0 menus-*.mjs)

Fix: downgrade core devDeps alongside root and starter.

Co-authored-by: Timchosen Uzua <timchosen@gmail.com>
@cavewebs
cavewebs marked this pull request as ready for review September 21, 2026 08:18
cavewebs added a commit that referenced this pull request Sep 22, 2026
CEO daily growth: fix misleading "0.37+" (npm peer is <0.38 until PR #28), add npm/GitHub shields, and surface EmDash experimental plugin registry as the next discovery channel after npm.

Copy link
Copy Markdown
Contributor Author

EmDash 0.39.0 shipped today (npm latest).

This PR’s peer upper bound is currently >=0.37.0 <0.39.0, which already excludes 0.39.0. Even if we merge+publish as-is, day-one EmDash 0.39 installs would still fail peer checks.

Ask before merge

Please hold merge until we widen the peer through 0.39 (likely >=0.37.0 <0.40.0), refresh patches/CI matrix if needed, and re-green CI. I tried to launch a Cursor cloud agent on this branch for that work; launch failed because Cursor usage is exhausted (on-demand needed).

Meanwhile (unchanged)

  • CI on current head remains green for 0.37 / typecheck+build.
  • Do not merge PR #27 (Version Packages) until this lands.
  • Keep 0.1.x unbricked; this stays a patch path to 0.2.1 after publish.

Growth note from 0.39

EmDash 0.39 makes the plugin registry the default discovery path (Marketplace browse/install deprecated). Once peer catches up, listing DashCommerce on registry.emdashcms.com (Atmosphere publisher login) is the highest-leverage organic install channel.

Copy link
Copy Markdown
Contributor Author

CEO daily 24 Sep — EmDash 0.39.1 landed; this PR’s upper bound is already stale

Facts

  • npm emdash latest is 0.39.1 (0.39.0 ~06:37 UTC 23 Sep, patch 0.39.1 same morning).
  • This PR widens peer to >=0.37.0 <0.39.0, so 0.39.x is already excluded even after merge.
  • Published @dashcommerce/core@0.2.0 is still >=0.37.0 <0.38.0.
  • Cloud agent to extend this branch for 0.39 failed again today (Cursor usage exhausted / on-demand needed). CI on this PR remains green for 0.37+0.38.

0.39.0 highlights that matter for DashCommerce

  1. Plugin registry is now default discovery (https://registry.emdashcms.com when sandbox is enabled). experimental.registry deprecated; top-level registry option. Marketplace browse/install hidden. This is the biggest organic-install lever we have — listing @…/dashcommerce should be next growth bet once peers catch up.
  2. Binary-safe sandboxed ctx.http.fetch (8 MiB buffer) — review any Stripe/webhook/media fetch paths after we bump.
  3. New consented sandbox capabilities (schema, redirects, comments, media bytes/metadata, settings secrets, publish/restore, editor panels/actions, content-policy hooks). Likely additive; scan for breakages when extending.
  4. 0.39.1: D1 migrate fix for 081_redirect_write_guards (Cloudflare-relevant).

Ask

  1. Enable Cursor on-demand (or otherwise free cloud-agent usage) so we can push 0.39.x onto this branch before merge+publish.
  2. Or review/merge this PR as an interim 0.38-only 0.2.1, then immediately open a 0.39 follow-up — knowing new installs on EmDash latest will still fail peers until that lands.
  3. Hold Version Packages chore: version packages #27 until the compat PR you want published is merged.

Prefer one ship that covers 0.38+0.39 once usage is unblocked.

Copy link
Copy Markdown
Contributor Author

CEO daily 25 Sep — EmDash 0.39 scan (still blocked on cloud-agent usage)

Facts

  • npm @dashcommerce/core@0.2.0 peer remains emdash >=0.37.0 <0.38.0
  • This PR widens to <0.39.0, which already excludes EmDash 0.39.0 / 0.39.1 (npm latest as of this morning)
  • Cursor cloud agent launch to extend this branch failed again: account usage exhausted (on-demand needed)

0.39.0 / 0.39.1 notes relevant to DashCommerce (from EmDash releases)

  1. Registry is default discovery (#3145) — Marketplace browse/install hidden. Organic installs now go through registry.emdashcms.com / admin Registry. Tracked in growth: list DashCommerce on EmDash plugin registry (default discovery in 0.39) #33.
  2. Sandbox capability surface expanded (schema/read, redirects, comments, media bytes/metadata, ctx.settings + secret encryption, content publish/restore, editor draft panels, binary-safe ctx.http.fetch). Native DashCommerce may be unaffected until we ship a sandboxed registry build; for a sandboxed port we must declare only the capabilities we need and plan consent UX.
  3. 0.39.1 — D1 migration 081_redirect_write_guards fix only; low DashCommerce risk.
  4. No obvious day-one break for our current native peer path beyond the peer upper bound. Still need CI matrix + patches verified on 0.39 (same dual-version patch pattern as 0.37/0.38).

Ask for Timchosen

  1. Enable Cursor on-demand usage (or run the 0.39 peer widen locally) so we can land >=0.37 <0.40 on this PR before merge/publish.
  2. Do not merge chore: version packages #27 (Version Packages) until this PR covers 0.39 and you green-light publish.

0.1.x / EmDash 0.28.x line stays untouched.

Copy link
Copy Markdown
Contributor Author

CEO daily — Mon 2026-09-28 (EmDash velocity alert)

Published @dashcommerce/core@0.2.0 peer is still emdash >=0.37.0 <0.38.0. EmDash has moved far past the 0.39 target this PR was waiting to extend.

EmDash npm since last CEO daily (2026-09-25)

Version Published (UTC)
0.39.1 2026-09-23 (baseline last pulse)
0.40.0 2026-09-25 ~09:58Z
0.40.1 2026-09-25 ~16:44Z
0.41.0 2026-09-26 ~10:50Z
0.42.0 2026-09-27 ~20:27Z (current latest)
1.0.1-rc.0 2026-09-28 ~05:43Z (same-day GitHub release train)

Sources: npm view emdash version → 0.42.0; registry time fields; GitHub emdash-cms/emdash releases include the 1.0.1-rc.0 package set this morning.

What this means for #28

  • Branch is still 0.38-ready (mergeable_state: clean); peer widen in this PR only goes to <0.39.0.
  • Even if we merge+publish as-is, new EmDash installs on 0.39–0.42 / 1.0-rc still fail peer checks.
  • Prior cloud-agent attempts to extend this PR to 0.39 repeatedly failed (Cursor usage exhausted). Do not assume another CloudAgent run will succeed without Timchosen confirming usage/budget.

Proposal (needs Timchosen confirmation — no publish yet)

  1. Strategy choice: (A) merge 0.38 patch now for partial catch-up + open a fresh PR targeting 0.42 / 1.0-rc with CI matrix, or (B) skip intermediate publishes and jump peers in one carefully tested PR once CloudAgent/local capacity is available.
  2. Keep 0.1.x line intact for EmDash 0.28.x consumers (no breaking latest bump without confirmation).
  3. Hold Changesets bot chore: version packages #27 until the chosen compat PR is approved.

Pulse (28 Sep)

No npm latest bump and no peer widen beyond review in this comment.

cavewebs added a commit that referenced this pull request Sep 29, 2026
## Summary
CEO daily (22 Sep): growth-facing README polish — no runtime/publish
impact.

- Add npm version/downloads + GitHub stars + MIT shields for social
proof
- Correct misleading **EmDash 0.37+** copy: published peer is `>=0.37.0
<0.38.0`; point to ready [PR
#28](#28) for 0.38 →
`0.2.1`
- Reaffirm 0.1.x stays unbricked for EmDash 0.28.x
- Call out EmDash experimental [plugin
registry](https://docs.emdashcms.com/plugins/registry/) as the next
organic discovery bet (needs Atmosphere publisher credentials — not
publishing in this PR)

## Test plan
- [x] Docs-only change
- [ ] Skim rendered README on GitHub after merge

Safe to merge anytime; does not require a release.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants