chore: bring development dependencies current and build on Node 26 - #84
Merged
Merged
Conversation
Raises the devDependency ranges that sat below what the lockfile resolves,
refreshes the transitive packages that had newer releases within their
ranges, and moves the two allowScripts pins onto the versions now installed.
@types/node ^26.6.2 -> ^26.6.3
@vitest/coverage-v8 ^5.0.1 -> ^5.0.2
esbuild ^0.28.1 -> ^0.28.2
knip ^6.37.0 -> ^6.38.0
lint-staged ^17.3.0 -> ^17.5.1
prettier ^3.9.8 -> ^3.9.9
typescript-eslint ^8.66.0 -> ^8.70.1
vitest ^5.0.1 -> ^5.0.2
The ranges follow the lockfile, so none of them moves a resolved version.
Thirty transitive packages do move, playwright 1.63.0 among them, and two
nested copies are deduplicated.
## Why the allowScripts pins change
The entries pin exact versions, so they fall behind whenever the lockfile
moves. esbuild has resolved to 0.28.2 while its entry named 0.28.1: npm 11
skipped its install script and reported it as not covered by allowScripts on
every install. Nothing failed, because esbuild's platform binary arrives as an
optional dependency and the script only fetches it when that dependency is
missing. The refresh also moves @playwright/browser-chromium to 1.63.0, whose
install script downloads the browser the web extension host lane drives, so
its pin moves with it.
## Left out
Releases published within the last three days: typescript-eslint 8.71.0 with
its @typescript-eslint/* packages, lint-staged 17.6.0, and three transitive
packages. TypeScript stays on 6.0.3, the newest 6.x release.
## Verification
`npm run quality` and `npm run verify:package` pass. `npm install-scripts ls`
reports no unreviewed install scripts, and `npm install-scripts prune
--dry-run` finds no stale entries. The lockfile root matches package.json for
all 18 devDependencies.
knip again hints that `lint-staged` could leave `ignoreDependencies`. The hint
appears only where `.husky/` exists; a clean checkout has none, so the entry
stays.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
desktop-contract, web-contract, package and typescript7, the release workflow's verify and publish jobs, and the documentation build now run on Node 26, the newest release line, instead of 24. The quality matrix still covers 22, 24 and 26, and engines.node stays >=22.12.0, so the supported range is unchanged. CONTRIBUTING now names the version CI publishes with. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings the development toolchain current: the devDependency ranges, a lockfile refresh within them, the
allowScriptspins, and Node 26 for the jobs that run on a single version. Consumers are unaffected: the package has no runtime dependencies, andenginesis unchanged.Why
The
allowScriptspins had drifted from the lockfile. They pin exact versions, and esbuild has resolved to 0.28.2 while its entry named 0.28.1. npm 11 therefore skipped esbuild's install script and printed "install scripts not yet covered by allowScripts" on every install in the Node 24 and 26 jobs. Nothing failed, because esbuild's platform binary arrives as an optional dependency and the script only fetches it when that is missing, which is how the drift went unnoticed.Transitive packages only move when something regenerates the lockfile, so thirty of them had newer releases within their ranges. One of them is
@playwright/browser-chromium, whose install script downloads the browser the web extension host lane drives, so its pin moves in the same change.Dependencies
@types/node^26.6.2→^26.6.3@vitest/coverage-v8^5.0.1→^5.0.2esbuild^0.28.1→^0.28.2knip^6.37.0→^6.38.0lint-staged^17.3.0→^17.5.1prettier^3.9.8→^3.9.9typescript-eslint^8.66.0→^8.70.1vitest^5.0.1→^5.0.2The ranges follow what the lockfile already resolves, so none of them moves a resolved version. Thirty transitive packages do move (playwright 1.63.0 among them), and two nested copies are deduplicated. The
allowScriptspins now nameesbuild@0.28.2and@playwright/browser-chromium@1.63.0.Left out: releases published within the last three days, namely
typescript-eslint8.71.0 with its@typescript-eslint/*packages,lint-staged17.6.0, and three transitive packages. TypeScript stays on 6.0.3, the newest 6.x release; the non-blockingtypescript7job keeps watching the 7.x line.Node 26
desktop-contract,web-contract,packageandtypescript7, the release workflow'sverifyandpublishjobs, and the documentation build move from Node 24 to 26. Thequalitymatrix still covers 22, 24 and 26, andengines.nodestays>=22.12.0. CONTRIBUTING now names the version CI publishes with.The release and documentation workflows run only from a tag or by hand, so this pull request's checks do not exercise them.
Verification
npm run qualityandnpm run verify:packagepass.npm install-scripts lsreports no unreviewed install scripts, andnpm install-scripts prune --dry-runfinds no stale entries.package.jsonfor all 18 devDependencies, and every newresolvedURL points at registry.npmjs.org.allowScripts.🤖 Generated with Claude Code