Skip to content

chore: bring development dependencies current and build on Node 26 - #84

Merged
kkdev92 merged 2 commits into
mainfrom
chore/dependencies-20260929
Sep 29, 2026
Merged

kkdev92 merged 2 commits into
mainfrom
chore/dependencies-20260929

Conversation

@kkdev92

@kkdev92 kkdev92 commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Brings the development toolchain current: the devDependency ranges, a lockfile refresh within them, the allowScripts pins, and Node 26 for the jobs that run on a single version. Consumers are unaffected: the package has no runtime dependencies, and engines is unchanged.

Why

The allowScripts pins had drifted from the lockfile. They pin exact versions, and esbuild has resolved to 0.28.2 while its entry named 0.28.1. npm 11 therefore skipped esbuild's install script and printed "install scripts not yet covered by allowScripts" on every install in the Node 24 and 26 jobs. Nothing failed, because esbuild's platform binary arrives as an optional dependency and the script only fetches it when that is missing, which is how the drift went unnoticed.

Transitive packages only move when something regenerates the lockfile, so thirty of them had newer releases within their ranges. One of them is @playwright/browser-chromium, whose install script downloads the browser the web extension host lane drives, so its pin moves in the same change.

Dependencies

Package Range
@types/node ^26.6.2 → ^26.6.3
@vitest/coverage-v8 ^5.0.1 → ^5.0.2
esbuild ^0.28.1 → ^0.28.2
knip ^6.37.0 → ^6.38.0
lint-staged ^17.3.0 → ^17.5.1
prettier ^3.9.8 → ^3.9.9
typescript-eslint ^8.66.0 → ^8.70.1
vitest ^5.0.1 → ^5.0.2

The ranges follow what the lockfile already resolves, so none of them moves a resolved version. Thirty transitive packages do move (playwright 1.63.0 among them), and two nested copies are deduplicated. The allowScripts pins now name esbuild@0.28.2 and @playwright/browser-chromium@1.63.0.

Left out: releases published within the last three days, namely typescript-eslint 8.71.0 with its @typescript-eslint/* packages, lint-staged 17.6.0, and three transitive packages. TypeScript stays on 6.0.3, the newest 6.x release; the non-blocking typescript7 job keeps watching the 7.x line.

Node 26

desktop-contract, web-contract, package and typescript7, the release workflow's verify and publish jobs, and the documentation build move from Node 24 to 26. The quality matrix still covers 22, 24 and 26, and engines.node stays >=22.12.0. CONTRIBUTING now names the version CI publishes with.

The release and documentation workflows run only from a tag or by hand, so this pull request's checks do not exercise them.

Verification

  • npm run quality and npm run verify:package pass.
  • npm install-scripts ls reports no unreviewed install scripts, and npm install-scripts prune --dry-run finds no stale entries.
  • The lockfile root matches package.json for all 18 devDependencies, and every new resolved URL points at registry.npmjs.org.
  • In CI, the four single-version jobs ran on Node 26, both host contract lanes and the package checks pass, and no install reports scripts outside allowScripts.

🤖 Generated with Claude Code

kkdev92 and others added 2 commits September 29, 2026 13:36
Raises the devDependency ranges that sat below what the lockfile resolves,
refreshes the transitive packages that had newer releases within their
ranges, and moves the two allowScripts pins onto the versions now installed.

    @types/node          ^26.6.2  -> ^26.6.3
    @vitest/coverage-v8  ^5.0.1   -> ^5.0.2
    esbuild              ^0.28.1  -> ^0.28.2
    knip                 ^6.37.0  -> ^6.38.0
    lint-staged          ^17.3.0  -> ^17.5.1
    prettier             ^3.9.8   -> ^3.9.9
    typescript-eslint    ^8.66.0  -> ^8.70.1
    vitest               ^5.0.1   -> ^5.0.2

The ranges follow the lockfile, so none of them moves a resolved version.
Thirty transitive packages do move, playwright 1.63.0 among them, and two
nested copies are deduplicated.

## Why the allowScripts pins change

The entries pin exact versions, so they fall behind whenever the lockfile
moves. esbuild has resolved to 0.28.2 while its entry named 0.28.1: npm 11
skipped its install script and reported it as not covered by allowScripts on
every install. Nothing failed, because esbuild's platform binary arrives as an
optional dependency and the script only fetches it when that dependency is
missing. The refresh also moves @playwright/browser-chromium to 1.63.0, whose
install script downloads the browser the web extension host lane drives, so
its pin moves with it.

## Left out

Releases published within the last three days: typescript-eslint 8.71.0 with
its @typescript-eslint/* packages, lint-staged 17.6.0, and three transitive
packages. TypeScript stays on 6.0.3, the newest 6.x release.

## Verification

`npm run quality` and `npm run verify:package` pass. `npm install-scripts ls`
reports no unreviewed install scripts, and `npm install-scripts prune
--dry-run` finds no stale entries. The lockfile root matches package.json for
all 18 devDependencies.

knip again hints that `lint-staged` could leave `ignoreDependencies`. The hint
appears only where `.husky/` exists; a clean checkout has none, so the entry
stays.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
desktop-contract, web-contract, package and typescript7, the release
workflow's verify and publish jobs, and the documentation build now run on
Node 26, the newest release line, instead of 24. The quality matrix still
covers 22, 24 and 26, and engines.node stays >=22.12.0, so the supported
range is unchanged. CONTRIBUTING now names the version CI publishes with.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kkdev92
kkdev92 merged commit a7785ed into main Sep 29, 2026
10 checks passed
@kkdev92
kkdev92 deleted the chore/dependencies-20260929 branch September 29, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant