Skip to content

Add npm to Dependabot and update dependencies - #58

Merged
dduugg merged 5 commits into
mainfrom
update-dependencies
Sep 30, 2026
Merged

dduugg merged 5 commits into
mainfrom
update-dependencies

Conversation

@dduugg

@dduugg dduugg commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Brings over the Dependabot and dependency work done in rubyatscale/packwerk-vscode (#27 to #35 there). There are five commits, which can be reviewed separately.

  • Dependabot npm updates: adds the npm ecosystem to .github/dependabot.yml, using the same block as packwerk-vscode. Minor and patch updates come as one monthly grouped PR, majors come as separate PRs, and all updates have a 7-day cooldown.
    • It uses versioning-strategy: increase-if-necessary. By default, Dependabot raises every range in package.json, which would move @types/vscode to ^1.138.0, above engines.vscode. vsce refuses to package that combination (Raise the minimum VS Code version to 1.110 #57), and CI doesn't run vsce, so it would first fail at publish time.
    • With increase-if-necessary, updates that fit the current range change only package-lock.json.
  • In-range updates: npm update changes the lockfile only; no ranges change. That includes @types/vscode 1.110.0 → 1.138.0, typescript-eslint 8.57 → 8.71, ESLint 10.1 → 10.11, Jest 30.3 → 30.5, Prettier 3.8 → 3.9, webpack 5.105 → 5.111 and webpack-cli 7.0 → 7.2. It also moves fast-uri from 3.1.7 to 3.1.8, which clears the one moderate advisory npm audit reports on main.
  • TypeScript 5.9 → 6.0: pinned to ~6.0.3. TypeScript 7 is out, but typescript-eslint supports only <6.1.0. TypeScript 6 changes two defaults that affect this repo:
    • types now defaults to [], so tsconfig.json lists node and jest.
    • strict now defaults to true. It replaces the narrower strictNullChecks, and its only new errors are the two catch blocks that read .message. A small errorMessage() helper handles them and logs the same text as before.
  • js-yaml 4 → 5: js-yaml 5 ships its own types, so @types/js-yaml is removed.
    • Its load() now defaults to the YAML 1.2 core schema, which doesn't resolve << merge keys. A team config that inherits slack.room_for_humans through <<: *defaults would lose its Slack button. Team configs are now loaded with CORE_SCHEMA.withTags(mergeTag), the migration guide's way to restore v4 behavior.
    • js-yaml 5 is larger: the bundle grows from 48.8 KB to 70.1 KB, and the .vsix from 20 KB to 24.6 KB.
  • Lockfile regenerated with npm 11.19.0: the first CI run failed at npm ci. CI's Node 24.21 ships npm 11.19.0, which rejected the lockfile my local npm 11.6.1 wrote as out of sync: it was missing top-level @emnapi/core and @emnapi/runtime, optional peers used by unrs-resolver's WebAssembly fallback. Running npm install under 11.19.0 adds them and changes some peer flags. No other versions change, and both npm versions now accept the lockfile.

Not updated, as requested: @types/node 26 (it stays on 25.x, now 25.9.8) and TypeScript 7.

Worth deciding separately

  • @types/vscode vs engines.vscode: the installed types are now 1.138.0, while engines.vscode is ^1.110.0. That reopens the gap Raise the minimum VS Code version to 1.110 #57 closed: the compiler won't catch use of APIs newer than 1.110. The range is unchanged, so vsce still packages, and the new Dependabot group would make the same lockfile bump next month anyway. To keep them matched, either ignore @types/vscode updates in Dependabot and bump it together with engines.vscode, or raise engines.vscode.
  • npm run lint already fails on main: .prettierrc sets singleQuote: true, and Prettier also applies it to YAML. It flags the double quotes in .github/dependabot.yml, .github/workflows/codeql.yml and .github/workflows/zizmor.yml, with both Prettier 3.8.1 and 3.9.9. CI doesn't run lint. The new Dependabot block follows the file's existing double-quote style.

Test plan

  • Clean npm ci under both npm 11.6.1 and 11.19.0 (the version CI uses), then npm run build:prod, npm t and npx vsce package. The package has 7 files and is 24.61 KB.
  • tsc --noEmit and ESLint (type-aware, via tsconfig.eslint.json) pass. Prettier passes on the changed source and config files.
  • Smoke test of the bundled extension, since the repo has no tests. I loaded dist/extension.js with a stubbed vscode API and a fake workspace containing bin/codeownership and a team YAML that uses <<: *defaults. The status bar, info message and actions matched main's bundle in three cases: success, a failing bin/codeownership, and output on stderr. As a control, a build without mergeTag lost the Slack action.
  • npm audit: 0 vulnerabilities (main has 1 moderate, fast-uri).
  • Fresh Eyes local review: one minor finding, an Error with an empty message logging "" instead of "Error". Fixed in the TypeScript commit.
  • CI passes on Ubuntu and Windows.

Group minor and patch updates into one monthly PR with a 7-day cooldown,
matching the github-actions entry. Majors arrive as separate PRs so
each can be migrated on its own.

Use the increase-if-necessary versioning strategy so updates that fit
the existing range change only package-lock.json. The default strategy
raises every range, including @types/vscode past engines.vscode, and
vsce refuses to package when the @types/vscode range exceeds
engines.vscode (see #57). CI doesn't run vsce, so that would first fail
at publish time.
Run npm update, which moves every package to the newest version its
range allows, including transitive dependencies. No ranges in
package.json change. Notable direct updates:

- @types/node 25.5.0 -> 25.9.8
- @types/vscode 1.110.0 -> 1.138.0
- @typescript-eslint/* 8.57.2 -> 8.71.0
- eslint 10.1.0 -> 10.11.0
- jest 30.3.0 -> 30.5.2, ts-jest 29.4.6 -> 29.4.14
- prettier 3.8.1 -> 3.9.9
- ts-loader 9.5.4 -> 9.6.2
- webpack 5.105.4 -> 5.111.1, webpack-cli 7.0.2 -> 7.2.3

webpack 5.111 replaces terser-webpack-plugin with webpack's own
minimizer-webpack-plugin, and jest-haste-map 30.5 adds @parcel/watcher.
TypeScript 7 is out, but typescript-eslint supports only >=4.8.4 <6.1.0,
so pin ~6.0.3, the latest release it supports.

TypeScript 6 changes two defaults that matter here:

- types defaults to [], so the declarations in @types/node and
  @types/jest (setTimeout, describe, and built-in modules like path and
  fs) are no longer loaded implicitly. List both. @types/vscode and
  @types/js-yaml still resolve through their imports.
- strict defaults to true. Set it explicitly in place of the narrower
  strictNullChecks. It reports only catch variables typed as unknown,
  at the two catch blocks that read .message. Add an errorMessage()
  helper: for the Error and stderr-string rejections those blocks see,
  it logs the same text as before.
js-yaml 5 ships its own type declarations, so drop @types/js-yaml. The
namespace import and yaml.load() call keep working unchanged.

Its load() now defaults to the YAML 1.2 core schema, which no longer
resolves `<<` merge keys. A team config that inherits
slack.room_for_humans through `<<: *defaults` would lose its Slack
action, so load team configs with CORE_SCHEMA plus mergeTag, the
migration guide's way to restore v4's merge handling. The other v5
changes don't affect this call: load() now throws on empty input, and
getSlackChannel() already returns undefined when load() throws.
@dduugg
dduugg requested a review from a team as a code owner September 30, 2026 19:47
CI's Node 24.21 ships npm 11.19.0, whose npm ci rejected the lockfile
written by npm 11.6.1 as out of sync: it was missing top-level
@emnapi/core and @emnapi/runtime. They are optional peers of
@napi-rs/wasm-runtime, part of unrs-resolver's WebAssembly fallback,
so nothing failed locally.

npm install under 11.19.0 adds those two entries. The other changes
are peer flags that 11.19.0 records differently. No other package
versions change, and both npm 11.6.1 and 11.19.0 now accept the
lockfile in npm ci.
@dduugg
dduugg merged commit 43f0c8c into main Sep 30, 2026
7 checks passed
@dduugg
dduugg deleted the update-dependencies branch September 30, 2026 20:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant