Skip to content

chore(deps): raise stale transitive dependency floors - #4629

Open
nicktrn wants to merge 1 commit into
mainfrom
chore/bump-transitive-dep-floors
Open

chore(deps): raise stale transitive dependency floors#4629
nicktrn wants to merge 1 commit into
mainfrom
chore/bump-transitive-dep-floors

Conversation

@nicktrn

@nicktrn nicktrn commented Aug 15, 2026

Copy link
Copy Markdown
Collaborator

Summary

A number of pnpm.overrides entries had drifted behind the releases they were written against. An override fixes the resolved version outright, so in every one of these cases the tree was pinned to the floor value rather than picking up later releases in the same line. This raises each floor to a current release, and widens the selectors that were scoped to an exact upper bound so they keep matching.

Override Before After
body-parser (under express@^4) 1.20.3 ^1.20.6
tar 7.5.19 7.5.21
hono 4.12.25 4.12.34
undici (6.x) 6.27.0 6.28.0
undici (7.x) 7.28.0 7.29.0
js-yaml (3.x) 3.14.2 3.15.1
js-yaml (4.x) 4.1.1 4.3.1
dompurify ^3.4.1 ^3.4.13
vite ^6.4.2 ^6.4.3
protobufjs ^7.5.6 ^7.6.5
socket.io-parser ^4.2.6 ^4.2.7
postcss ^8.5.10 ^8.5.23
fast-uri ^3.1.2 ^3.1.5
brace-expansion (1.x) 1.1.13 1.1.18
brace-expansion (2.x) 2.0.3 2.1.4
brace-expansion (5.x) 5.0.6 5.0.9
ip-address (under @jsonhero/json-infer-types) ^10.2.0 ^10.3.1

Every parent's declared range still accepts the new resolution, so nothing is forced outside its stated bounds by this change.

Two of these changed a default rather than just moving version. js-yaml 4.2.0 stopped resolving underscore-separated scalars such as 1_000 as numbers, which is the YAML 1.2 behaviour, and there are none in any YAML in this repo. brace-expansion 2.1.x now caps expansion size by default, well above anything a real glob produces, and minimatch calls it with no options. Neither is reachable from how we use them.

undici@5.29.0 and vite@4.4.9 are left alone: their parents cap below the newer lines, so moving either would mean taking the parent across a major.

Verified with a clean install, and pnpm run typecheck passes.

@nicktrn nicktrn self-assigned this Aug 15, 2026
@changeset-bot

changeset-bot Bot commented Aug 15, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 68370f0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

Updated pnpm dependency overrides in package.json for body-parser, tar, hono, undici, js-yaml, dompurify, vite, protobufjs, socket.io-parser, postcss, fast-uri, brace-expansion, and ip-address.

Merge Risk: 🟡 Moderate · up to 68370

The dependency overrides currently force several packages outside the compatible ranges declared by their parents, which can produce an invalid or incompatible install tree; these selectors should be scoped or corrected before merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the dependency override updates.
Description check ✅ Passed The description clearly explains the dependency changes and records clean-install and typecheck validation, but omits the template checklist and issue reference.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/bump-transitive-dep-floors

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Open in Devin Review

Comment thread package.json

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2e80d949-5939-4071-a9a2-533023fa2e30

📥 Commits

Reviewing files that changed from the base of the PR and between b98dd79 and 68370f0.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json
📜 Review details
⏰ Context from checks skipped due to timeout. (23)
  • GitHub Check: e2e / 🧪 CLI v3 tests (warp-ubuntu-latest-x64-4x - pnpm)
  • GitHub Check: sdk-compat / Node.js 26.4 (warp-ubuntu-latest-x64-4x)
  • GitHub Check: packages / 🧪 Unit Tests: Packages (3, 3)
  • GitHub Check: typecheck / typecheck
  • GitHub Check: sdk-compat / Node.js 22.23 (warp-ubuntu-latest-x64-4x)
  • GitHub Check: sdk-compat / Bun Runtime
  • GitHub Check: packages / 🧪 Unit Tests: Packages (1, 3)
  • GitHub Check: packages / 🧪 Unit Tests: Packages (2, 3)
  • GitHub Check: sdk-compat / Node.js 24.18 (warp-ubuntu-latest-x64-4x)
  • GitHub Check: webapp / 🧪 Unit Tests: Webapp (9, 12)
  • GitHub Check: e2e / 🧪 CLI v3 tests (warp-ubuntu-latest-x64-4x - npm)
  • GitHub Check: sdk-compat / Cloudflare Workers
  • GitHub Check: sdk-compat / Deno Runtime
  • GitHub Check: webapp / 🧪 Unit Tests: Webapp (2, 12)
  • GitHub Check: sdk-compat / Node.js 20.20 (warp-ubuntu-latest-x64-4x)
  • GitHub Check: webapp / 🧪 Unit Tests: Webapp (5, 12)
  • GitHub Check: fk-cascade-guard / fk-cascade-guard
  • GitHub Check: code-quality / code-quality
  • GitHub Check: audit
  • GitHub Check: audit
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (actions)
  • GitHub Check: Build and publish previews
🧰 Additional context used
📓 Path-based instructions (1)
**/package.json

📄 CodeRabbit inference engine (AGENTS.md)

When adding Zod, use the exact repository-wide pinned version 3.25.76, never a different version or range.

Files:

  • package.json
🔇 Additional comments (2)
package.json (2)

103-104: LGTM!

Also applies to: 106-120, 122-137, 140-144


103-144: 🗄️ Data Integrity & Integration

Keep the pnpm configuration in package.json. The repository pins pnpm 10.33.2, which supports this location.

			> Likely an incorrect or invalid review comment.

Comment thread package.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant