chore(deps): raise stale transitive dependency floors - #4629
Conversation
|
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughUpdated pnpm dependency overrides in 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
68370f0 to
1c390a1
Compare
@trigger.dev/build
trigger.dev
@trigger.dev/core
@trigger.dev/python
@trigger.dev/react-hooks
@trigger.dev/redis-worker
@trigger.dev/rsc
@trigger.dev/schema-to-json
@trigger.dev/sdk
commit: |
Summary
A number of
pnpm.overridesentries had drifted behind the releases they were written against. An override fixes the resolved version outright, so in every one of these cases the tree was pinned to the floor value rather than picking up later releases in the same line. This raises each floor to a current release, and widens the selectors that were scoped to an exact upper bound so they keep matching.body-parser(underexpress@^4)1.20.3^1.20.6tar7.5.197.5.21hono4.12.254.12.34undici(6.x)6.27.06.28.0undici(7.x)7.28.07.29.0js-yaml(3.x)3.14.23.15.1js-yaml(4.x)4.1.14.3.1dompurify^3.4.1^3.4.13vite^6.4.2^6.4.3protobufjs^7.5.6^7.6.5socket.io-parser^4.2.6^4.2.7postcss^8.5.10^8.5.23fast-uri^3.1.2^3.1.5brace-expansion(1.x)1.1.131.1.18brace-expansion(2.x)2.0.32.1.4brace-expansion(5.x)5.0.65.0.9ip-address(under@jsonhero/json-infer-types)^10.2.0^10.3.1Every parent's declared range still accepts the new resolution, so nothing is forced outside its stated bounds by this change.
Two of these changed a default rather than just moving version.
js-yaml4.2.0 stopped resolving underscore-separated scalars such as1_000as numbers, which is the YAML 1.2 behaviour, and there are none in any YAML in this repo.brace-expansion2.1.x now caps expansion size by default, well above anything a real glob produces, andminimatchcalls it with no options. Neither is reachable from how we use them.undici@5.29.0andvite@4.4.9are left alone: their parents cap below the newer lines, so moving either would mean taking the parent across a major.Verified with a clean install, and
pnpm run typecheckpasses.