Skip to content

[quantity-formatting] Bump iTwin.js core to 5.14, eslint-plugin 6.1.1, Vite 8, Vitest 4 - #1826

Open
hl662 wants to merge 3 commits into
masterfrom
nam/qf-1-tooling
Open

hl662 wants to merge 3 commits into
masterfrom
nam/qf-1-tooling

Conversation

@hl662

@hl662 hl662 commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

TL;DR

@itwin/quantity-formatting-react was still building against core 5.3/5.4 and an @itwin/eslint-plugin that pulls in the vulnerable braces, so pnpm audit reported 83 findings for the package. This updates the dev tooling to match the rest of the repo and regenerates the lockfile. Shipped code doesn't change, and the supported core version range stays at ^5.3.0.

First of three stacked PRs: tooling (this one) → format editing fixes → package cleanup.

What

Asset Why it exists
package.json devDependencies Core and build tools were on 5.3/5.4 and @itwin/eslint-plugin 5.x pulled in vulnerable braces. Moves to core ^5.14.0, eslint-plugin 6.1.1, Vite 8, Vitest 4, and @vitejs/plugin-react 6, and drops ESLint plugins that eslint-plugin 6 already includes.
sass-embedded (devDependency) Vite 8 no longer finds a Sass compiler on its own, so 13 of 22 test files couldn't import FormatPanel.scss.
vite.config.ts Removes the Sass preprocessor options that Vite 8 no longer needs.
Paste tests in FormatSample / StationBaseFactor In core-frontend 5.14, the tool manager's document-level key handler blocks Ctrl+V unless an editable element has focus. The tests now focus the input first, as a real user would.
QuantityFormatPanel.test.tsx mock types Vitest 4 types vi.fn() more strictly, so the callback mock declares its signature.
api/quantity-formatting-react.api.md API Extractor now writes component return types as React.JSX.Element instead of JSX.Element. The types themselves didn't change.
README.md The README snippets had drifted from learning-snippets, which fails check-extractions. Synced so this stack passes CI.

Core is pinned to ^5.14.0 rather than 5.14.2 because 5.14.2 is newer than the repo's minimum package age allows.

Audit

Before After
pnpm audit (all deps) 83 (4 critical, 49 high) 5 (1 high, 2 moderate, 2 low)
pnpm audit --prod (what CI checks) — No known vulnerabilities

All 5 remaining findings are dev-only: serialize-javascript and diff via @itwin/build-tools → mocha, sprintf-js via API Extractor, and i18next-http-backend via core-frontend → core-i18n. Fixing them here would need root pnpm-workspace.yaml overrides that apply to every package, and the serialize-javascript fix is a major version past what mocha expects. They belong upstream in itwinjs-core.

Validation

tsc, pnpm lint, pnpm test (153/153), pnpm build, extract-api, and check-extractions all pass.


Nambot 🤖 (powered by claude-opus-5.5)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

README assertions differ from their extraction sources and cause the documentation consistency CI check to fail.

1 open finding
What changed in this PR

Updates quantity-formatting development tooling to reduce vulnerable dependencies while preserving runtime code and the supported core version range.

Changes:

  • Upgrades core development dependencies, ESLint tooling, Vite, and Vitest.
  • Adapts Sass configuration and tests to the upgraded tools.
  • Refreshes API declarations and README examples.
File Description
packages/​quantity-formatting/​vite.config.ts Removes explicit Sass compiler options.
packages/​quantity-formatting/​src/​test/​quantityformat/​QuantityFormatPanel.test.tsx Adds a typed callback mock.
packages/​quantity-formatting/​src/​test/​quantityformat/​internal/​StationBaseFactor.test.tsx Focuses inputs before shortcut tests.
packages/​quantity-formatting/​src/​test/​quantityformat/​FormatSample.test.tsx Focuses inputs before shortcut tests.
packages/​quantity-formatting/​README.md Adds assertions to format-set examples.
packages/​quantity-formatting/​package.json Upgrades development dependencies and adds Sass.
packages/​quantity-formatting/​api/​quantity-formatting-react.api.md Refreshes React JSX return-type references.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread packages/quantity-formatting/README.md Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants