Skip to content

chore(control-plane): update npm dependencies to the newest supported versions - #1419

Merged
raydocs merged 3 commits into
mainfrom
claude/deps-control-plane-20261006
Oct 6, 2026
Merged

raydocs merged 3 commits into
mainfrom
claude/deps-control-plane-20261006

Conversation

@raydocs

@raydocs raydocs commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Owned by the ops plan (docs/ops/plan-2026-09-11.md); not a ship gate. Supersedes dependabot #1381, whose CI is red because it moves vitest to 5.x.

What changes

  • @cloudflare/workers-types 5.20260911.1 → 5.20261006.1, fast-check 4.5.3 → 4.10.2, jsdom 30.0.1 → 30.1.2, vite 8.3.0 → 8.3.3, wrangler 4.131.1 → 4.148.0, overrides.sharp 0.35.4 → 0.35.5 (GHSA-wq5f-xc86-pv6w).
  • No source, config or test change.

Held, and why

  • vitest and @vitest/coverage-istanbul stay on 4.1.11. @cloudflare/vitest-pool-workers 0.22.0 is the newest release and declares vitest ^4.1.0. Tried anyway, not committed: with vitest 5.0.3 every test file fails to start ([vitest-pool]: Failed to start cloudflare-pool worker … SyntaxError: Unexpected identifier 'file', 44 errors, no tests run).

Verification

  • MacBook, Node 24: rm -rf node_modules && npm ci ok; npm run typecheck ok; npm test 44 files / 1002 tests passed, coverage identical to the baseline on main; wrangler deploy --dry-run bundles both Workers.
  • Not run: any deploy or remote wrangler command, check:contract, check:budgets. ci-gate on the exact head is read on GitHub.

Limitations

  • npm audit still reports high findings under miniflare (undici, pinned by miniflare) and source-map-js (transitive); the only automated fix downgrades the pool to 0.16.16.
  • wrangler moves 17 minor versions; the deployed bundle is only proven by the dry-run and the tests until the next deploy.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Cq68RQJmV6Xiao13p3SEat

raydocs and others added 2 commits October 6, 2026 13:11
… versions

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cq68RQJmV6Xiao13p3SEat
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cq68RQJmV6Xiao13p3SEat
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor
check measured budget
console initial JS gzip 206.2 KB 400.0 KB
console total JS gzip 319.7 KB 600.0 KB
console files over 400 lines 0 0
Worker src/index.ts lines 3783 3783

@raydocs

raydocs commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Review record (jev-route)

  • Decision 8dcffa01, run c9129b08, range origin/main...fd8c0801b: single slot, Opus 5.5 (jev-reviewer), verified by Codex gpt-6.1-sol. PASSED, 0 blocking.
  • opus:F1 (minor, record): the changelog did not name this PR and gave the wrong baseline. Fixed in 615ea3ddb (docs only: PR chore(control-plane): update npm dependencies to the newest supported versions #1419, baseline 5a77c6b68). No code changed after the reviewed head.
  • Not verifiable by the reviewer offline, checked here instead: npm ci, typecheck, npm test (44 files / 1002 tests) and both wrangler deploy --dry-run bundles ran locally before the PR; hosted services / control-plane and services / migrations ran on this head.
  • ci-gate on the exact head 615ea3ddb88405d6544684fc0a2914928a7617fc: run 37519599990 SUCCESS
  • Review threads: 0 unresolved; no CHANGES_REQUESTED.
  • Held and why (unchanged): vitest / @vitest/coverage-istanbul stay on 4.1.11 because @cloudflare/vitest-pool-workers 0.22.0 peers vitest ^4.1.0. Supersedes dependabot chore(deps-dev): Bump the control-plane group in /services/control-plane with 7 updates #1381.

@raydocs
raydocs marked this pull request as ready for review October 6, 2026 20:02
@raydocs
raydocs merged commit e762329 into main Oct 6, 2026
18 checks passed
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant