Skip to content

chore(windows): update frontend and Rust dependencies to the newest supported versions - #1421

Merged
raydocs merged 2 commits into
mainfrom
claude/deps-windows-20261006
Oct 6, 2026
Merged

raydocs merged 2 commits into
mainfrom
claude/deps-windows-20261006

Conversation

@raydocs

@raydocs raydocs commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Owned by the ops plan (docs/ops/plan-2026-09-11.md); not a ship gate. Supersedes dependabot #1403 (frontend) and #1384 (Rust), both red.

What changes

  • Frontend: pnpm update --latest for 25 packages, among them @tauri-apps/api and cli 2.12.1, the six Tauri JS plugins, vite 8.3.2, vitest 5.0.3, eslint 10.12.0, typescript-eslint 8.71.1. pnpm outdated now lists only typescript.
  • Rust: cargo update in the four Windows lockfiles (apps/windows, app, service, crates/tono-plugin-core). tauri 2.11.5 → 2.12.1, wry 0.55.1 → 0.57.0, tao 0.35.3 → 0.37.1, webview2-com 0.39.1, windows 0.62.2, hyper 1.12.0, rustls 0.23.45, tokio 1.53.2; Rust and JS Tauri plugins on the same minor. No Cargo.toml change.

Why the dependabot PRs were red

Held, and why

  • typescript 6.0.3: typescript-eslint 8.71.1 declares typescript >=4.8.4 <6.1.0 and refuses to load on TypeScript 7.
  • minisign-verify =0.2.5 (dependabot wanted 0.3.0 in the Service): the pin exists so the Service verifies with the version the App's Tauri updater locks, and tauri-plugin-updater 2.13.1 still locks 0.2.5.
  • Majors that need call-site changes are not in this PR: ed25519-dalek 3, keyring 4, boa_engine 0.22.

Verification

  • The lockfiles were generated on a hosted ubuntu-24.04 runner with the pinned 1.98.1 toolchain (throwaway branch and workflow, run 37517123885, deleted after use) because the MacBook does not run cargo.
  • MacBook, frontend only: typecheck 79 (baseline 79); vitest 56 files / 393 tests; test:dev-control 123 pass; the three node contract tests 21 pass; web:build ok.
  • Not run locally: any Rust compile or test. ci-gate on the exact head is the first compile.

Limitations

  • tauri, wry, tao and webview2-com are the window and WebView runtime. Nothing on hardware has seen the window, tray or updater on the new versions; that belongs to the next 0.0.75 candidate's device round.
  • CI does not run tauri build; packaging is only proven by the candidate workflow.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Cq68RQJmV6Xiao13p3SEat

raydocs and others added 2 commits October 6, 2026 13:14
…upported versions

Frontend: pnpm update --latest for everything but TypeScript (held by
typescript-eslint's peer range). Rust: cargo update in the four Windows
lockfiles, generated on a hosted runner; no Cargo.toml change, and
minisign-verify stays on the version the Tauri updater locks.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cq68RQJmV6Xiao13p3SEat
@raydocs

raydocs commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Review record (jev-route)

  • Decision 11b0fb99, run 1518639e, range origin/main...262abd112 (protected path): triple, Opus 5.5 + Codex gpt-6.1-sol + Grok 4.7, each verified by another vendor. PASSED, 0 blocking.
    • codex:F1 = grok:F1 (minor, record): the counts in the changelog did not match the diff. Fixed in 191236e52 (docs only): 23 package.json declarations; by crate name app 167 changed / 5 added / 10 removed, plugin-core 102 / 1 / 12, service 21, workspace 14.
    • opus:F1 (minor): refuted by the verifier; the plugin-core starting version (tauri 2.11.6) is now stated anyway.
    • opus:F2 (suggestion, open): the Cargo.toml floors (tauri = "2.11.5", plugin 2.6.0 …) were not raised with the lockfiles, so a regenerated lock could in principle resolve older Rust plugins than the JS side. Not changed here: the lockfiles are committed and tooling/scripts/tests/windows-tauri-plugin-versions.test.mjs fails CI on any JS/Rust minor mismatch.
  • All three reviewers list as unverifiable offline: the upstream changelogs of tauri 2.12 / wry 0.57 / tao 0.37 and the plugins (default permission sets, shell/http/fs scopes, updater signature handling), and auto-launch 0.5 → 0.6 on Windows. No capability or permission file changed in this PR; behaviour on a real Windows machine is not verified and goes to the 0.0.75 candidate's device round.
  • ci-gate on the exact head 191236e52dec524a45df526e7f92b8d6e36e9ae8: run 37521498536 SUCCESS. The previous head 262abd112 (identical code) was the first hosted compile of these lockfiles: windows / app-rust, service, core, app all passed.
  • Review threads: 0 unresolved; no CHANGES_REQUESTED.
  • Held and why (unchanged): minisign-verify 0.2.5 (the Tauri updater locks it and the Service pins the same version on purpose); ed25519-dalek 3, keyring 4, boa_engine 0.22 are majors that need call-site changes. Supersedes dependabot chore(deps): bump the windows-frontend group across 1 directory with 20 updates #1403 and chore(deps): Bump the windows-rust group across 2 directories with 3 updates #1384.

@raydocs
raydocs marked this pull request as ready for review October 6, 2026 20:02
@raydocs
raydocs enabled auto-merge October 6, 2026 20:02
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant