deps: bump typescript from 6.0.3 to 7.0.2 in /frontend - #93
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v6.0.3...v7.0.2) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
| "svelte": "^5.57.0", | ||
| "svelte-check": "^4.7.6", | ||
| "typescript": "^6.0.3", | ||
| "typescript": "^7.0.2", |
There was a problem hiding this comment.
🔴 Frontend installs fail on peer conflict
With typescript at 7, npm ci rejects the locked svelte-check peer requirement of TypeScript 5 or 6. The frontend test target and deployment rebuild cannot install dependencies.
Learn more
The lockfile retains svelte-check@4.7.6, whose peerDependencies exclude TypeScript 7. npm's normal peer resolution therefore rejects this dependency tree during npm ci. Both test-unit and the frontend rebuild run installs before checking or building the app. Bypassing the peer check does not establish compatibility: this repository documents a prior svelte-check startup failure with TypeScript 7.
Example: On a clean checkout, cd frontend && npm ci encounters TypeScript 7 alongside svelte-check@4.7.6 and stops with a peer dependency resolution error. make test-unit consequently never reaches npm run check.
Recommended fix: Keep TypeScript on the compatible 6.x line until a verified svelte-check version supports 7, or upgrade the checker and its lockfile entry together. Confirm npm ci and npm run check work without legacy-peer-deps before merging.
Was this helpful? React with 👍 or 👎 to provide feedback.
CherylSnowVeil
left a comment
There was a problem hiding this comment.
Review — dependabot typescript 6.0.3 → 7.0.2 (/frontend)
Findings
🔴 [blocking] frontend/package.json — typescript ^7.0.2 breaks npm ci via svelte-check peer conflict
This bump reintroduces the exact regression fixed in #87 (d56848f, "pin typescript ^6 so svelte-check runs"). svelte-check@4.7.6 — still the latest published release — declares peerDependencies: typescript ^5.0.0 || ^6.0.0, so the lockfile is unresolvable:
npm error ERESOLVE could not resolve
npm error While resolving: svelte-check@4.7.6
npm error Found: typescript@7.0.2
npm error Could not resolve dependency:
npm error peer typescript@"^5.0.0 || ^6.0.0" from svelte-check@4.7.6
Concrete consequence, already visible on this PR: CI test fails in test-unit at cd frontend && npm ci (Makefile:40), and the snyk job fails identically at "Install frontend dependencies". Nothing in frontend/ can be installed, built, tested, or deployed from this revision — deploy/update.sh's npm ci && npm run build path would fail too.
And it is not merely an install-time complaint: per the #87 commit message and CLAUDE.md, even forcing past the peer conflict (e.g. re-adding frontend/.npmrc with legacy-peer-deps=true, which was deliberately removed and must not come back) leaves svelte-check hard-failing in its own version guard under TS 7, silently disabling npm run check. The only supported TS 7 path today is the experimental --tsgo dual install (TS 6 plus a typescript@7 alias via @typescript/native), which this PR does not set up.
Remediation: do not merge. Close this PR and have dependabot stop proposing it (@dependabot ignore this major version, or an ignore/exclude-patterns entry for typescript majors in .github/dependabot.yml). Revisit when svelte-check publishes a release whose peer range covers TS 7.
🟢 [suggestion] .github/dependabot.yml — exclude typescript major bumps
typescript is not in the vite-toolchain group or the routine group's exclude-patterns, and major bumps bypass the minor/patch-only groups — so every TS 7.x release will spawn a new permanently-red PR like this one until it's ignored. An ignore: dependency-name: "typescript", update-types: ["version-update:semver-major"] entry (or a comment-only @dependabot ignore this major version) would stop the noise while still allowing TS 6 minor/patch bumps.
Summary
Two-file dependabot diff (package.json + package-lock.json) bumping typescript to 7.0.2. The lockfile itself is internally consistent, but the bump is unmergeable as-is: it conflicts with svelte-check's peer range, fails npm ci in two CI jobs, and undoes the deliberate ^6 pin from #87. Verified against the actual CI logs and the npm registry (latest svelte-check is 4.7.6, still typescript ^5||^6). No other changes in the diff to review.
Bumps typescript from 6.0.3 to 7.0.2.
Release notes
Sourced from typescript's releases.
Commits
1e4744dMerge branch 'main' into ts7-releasea5a219cmicrosoft/typescript-go#4558ecfe30dUpdate status localization5de25b5Hide executable name in TypeScript statusd7ce74aShow bundled TypeScript version for packaged servers29be66aCorrect TS 7 release version to 7.0.2ed2bd1bMerge branch 'main' into ts7-release8873075Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...9427131Set up stable / nightly extension split, other prep (microsoft/typescript-go#...d4eaca5microsoft/typescript-go#4549Maintainer changes
This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.
You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)