Skip to content

build(deps): update effect monorepo - #247

Merged
ncaq merged 1 commit into
masterfrom
renovate/effect-monorepo
Sep 19, 2026
Merged

ncaq merged 1 commit into
masterfrom
renovate/effect-monorepo

Conversation

@renovate

@renovate renovate Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@effect/cli (source) 0.77.00.77.2 age confidence
@effect/platform (source) 0.97.10.97.2 age confidence
@effect/platform-node (source) 0.108.10.108.2 age confidence
effect (source) 3.22.13.22.2 age confidence

Release Notes

Effect-TS/effect (@​effect/cli)

v0.77.2

Compare Source

Patch Changes

v0.77.1

Compare Source

Patch Changes

Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the Type: Dependencies Dependency issues or Changes to dependency files label Sep 12, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effectモノレポのパッチバージョン更新のみで、package-lock.json以外の変更はありません。

  • effect 3.22.1 -> 3.22.2
  • @effect/platform 0.97.1 -> 0.97.2
  • @effect/platform-node 0.108.1 -> 0.108.2
  • @effect/cli 0.77.0 -> 0.77.1

いずれもバグ修正中心のパッチリリースで破壊的変更はなく、package.jsonのバージョンレンジとも整合しています。依存関係の追加・削除もありません。セキュリティ・コード品質・パフォーマンス・テスト・ドキュメントの観点でも指摘事項はありませんでした。

Review metadata

Comment thread package-lock.json
@renovate
renovate Bot force-pushed the renovate/effect-monorepo branch from 8fad84b to 665a31b Compare September 19, 2026 01:35

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

前回レビュー(commit 8fad84b)以降の差分はpackage-lock.jsonのみで、@effect/cli 0.77.1 -> 0.77.2 とそれに伴う間接依存toml 3.0.0 -> 4.3.0 のメジャーアップデートです。

toml 4.x は7年ぶりの再開発リリースですが、同一メンテナによるもので、プロトタイプ汚染(GHSA-v5mp-jgw5-2x6j)とスタックオーバーフローによるクラッシュ(GHSA-82x6-q7mm-w9cf)の修正を含むため、セキュリティ上はむしろ改善です。engines.node: >=20 要求も本リポジトリの >=22.22 で満たしています。toml@effect/cliConfigFile 経由でのみ使われますが、本リポジトリは @effect/cli から ArgsCommand しか使っていないため挙動への影響はありません。

コード品質・パフォーマンス・テスト・ドキュメントの観点でも新たな指摘はありません。前回のAPPROVE判定を維持します。

Review metadata

Comment thread package-lock.json
@renovate
renovate Bot force-pushed the renovate/effect-monorepo branch from 665a31b to 9b7f895 Compare September 19, 2026 11:32

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

前回レビュー(commit 665a31b)以降の差分はrebaseに伴うpackage-lock.jsonの再生成のみで、依存内容そのものに新しい変更はありません。

変更内容はEffectモノレポのパッチ更新(effect 3.22.1 -> 3.22.2, @effect/platform 0.97.1 -> 0.97.2, @effect/platform-node 0.108.1 -> 0.108.2, @effect/cli 0.77.0 -> 0.77.2)と、それに伴う推移的依存toml 3.0.0 -> 4.3.0 のままです。

今回検出された指摘はいずれも既存の未解決レビュースレッドで指摘済みの内容と同一のため、新規インラインコメントはありません。コード品質・パフォーマンス・テスト・ドキュメントの観点でも指摘事項はなく、前回のAPPROVE判定を維持します。

Review metadata

@renovate
renovate Bot force-pushed the renovate/effect-monorepo branch from 9b7f895 to e606a22 Compare September 19, 2026 12:45

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

前回レビュー(commit 9b7f895)以降はmasterへの追従リベースによるpackage-lock.jsonの再生成のみで、依存内容自体に新しい変更はありません。

変更はEffectモノレポのパッチ更新(effect 3.22.1 -> 3.22.2, @effect/platform 0.97.1 -> 0.97.2, @effect/platform-node 0.108.1 -> 0.108.2, @effect/cli 0.77.0 -> 0.77.2)と、それに伴う推移的依存toml 3.0.0 -> 4.3.0 のままです。

今回検出された指摘はすべて既存の未解決レビュースレッドと同一内容のため、新規インラインコメントはありません。コード品質・パフォーマンス・テスト・ドキュメントの観点でも指摘事項はなく、前回のAPPROVE判定を維持します。

Review metadata

@renovate
renovate Bot force-pushed the renovate/effect-monorepo branch from e606a22 to 0407539 Compare September 19, 2026 13:01

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

前回レビュー(commit e606a22)以降の差分は、masterへの追従リベースに伴うpackage-lock.jsonの再生成のみで、依存内容自体に新しい変更はありません。

変更はEffectモノレポのパッチ更新(effect 3.22.1 -> 3.22.2, @effect/platform 0.97.1 -> 0.97.2, @effect/platform-node 0.108.1 -> 0.108.2, @effect/cli 0.77.0 -> 0.77.2)と、それに伴う推移的依存toml 3.0.0 -> 4.3.0 のままです。

今回検出された指摘はすべて既存の未解決レビュースレッドと同一内容のため、新規インラインコメントはありません。コード品質・パフォーマンス・テスト・ドキュメントの観点でも指摘事項はなく、前回のAPPROVE判定を維持します。

Internal errors

dependency-reviewerスキルの初回起動が結果を返さず再実行した

並列起動したレビュースキルのうちkyosei:dependency-reviewerのみ、初回呼び出しがJSON配列ではなくWaiting for the research agent to finish.という文字列を返して終了しました。調査用サブエージェントの完了待ちと実行終了が競合したものと思われます。同じ引数で再実行したところ正常にJSON配列が返り、そちらの結果を採用しています。欠損したままレビューを組み立ててはいません。

Review metadata

@renovate
renovate Bot force-pushed the renovate/effect-monorepo branch from 0407539 to c2bde17 Compare September 19, 2026 13:13
@renovate
renovate Bot force-pushed the renovate/effect-monorepo branch from c2bde17 to 10ecc89 Compare September 19, 2026 13:18
@ncaq
ncaq enabled auto-merge September 19, 2026 13:19
@ncaq
ncaq merged commit 8373bde into master Sep 19, 2026
6 checks passed
@ncaq
ncaq deleted the renovate/effect-monorepo branch September 19, 2026 13:22

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovateによるeffectモノレポのパッチ更新です。

  • effect 3.22.1 -> 3.22.2, @effect/platform 0.97.1 -> 0.97.2, @effect/platform-node 0.108.1 -> 0.108.2, @effect/cli 0.77.0 -> 0.77.2 のいずれもパッチリリースで、破壊的変更はありません。
  • 推移的依存の toml 3.0.0 -> 4.3.0 は @effect/cli 側の脆弱性対応 (プロトタイプ汚染およびDoS) によるもので、セキュリティ上プラスです。toml 4.x は Node.js >= 20 を要求しますが、本リポジトリの engines.node>=22.22 のため問題ありません。
  • 修正対象 (TMap、Schema、multipart、HTTPサーバ) はいずれも本プロジェクトが使用していない領域で、実質的な挙動変化はありません。

上記2点の詳細は前回レビューの解決済みインラインコメントで既に扱っているため、今回は再掲しません。コード変更はなくロックファイル更新のみで、package.json の範囲指定 (^) とも整合しています。問題は見当たりませんでした。

Review metadata

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Type: Dependencies Dependency issues or Changes to dependency files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant