Skip to content

chore(deps): upgrade @objectstack/* to 17.5.0 - #1970

Merged
hotlong merged 4 commits into
mainfrom
claude/objectstack-release-steps-ynhz3j
Sep 30, 2026
Merged

hotlong merged 4 commits into
mainfrom
claude/objectstack-release-steps-ynhz3j

Conversation

@hotlong

@hotlong hotlong commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Description

Moves HotCRM from ObjectStack 17.4.0 to 17.5.0 (published to latest on 2026-09-29) and adopts the 17.5.0 breaking changes that reach this app's metadata. pnpm verify is green locally.

Known issue: on 17.5.0, three default list views render an error in every group. It is fixed upstream (objectui#11119, merged) and reaches HotCRM with the next platform release. The changeset records it. See Known platform issues.

Type of Change

  • Breaking change (platform major-behaviour moves; see changeset)
  • Documentation update

Changes Made

  • Bump. All 21 @objectstack/* go 17.4.0 → 17.5.0.
    • specVersion / engines.protocol move to ^17.5.0 in objectstack.manifest.json and objectstack.config.ts.
    • Lockfile: 726 → 725 packages; plugin-reports leaves the tree.
  • Dashboards. Removed 34 chartConfig.type / xAxis / yAxis keys (8271c81, #19363). Every removed value matched the widget binding. Eight charts lose their axis titles.
  • Close Case flow. The lookup screen field declares reference: 'crm_knowledge_article' (2f1a6f6, #17913), so it is now a real picker. Verified in the browser.
  • Sales Home. The four object-metric filters use the ViewFilterRule array (4792049, #17257).
  • page.assignedProfiles deleted from six pages: app_launcher, home, utility_bar, lead_detail, opportunity_detail, case_detail.
    • The maintainer approved this.
    • The spec's own refusal says the key "gated nothing: no renderer, route or metadata read door ever read the key", so page audience is unchanged.
    • The two tests that checked the retired key ran over zero pages. They are deleted, on the maintainer's decision:
      • "assignedProfiles name real profiles";
      • "every related list is readable by every profile its page is assigned to".
  • Contact section "Account & Role" → "Account & Title". The new author-time rule security-role-word reserves "role". zh/ja/es already said "job title".
  • Nested page i18n. 17.5.0 os lint now requires translations for nested and slot page components. There are 14 keys in each of zh-CN / ja-JP / es-ES.
    • A zh-CN browser check of Lead Detail shows none of these labels as visible text, so readers see no change.
    • The i18n gate's failure hint now gives os i18n extract --no-objects-only. The bare command does not scaffold page keys.
  • One driver test adapted. 17.5.0's SQL drivers withhold the operator and field names from a refused filter's message. The retired-$regex premise test now reads the full diagnostic via withheldFilterDiagnosticOf and also asserts that the public message does not name the operator.
  • Decision default flip (#15429): no edit. All 13 decisions partition their out-edges, so first-match behaves identically.
  • Docs.
    • The admin Automation page (three locales) says scheduled flows need OS_AUTOMATION_SCHEDULED_WORK_ENABLED=true.
    • whats-new gets a dated 17.5.0 line.
    • About 30 pin claims are re-scoped, not renumbered.

Testing

  • pnpm verify (validate → typecheck → lint → lint:i18n-gate → hygiene ×2 → build → test): green at e91e1b3.
    • 173 test files: 3714 passed, 1 skipped.
    • The two retired tests account for the drop from 3716.
  • In-place upgrade. objectstack dev on 17.5.0 was booted on a database that 17.4.0 created. It was ready in 16 s.
    • os migrate plan on a copy of that database: 0 destructive changes, 1 additive column.
  • Browser pass (Playwright script, the same 29 steps as the 17.4.0 baseline): 29/29 steps pass.
    • The steps cover login, 13 object lists, kanban, record pages, create, edit, 5 dashboards, search, the approvals inbox and the Close Case flow.
    • The baseline's one failure — edit-account PATCH 400 on display_title — no longer reproduces.
    • The step pass count hides the known issue below.
  • pnpm test:e2e: 16/16 on 17.5.0.

Known platform issues (filed upstream, not worked around)

  • objectui#11105 — regression, fixed upstream, not yet released. On 17.5.0, the server-grouped grid sends select=id,[object Object],… when a view's columns are objects. The Products, Knowledge Articles and Forecasts default lists show INVALID_FIELD in every group. The same views work on 17.4.0.
    • Fixed by objectui#11119 (merged).
    • It reaches HotCRM once objectstack ships a release whose @objectstack/console carries it. HotCRM then needs only a pin bump.
  • objectstack#20648. Every boot of a database created on 17.4 prints a false-positive "Paged read of 'sys_migration' is NOT deterministic" warning.
  • objectui#11002 (already open). The console probes the cloud-only GET /api/v1/usage/storage on every page, which logs a 404 on a self-hosted runtime.

Checklist

  • I have added a changeset (.changeset/objectstack-17-5-0.md)
  • I have made corresponding changes to the documentation
  • New and existing unit tests pass locally with my changes

Additional Notes

The maintainer decided to merge now rather than wait for the platform release, with the known issue recorded in the changeset. The diff touches no governed path, so it lands through the merge queue once every check is green.

Open for the maintainer, not blocking this PR:

  1. Scheduled work. Should the docs or pnpm dev turn on OS_AUTOMATION_SCHEDULED_WORK_ENABLED? Without it, Demo Bootstrap and every SLA, expiry and reminder flow stop.
  2. SaaS composition. Under isolated, each scheduled flow must name one organization.

Generated by Claude Code

…ssignedProfiles pending)

Move all 21 @objectstack/* dependencies to 17.5.0 together, with
specVersion and engines.protocol at ^17.5.0 in objectstack.manifest.json
and objectstack.config.ts. Regenerate pnpm-lock.yaml from the public
registry.

Adopt the 17.5.0 breaking changes that reach this app's metadata:

- dashboards: drop chartConfig.type / xAxis / yAxis from 34 dataset-bound
  widgets. The spec refuses them, and every removed value agreed with the
  widget's own type / dimensions / values. Axis titles are lost.
- close_case flow: the lookup screen field declares
  reference: 'crm_knowledge_article'. It is now required, and it gives the
  field a real picker.
- sales home: the four object-metric filters use the ViewFilterRule array.
- decision default flip (#15429): no edit. All 13 decisions that
  `os migrate meta --from 17` offers `mode: 'inclusive'` partition their
  out-edges, so first-match runs what every-true-edge ran.
- admin docs: scheduled flows need OS_AUTOMATION_SCHEDULED_WORK_ENABLED.

Re-scope the claims that named 17.4.0 (and four missed 17.3.0 claims) as
the current pin, and add the changeset.

NOT INCLUDED: removing page.assignedProfiles from six pages, which 17.5.0
refuses. This change was not applied in this session. Until it lands,
validate, typecheck, lint, build and boot all fail on those six keys.

Claude-Session: https://claude.ai/code/session_014VGCS11YUtYAiinRcdqQwL
Co-authored-by: Claude <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
hotcrm Ignored Ignored Sep 30, 2026 6:06am UTC

Request Review

@github-actions github-actions Bot added documentation Improvements or additions to documentation ci/cd CI plumbing and the verification pipeline dependencies Dependency bumps and lockfile changes metadata Declarative metadata — schema, security posture, UI surfaces configuration Build and app configuration files backend Server-side behaviour — hooks, flows, actions labels Sep 29, 2026
…sted page i18n

Complete the @objectstack/* 17.5.0 upgrade started in the previous commit.
`pnpm verify` is green again.

- pages: delete `assignedProfiles` from app_launcher, home, utility_bar,
  lead_detail, opportunity_detail and case_detail. spec 17.5.0 refuses
  the key. It gated nothing on 17.4.0, since no renderer, route or
  metadata read ever read it, so page audience is unchanged. The two
  tests that check declared assignedProfiles are kept as they are.
- contact: relabel the "Account & Role" section "Account & Title". The
  new `security-role-word` lint rule reserves "role", and the section
  holds the job title. Update the en bundle and the Contacts doc to
  match; zh/ja/es already said "job title".
- i18n: add the 14 page keys that 17.5.0 `os lint` now requires for
  nested and slot components, in each of zh-CN, ja-JP and es-ES.
  `os i18n extract` does not scaffold page keys.
- test: the SQL driver withholds the operator name from a refused
  filter's message. The `$regex` premise test now reads the full text
  through `withheldFilterDiagnosticOf` and also asserts that the public
  message does not name the operator.
- changeset: describe all four.

Claude-Session: https://claude.ai/code/session_014VGCS11YUtYAiinRcdqQwL
Co-authored-by: Claude <noreply@anthropic.com>
…geset's i18n claims

`os i18n extract` does scaffold page keys, but only with
`--no-objects-only`, because its default covers objects alone. The
i18n gate's failure hint gave the bare command, which does not
produce the page keys that the 17.5 `i18n/missing-page` rule asks for.
The hint now gives the full command and explains why.

Correct the changeset on two points:

- it said extract cannot scaffold page keys, which is wrong;
- it said the nested components showed English before this change. A
  zh-CN browser check of Lead Detail on 17.5.0 found none of those
  labels drawn as visible text, so readers see no change.

Claude-Session: https://claude.ai/code/session_014VGCS11YUtYAiinRcdqQwL
Co-authored-by: Claude <noreply@anthropic.com>
@hotlong hotlong changed the title chore(deps): upgrade @objectstack/* to 17.5.0 (draft, blocked on page.assignedProfiles) chore(deps): upgrade @objectstack/* to 17.5.0 Sep 29, 2026
…ouped-list known issue

Delete the two tests that checked the key this upgrade retires. The
maintainer made the call.

- "assignedProfiles name real profiles" in
  test/metadata-references.test.ts.
- "every related list is readable by every profile its page is assigned
  to" in test/authorization-coverage.test.ts.

spec 17.5.0 refuses `page.assignedProfiles`, so no page can declare it
and both tests ran over zero pages. Remove the helpers that only they
used (the `profileNames` import, the local `pages` list) and the header
comments that described their checks.

The changeset now also records the known 17.5.0 issue: the Products,
Knowledge Articles and Forecasts default lists fail in every group. It
is fixed upstream (objectui#11105, PR objectui#11119) and lands with the
next platform release.

Claude-Session: https://claude.ai/code/session_014VGCS11YUtYAiinRcdqQwL
Co-authored-by: Claude <noreply@anthropic.com>
@hotlong
hotlong marked this pull request as ready for review September 30, 2026 06:10
@hotlong
hotlong added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 284b9e4 Sep 30, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend Server-side behaviour — hooks, flows, actions ci/cd CI plumbing and the verification pipeline configuration Build and app configuration files dependencies Dependency bumps and lockfile changes documentation Improvements or additions to documentation metadata Declarative metadata — schema, security posture, UI surfaces

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants