Skip to content

Consolidate the three stalled Dependabot bumps into one lockfile regeneration #157

Description

@os-zhuang

Filed by the repo:objectos execution seat (objectstack#9831), session session_01VFwZj1a84ZxFUcWAi5H8S5, round 1, on the maintainer's instruction to clear the open PR list ("这个清单需要合并的也要合并", 2026-08-22), who then chose this route over the alternative when both were put to them.

Why this card exists rather than three merges

Three Dependabot PRs are open, all safe patch/minor bumps, all stalled:

PR Bump Declared range today
#49 react-dom 19.2.6 → 19.2.7 ^19.2.6
#46 tailwindcss 4.3.0 → 4.3.3 ^4.3.0
#50 @tailwindcss/postcss 4.3.0 → 4.3.3 ^4.3.0

They cannot be merged as they stand and cannot be rebased by this seat:

  1. All three are ~67 commits behind and conflicted. Their only check is a build from 2026-07-19, which predates both the Node floor and Ownership & freshness gates — that green certifies nothing about today's main.
  2. All three rewrite pnpm-lock.yaml, so exactly one could land per lap even with working rebases; each merge invalidates the rest.
  3. @dependabot commands cannot be issued from this tooling. A sanitizer rewrites the mention on write — two separate sessions posted the command and both were stored as ·@·d·ependabot r·ebase. This is recorded on chore(deps): bump react-dom from 19.2.6 to 19.2.7 #49; it is a tooling artefact, not a mis-typed command, and no amount of re-asking will move the bot.

One change that regenerates the lockfile once is strictly better than three sequential rebases: one CI run, one lockfile regeneration, and one production docs deploy instead of three — deploy-docs.yml fires on every pnpm-lock.yaml push to main.

Scope

apps/docs/package.json (dependencies / devDependencies only) and pnpm-lock.yaml.

Because all three declared ranges are carets that already permit their targets, the manifest edit is the small half — the substantive change is the regenerated lockfile.

⚠️ The interaction that makes this more than a version bump

main now carries a blocking unsupported rule (landed this round as ca34d36, #137/#138): every declaration's floor — >=22.12.0 — must itself satisfy every engines.node range in pnpm-lock.yaml. A regenerated lockfile can introduce a range with a hole at 22.12.0, and that now fails CI rather than passing quietly.

Before this rule existed, a dependency bump could not redden the Node floor gate. It can now. Re-running node .github/scripts/check-node-floor.mjs after the regeneration is not optional, and a red there is a real finding, not a flake.

Definition of done

  1. The three packages resolve to their target versions in pnpm-lock.yaml.
  2. engines blocks are untouched in every package.json.
  3. node .github/scripts/check-node-floor.mjs exits 0 on the regenerated lockfile.
  4. The required build job passes.

react is already ^19.2.7 on main while react-dom sits at ^19.2.6; #49 closes that pairing gap, which is the one item here with a correctness argument behind it rather than just currency.

Once landed, #46, #49 and #50 close as superseded against the commit that carries their bumps — not on a promise. #48 (@opennextjs/cloudflare) is not in scope: it upgrades the deploy adapter itself and is held on a separate question with the maintainer.

Activity

  1. self-assigned this
    on Aug 22, 2026
  2. os-zhuang commented on Aug 22, 2026

    @os-zhuang
    ContributorAuthor

    Claim: PM loop round 1
    Session: session_01VFwZj1a84ZxFUcWAi5H8S5
    Branch: claude/issue-157-dependabot-consolidation
    Worktree: objectos-issue-157
    Domain: repo:objectos (seat objectstack#9831)
    File surface: apps/docs/package.json (dependencies / devDependencies only) · pnpm-lock.yaml (stop on breach; explain in the report)
    Container & model: S, mode:subagent, model: sonnet — dispatch-gates.mjs --tier returns no path-derived mandate. Taken at the floor rather than the default, deliberately: the change itself is mechanical (three version strings, one pnpm install) and its correctness is decided entirely by the gate farm, not by judgement. The one judgement-shaped risk — a regenerated lockfile reddening the new unsupported rule — is a measured outcome with an explicit stop-and-report, not something a higher tier would reason its way around.
    Clause-②: no
    Serial constraints cleared: now genuinely clean, and it was not when this round opened. apps/docs/package.json was contended with the folded #137+#138 unit, which edits that file's engines block; that PR merged as ca34d36, so the contention is discharged rather than assumed away. This card was held out of the earlier batch for exactly that reason — same-batch surfaces must be disjoint by construction, and these two were not. Nothing else is in flight in this lane: all three round-1 units landed (f0a830d, 539906a, ca34d36), no dev PR is open, and the only open PRs are the four Dependabot ones this card supersedes three of.

    Premise re-check at dispatch time, on origin/main at ca34d36

    Premise Verified
    react-dom declared ^19.2.6, react already ^19.2.7 ✅ the pairing gap is real
    tailwindcss / @tailwindcss/postcss both ^4.3.0 ✅
    All three carets already permit their targets ✅ so the lockfile, not the manifest, is the substantive change
    Three declarations now >=22.12.0, gate green on main ✅ ran the gate against ca34d36 myself
    deploy-docs.yml fires on pnpm-lock.yaml pushes to main ✅ read the trigger block

    The one thing that is different from every previous bump in this repo

    ca34d36 landed this round, minutes ago, and it makes the Node floor gate blocking on a property a dependency bump can break: the floor 22.12.0 must satisfy every engines.node range in the lockfile. Until today a lockfile regeneration could not redden that gate. It can now, and this is the first bump to run under the new rule.

    That is not a reason to avoid the bump — it is the rule doing its job on the first real input. But it means a red unsupported finding here is a genuine incompatibility to report, never something to work around by loosening the floor that was just ruled.


    Generated by Claude Code

  3. added a commit that references this issue on Aug 22, 2026
    af66c76
  4. os-zhuang commented on Aug 22, 2026

    @os-zhuang
    ContributorAuthor
    {
      "issue": 157,
      "status": "done",
      "branch": "claude/issue-157-dependabot-consolidation",
      "pr": "https://github.com/objectstack-ai/objectos/pull/158",
      "premise_still_valid": true,
      "summary": "Regenerated pnpm-lock.yaml once (single pnpm install) to land react-dom 19.2.6->19.2.7, tailwindcss 4.3.0->4.3.3, and @tailwindcss/postcss 4.3.0->4.3.3, replacing Dependabot PRs #49/#46/#50. react-dom was pinned to the exact 19.2.7 (dropping the caret) because a react-dom@19.2.8 patch has since been published upstream, and a caret range resolved past the named target to 19.2.8, producing a real unmet-peer warning against react@^19.2.7 (react is out of scope for this card). @opennextjs/cloudflare (#48) verified unchanged at 1.19.11. No engines block touched anywhere. Draft PR #158 opened against main.",
      "tests": "Full issue body read via issue_read (get + get_comments) before starting; body ends in a complete sentence discussing #48 scope, matches the dispatch prompt's quoted text verbatim -- no truncation observed. Worktree ../objectos-issue-157 created off origin/main@ca34d36 (confirmed ca34d36 = 'fix(ci): the declared Node floor must satisfy every dependency range...'); empty branch pushed first as write-path probe, succeeded (no 403). Baseline `node .github/scripts/check-node-floor.mjs` on ca34d36 before any edit: exit 0, 428 engines entries scanned, verdict '✅ Every declared floor clears what the dependency tree requires, and the declarations agree.' Edited apps/docs/package.json (react-dom ^19.2.6->19.2.7 exact, tailwindcss ^4.3.0->^4.3.3, @tailwindcss/postcss ^4.3.0->^4.3.3). `pnpm install` run twice: first pass with react-dom left as caret ^19.2.7 resolved to react-dom 19.2.8 with WARN 'unmet peer react@^19.2.8: found 19.2.7' (real defect, not a flake); re-pinned react-dom to exact 19.2.7 and re-ran pnpm install, exit 0, zero peer warnings, resolved exactly react-dom@19.2.7, tailwindcss@4.3.3, @tailwindcss/postcss@4.3.3 (confirmed via grep on pnpm-lock.yaml packages: section). @opennextjs/cloudflare@1.19.11 confirmed unchanged (grep, same line count/version pre and post). `node .github/scripts/check-node-floor.mjs` on regenerated lockfile: EXIT=0 (captured via PIPESTATUS before any pipe), verdict line '✅ Every declared floor clears what the dependency tree requires, and the declarations agree.' -- highest floor required 22.0.0 (wrangler/miniflare/kv-asset-handler), 430 engines entries scanned (up from 428, both new @tailwindcss/oxide platform variants), no 'unsupported' or 'lockfile' finding. Also ran `node .github/scripts/check-node-floor.mjs --self-test`: '✓ self-test: 17 rule case(s), 24 satisfies case(s) and 18 range case(s) -- every rule demonstrated able to fail, every silence-bearing rule demonstrated able to stay silent', exit 0. `npx turbo run type-check build test --force --concurrency=2` (NODE_OPTIONS=--max-old-space-size=4096): 'Tasks: 3 successful, 3 total' (@objectos/ci-scripts:test, @objectos/docs:type-check, @objectos/docs:build -- @objectos/docs has no test script and ci-scripts has no build/type-check script, so 3 is the full matched set, not a zero-match false-green: turbo printed 'Running type-check, build, test in 2 packages' and each per-task log line named its script), EXIT=0 captured pre-pipe. git diff confirmed zero `engines` hunks in any package.json. git status --porcelain after all commands: only apps/docs/package.json and pnpm-lock.yaml modified, no stray files. Full before/after lockfile diff done at package-identity level (parsed `packages:` section of git show HEAD:pnpm-lock.yaml vs working tree by name@version, script in scratchpad/issue-157/diff-lock.mjs): 20 changed entries, 0 added, 0 removed -- react-dom, tailwindcss, @tailwindcss/postcss + their direct co-versioned deps (@tailwindcss/node, @tailwindcss/oxide x12 platform variants), plus transitive drift in enhanced-resolve (5.22.0->5.24.5) and two multi-resolution additions (postcss gained 8.5.26 alongside existing 8.4.31/8.5.15; nanoid gained 3.3.18 alongside existing 3.3.12) -- all consistent with the tailwindcss/postcss chain, no unrelated packages moved. Final commit af66c761d50c25e292986468ba7d33fb7df1833b pushed to origin; PR #158 opened as draft against main, verified via pull_request_read (draft:true, base.sha=ca34d36, head.sha=af66c76, 2 files changed, body intact).",
      "open_questions": [],
      "out_of_scope_findings": []
    }

    Generated by Claude Code

  5. os-zhuang commented on Aug 22, 2026

    @os-zhuang
    ContributorAuthor

    os-dev-report

    (the HTML-comment marker on the previous comment was stripped by GitHub's body sanitizer on write — documented behavior per AGENTS.md — so this comment carries the same report, marked with the literal text instead.)

    {
      "issue": 157,
      "status": "done",
      "branch": "claude/issue-157-dependabot-consolidation",
      "pr": "https://github.com/objectstack-ai/objectos/pull/158",
      "premise_still_valid": true,
      "summary": "Regenerated pnpm-lock.yaml once (single pnpm install) to land react-dom 19.2.6->19.2.7, tailwindcss 4.3.0->4.3.3, and @tailwindcss/postcss 4.3.0->4.3.3, replacing Dependabot PRs #49/#46/#50. react-dom was pinned to the exact 19.2.7 (dropping the caret) because a react-dom@19.2.8 patch has since been published upstream, and a caret range resolved past the named target to 19.2.8, producing a real unmet-peer warning against react@^19.2.7 (react is out of scope for this card). @opennextjs/cloudflare (#48) verified unchanged at 1.19.11. No engines block touched anywhere. Draft PR #158 opened against main.",
      "tests": "Full issue body read via issue_read (get + get_comments) before starting; body ends in a complete sentence discussing #48 scope, matches the dispatch prompt's quoted text verbatim -- no truncation observed. Worktree ../objectos-issue-157 created off origin/main@ca34d36 (confirmed ca34d36 = 'fix(ci): the declared Node floor must satisfy every dependency range...'); empty branch pushed first as write-path probe, succeeded (no 403). Baseline `node .github/scripts/check-node-floor.mjs` on ca34d36 before any edit: exit 0, 428 engines entries scanned, verdict '✅ Every declared floor clears what the dependency tree requires, and the declarations agree.' Edited apps/docs/package.json (react-dom ^19.2.6->19.2.7 exact, tailwindcss ^4.3.0->^4.3.3, @tailwindcss/postcss ^4.3.0->^4.3.3). `pnpm install` run twice: first pass with react-dom left as caret ^19.2.7 resolved to react-dom 19.2.8 with WARN 'unmet peer react@^19.2.8: found 19.2.7' (real defect, not a flake); re-pinned react-dom to exact 19.2.7 and re-ran pnpm install, exit 0, zero peer warnings, resolved exactly react-dom@19.2.7, tailwindcss@4.3.3, @tailwindcss/postcss@4.3.3 (confirmed via grep on pnpm-lock.yaml packages: section). @opennextjs/cloudflare@1.19.11 confirmed unchanged (grep, same line count/version pre and post). `node .github/scripts/check-node-floor.mjs` on regenerated lockfile: EXIT=0 (captured via PIPESTATUS before any pipe), verdict line '✅ Every declared floor clears what the dependency tree requires, and the declarations agree.' -- highest floor required 22.0.0 (wrangler/miniflare/kv-asset-handler), 430 engines entries scanned (up from 428, both new @tailwindcss/oxide platform variants), no 'unsupported' or 'lockfile' finding. Also ran `node .github/scripts/check-node-floor.mjs --self-test`: '✓ self-test: 17 rule case(s), 24 satisfies case(s) and 18 range case(s) -- every rule demonstrated able to fail, every silence-bearing rule demonstrated able to stay silent', exit 0. `npx turbo run type-check build test --force --concurrency=2` (NODE_OPTIONS=--max-old-space-size=4096): 'Tasks: 3 successful, 3 total' (@objectos/ci-scripts:test, @objectos/docs:type-check, @objectos/docs:build -- @objectos/docs has no test script and ci-scripts has no build/type-check script, so 3 is the full matched set, not a zero-match false-green: turbo printed 'Running type-check, build, test in 2 packages' and each per-task log line named its script), EXIT=0 captured pre-pipe. git diff confirmed zero `engines` hunks in any package.json. git status --porcelain after all commands: only apps/docs/package.json and pnpm-lock.yaml modified, no stray files. Full before/after lockfile diff done at package-identity level (parsed `packages:` section of git show HEAD:pnpm-lock.yaml vs working tree by name@version, script in scratchpad/issue-157/diff-lock.mjs): 20 changed entries, 0 added, 0 removed -- react-dom, tailwindcss, @tailwindcss/postcss + their direct co-versioned deps (@tailwindcss/node, @tailwindcss/oxide x12 platform variants), plus transitive drift in enhanced-resolve (5.22.0->5.24.5) and two multi-resolution additions (postcss gained 8.5.26 alongside existing 8.4.31/8.5.15; nanoid gained 3.3.18 alongside existing 3.3.12) -- all consistent with the tailwindcss/postcss chain, no unrelated packages moved. Final commit af66c761d50c25e292986468ba7d33fb7df1833b pushed to origin; PR #158 opened as draft against main, verified via pull_request_read (draft:true, base.sha=ca34d36, head.sha=af66c76, 2 files changed, body intact).",
      "open_questions": [],
      "out_of_scope_findings": []
    }

    Generated by Claude Code

  6. os-zhuang commented on Aug 22, 2026

    @os-zhuang
    ContributorAuthor

    ACCEPT — PR #158

    repo:objectos seat (objectstack#9831), session session_01VFwZj1a84ZxFUcWAi5H8S5, round 1. Verified by reading the branch's lockfile directly, not the PR's tables.

    Checklist: draft ✓ · base main at ca34d36 ✓ · Fixes #157 first line ✓ · 2 files, exactly the declared surface ✓ · no changeset ✓ · not a governed surface ✓.

    Gates on af66c76: build (required) completed/success · Node floor completed/success. (Ownership & freshness correctly does not run — path-filtered to content/docs/**.)

    The check this round actually cared about

    ca34d36 landed the blocking unsupported rule ~10 minutes before this branch existed, so this is the first lockfile regeneration in this repo's history that could have reddened the Node floor gate. It did not. The gate scanned 430 engines blocks — up from 428, so the regeneration genuinely added ranges — and every one is satisfied at 22.12.0. The rule got a real input on its first day and held.

    Verified independently on the branch, not from the PR's tables

    Claim Checked
    engines untouched everywhere ✅ git diff over all package.json shows no engines/node hunks
    @tailwindcss/postcss 4.3.0 → 4.3.3 ✅
    tailwindcss 4.3.0 → 4.3.3 ✅
    react-dom 19.2.6 → 19.2.7 ✅
    react 19.2.7, unchanged — pairing now consistent ✅
    #48 did not drift in @opennextjs/cloudflare 1.19.11 → 1.19.11 ✅

    That last row is the one I most wanted to check myself, because "I didn't touch it" and "pnpm install didn't move it" are different claims and only the second one matters. Control-probed the grep against a known-present package (3 hits) so the empty scoped-package results were ruled a quoting artefact rather than read as absence.

    The deviation is correct, and it was surfaced rather than absorbed

    react-dom@19.2.8 published upstream after #49 was filed. ^19.2.7 therefore resolved to 19.2.8 and produced a real unmet peer against react@19.2.7, which is out of this card's scope to move. Pinning react-dom to exact 19.2.7 keeps the change to the three named targets and resolves clean.

    Both supporting claims hold: exact pins are already this file's convention (next, fumadocs-core, fumadocs-mdx, fumadocs-ui), and #157 names 19.2.7 specifically. Reporting the peer error verbatim instead of quietly bumping react to make it go away is the right instinct — bumping react would have been a silent scope widening dressed up as a fix.

    Transitive drift was reported rather than left for a reviewer to find, by diffing both lockfiles at package-identity level: no packages added or removed, enhanced-resolve 5.22.0 → 5.24.5, and postcss/nanoid gaining a co-resolved second version — normal pnpm multi-resolution, correctly explained rather than hand-waved. An unreported transitive bump is exactly what a reviewer cannot see, so volunteering the whole set is what makes this reviewable at all.

    Deviations: one, declared, accepted.

    Landing now; #46, #49 and #50 close as superseded against the resulting commit.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions