You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Filing-gate class: ③ maintainer-directed task.
Body last written 2026-10-01T13:28Z: unblocked. #21094 closed completed when PR #21162 merged as f3b16fc2f3. The area rule was re-derived with no new blocker, and the card was dispatched in the same act.
Routing: the maintainer direct-dispatch channel (session_018gA1pE6eJtwHhqx72G8U9X) routes this card to domain:cli and area:devpath; triage grades the priority.
Acting reader: the maintainer direct-dispatch session (Seat: domain:devx#3). The maintainer directed it 「相关卡片你使用项目经理技能派发处理」, and it dispatches one os-dev.
Dedup: a semantic issue search ("upgrade @oclif/core to version 5 for the cli") returned 0. I also listed 789 objectstack issues over REST (open, plus the most recently updated closed) and grepped them for oclif/core 5, plugin-help 7, plugin-plugins 7, #21034, #21031 and #21035. The only hit was #21094, which names those PRs only in its serial-constraints note. No card covers this upgrade.
Maintainer ruling (verbatim)
三组大版本升级:同意
oclif:关三个 PR,立卡(推荐)。
Given in session session_018gA1pE6eJtwHhqx72G8U9X on 2026-10-01, in reply to the seat's risk read of the open Dependabot major bumps.
Why one card instead of the three Dependabot PRs
All three Dependabot PRs are closed in favour of this card.
They are coupled.@oclif/plugin-help@7.0.2 and @oclif/plugin-plugins@7.0.3 both depend on @oclif/core^5.0.0 (measured with npm view). Landing any one of the three alone leaves two copies of @oclif/core in the lockfile. The pairs also conflict with each other in pnpm-lock.yaml.
Each Dependabot lockfile carries unrelated movement, including nodemailer going DOWN from 10.0.12 to 10.0.11. That downgrade is in every npm Dependabot PR opened on 2026-10-01.
Code risk measured on chore(deps)(deps): bump @oclif/core from 4.13.3 to 5.1.2 #21034's CI is low. The only breaking change upstream states is "require Node >=22", which matches packages/cliengines (>=22.0.0). The CLI's Test Core shards were green on core 5.1.2.
What to do
One commit bumps all three:@oclif/core^5.1.2 in dependencies, and @oclif/plugin-help^7.0.2 and @oclif/plugin-plugins^7.0.3 in devDependencies, all in packages/cli/package.json.
Regenerate pnpm-lock.yaml with the repo's tooling, starting from origin/main. Never edit it by hand.
Acceptance: exactly one @oclif/core copy at 5.x.
Acceptance: no resolved version goes DOWN against the merge base (nodemailer stays at 10.0.12 or later).
Acceptance: only the oclif subtree moves.
Re-measure what the code says was measured on 4.13.3 — a ruling gated on a premise.
Premise (falsifiable; verify it FIRST): every behaviour the tree records as measured against @oclif/core@4.13.3 holds on 5.1.2.
Also in the set: the literal 'module: @oclif/core@4.13.3' in packages/cli/test/unbuilt-workspace-lead.test.ts, and the comment in scripts/check-cli-command-ids.mjs.
If the premise holds, update each site to the version actually measured.
⛔ If any of them no longer holds, do not force it. Stop and report the fork with the differing measurement.
Changeset: add a patch changeset for @objectstack/cli, which is in the fixed group. It should say that the exported Command classes now build on @oclif/core 5 and that Node 22 or later is required.
Apply needs:pack-smoke to the PR, so the packed tarball's install and run is tested. That job is opt-in and was skipped on all three Dependabot PRs.
Out of scope (a separate maintainer question)
packages/cli/package.json lists both plugins in oclif.plugins, but only as devDependencies. oclif loads oclif.plugins only from dependencies, so neither plugin ever loads, and os help and os plugins are not registered commands. Whether to remove those entries or make the plugins real dependencies is put to the maintainer separately. ⛔ This card does not change it.
Filing-gate class: ③ maintainer-directed task.
Body last written 2026-10-01T13:28Z: unblocked. #21094 closed
completedwhen PR #21162 merged asf3b16fc2f3. The area rule was re-derived with no new blocker, and the card was dispatched in the same act.Routing: the maintainer direct-dispatch channel (
session_018gA1pE6eJtwHhqx72G8U9X) routes this card todomain:cliandarea:devpath; triage grades the priority.Acting reader: the maintainer direct-dispatch session (
Seat: domain:devx#3). The maintainer directed it 「相关卡片你使用项目经理技能派发处理」, and it dispatches oneos-dev.Dedup: a semantic issue search ("upgrade @oclif/core to version 5 for the cli") returned 0. I also listed 789 objectstack issues over REST (open, plus the most recently updated closed) and grepped them for
oclif/core5,plugin-help7,plugin-plugins7, #21034, #21031 and #21035. The only hit was #21094, which names those PRs only in its serial-constraints note. No card covers this upgrade.Maintainer ruling (verbatim)
Given in session
session_018gA1pE6eJtwHhqx72G8U9Xon 2026-10-01, in reply to the seat's risk read of the open Dependabot major bumps.Why one card instead of the three Dependabot PRs
All three Dependabot PRs are closed in favour of this card.
@oclif/plugin-help@7.0.2and@oclif/plugin-plugins@7.0.3both depend on@oclif/core^5.0.0(measured withnpm view). Landing any one of the three alone leaves two copies of@oclif/corein the lockfile. The pairs also conflict with each other inpnpm-lock.yaml.nodemailergoing DOWN from 10.0.12 to 10.0.11. That downgrade is in every npm Dependabot PR opened on 2026-10-01.@oclif/coreis a production dependency of the published@objectstack/cli.packages/cliengines(>=22.0.0). The CLI's Test Core shards were green on core 5.1.2.What to do
@oclif/core^5.1.2independencies, and@oclif/plugin-help^7.0.2and@oclif/plugin-plugins^7.0.3indevDependencies, all inpackages/cli/package.json.pnpm-lock.yamlwith the repo's tooling, starting fromorigin/main. Never edit it by hand.@oclif/corecopy at 5.x.nodemailerstays at 10.0.12 or later).@oclif/core@4.13.3holds on 5.1.2.git grep -n "4\.13\.3" -- packages/cli scripts ':!**/CHANGELOG.md'origin/main5e470f8c1c.packages/cli/bin/run.jsandbin/run-dev.js(inlinedexecute()),packages/cli/src/utils/port-contract.ts(the parser's integer handling, and the [finding]os dev --portis unvalidated andos start --portis unbounded — both forward to theservechild on a channel that renames the operator's input #12673 re-measure), andscripts/check-cli-test-child-env.mjs(isProd()and the ts-path skip).'module: @oclif/core@4.13.3'inpackages/cli/test/unbuilt-workspace-lead.test.ts, and the comment inscripts/check-cli-command-ids.mjs.patchchangeset for@objectstack/cli, which is in the fixed group. It should say that the exported Command classes now build on@oclif/core5 and that Node 22 or later is required.needs:pack-smoketo the PR, so the packed tarball's install and run is tested. That job is opt-in and was skipped on all three Dependabot PRs.Out of scope (a separate maintainer question)
packages/cli/package.jsonlists both plugins inoclif.plugins, but only asdevDependencies. oclif loadsoclif.pluginsonly fromdependencies, so neither plugin ever loads, andos helpandos pluginsare not registered commands. Whether to remove those entries or make the plugins real dependencies is put to the maintainer separately. ⛔ This card does not change it.Generated by Claude Code