Skip to content

cli: move to the @oclif/core 5 line, with plugin-help 7 and plugin-plugins 7 in the same commit (replaces Dependabot #21034, #21031, #21035) #21125

Description

@objectstack-fleet

Filing-gate class: ③ maintainer-directed task.
Body last written 2026-10-01T13:28Z: unblocked. #21094 closed completed when PR #21162 merged as f3b16fc2f3. The area rule was re-derived with no new blocker, and the card was dispatched in the same act.
Routing: the maintainer direct-dispatch channel (session_018gA1pE6eJtwHhqx72G8U9X) routes this card to domain:cli and area:devpath; triage grades the priority.
Acting reader: the maintainer direct-dispatch session (Seat: domain:devx#3). The maintainer directed it 「相关卡片你使用项目经理技能派发处理」, and it dispatches one os-dev.
Dedup: a semantic issue search ("upgrade @oclif/core to version 5 for the cli") returned 0. I also listed 789 objectstack issues over REST (open, plus the most recently updated closed) and grepped them for oclif/core 5, plugin-help 7, plugin-plugins 7, #21034, #21031 and #21035. The only hit was #21094, which names those PRs only in its serial-constraints note. No card covers this upgrade.

Maintainer ruling (verbatim)

三组大版本升级:同意

  • oclif:关三个 PR,立卡(推荐)。

Given in session session_018gA1pE6eJtwHhqx72G8U9X on 2026-10-01, in reply to the seat's risk read of the open Dependabot major bumps.

Why one card instead of the three Dependabot PRs

All three Dependabot PRs are closed in favour of this card.

  • They are coupled. @oclif/plugin-help@7.0.2 and @oclif/plugin-plugins@7.0.3 both depend on @oclif/core ^5.0.0 (measured with npm view). Landing any one of the three alone leaves two copies of @oclif/core in the lockfile. The pairs also conflict with each other in pnpm-lock.yaml.
  • Each Dependabot lockfile carries unrelated movement, including nodemailer going DOWN from 10.0.12 to 10.0.11. That downgrade is in every npm Dependabot PR opened on 2026-10-01.
  • chore(deps)(deps): bump @oclif/core from 4.13.3 to 5.1.2 #21034 has no changeset, yet @oclif/core is a production dependency of the published @objectstack/cli.
  • Code risk measured on chore(deps)(deps): bump @oclif/core from 4.13.3 to 5.1.2 #21034's CI is low. The only breaking change upstream states is "require Node >=22", which matches packages/cli engines (>=22.0.0). The CLI's Test Core shards were green on core 5.1.2.

What to do

  1. One commit bumps all three: @oclif/core ^5.1.2 in dependencies, and @oclif/plugin-help ^7.0.2 and @oclif/plugin-plugins ^7.0.3 in devDependencies, all in packages/cli/package.json.
  2. Regenerate pnpm-lock.yaml with the repo's tooling, starting from origin/main. Never edit it by hand.
    • Acceptance: exactly one @oclif/core copy at 5.x.
    • Acceptance: no resolved version goes DOWN against the merge base (nodemailer stays at 10.0.12 or later).
    • Acceptance: only the oclif subtree moves.
  3. Re-measure what the code says was measured on 4.13.3 — a ruling gated on a premise.
    • Premise (falsifiable; verify it FIRST): every behaviour the tree records as measured against @oclif/core@4.13.3 holds on 5.1.2.
    • Re-check command: git grep -n "4\.13\.3" -- packages/cli scripts ':!**/CHANGELOG.md'
    • It gives 17 lines at origin/main 5e470f8c1c.
    • The ones that state a measurement are in packages/cli/bin/run.js and bin/run-dev.js (inlined execute()), packages/cli/src/utils/port-contract.ts (the parser's integer handling, and the [finding] os dev --port is unvalidated and os start --port is unbounded — both forward to the serve child on a channel that renames the operator's input #12673 re-measure), and scripts/check-cli-test-child-env.mjs (isProd() and the ts-path skip).
    • Also in the set: the literal 'module: @oclif/core@4.13.3' in packages/cli/test/unbuilt-workspace-lead.test.ts, and the comment in scripts/check-cli-command-ids.mjs.
    • If the premise holds, update each site to the version actually measured.
    • ⛔ If any of them no longer holds, do not force it. Stop and report the fork with the differing measurement.
  4. Changeset: add a patch changeset for @objectstack/cli, which is in the fixed group. It should say that the exported Command classes now build on @oclif/core 5 and that Node 22 or later is required.
  5. Apply needs:pack-smoke to the PR, so the packed tarball's install and run is tested. That job is opt-in and was skipped on all three Dependabot PRs.

Out of scope (a separate maintainer question)

packages/cli/package.json lists both plugins in oclif.plugins, but only as devDependencies. oclif loads oclif.plugins only from dependencies, so neither plugin ever loads, and os help and os plugins are not registered commands. Whether to remove those entries or make the plugins real dependencies is put to the maintainer separately. ⛔ This card does not change it.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratedependenciesPull requests that update a dependency filedomain:cli

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions