chore(deps): take the 2026-10 production-dependency group without the better-auth family (#21094) - #21162
Conversation
… better-auth family Re-applies Dependabot's production-dependencies manifest moves onto current main, minus apps/docs (next is owned elsewhere) and minus the five better-auth family lines, which stay at 1.7.3 with their override targets. The lockfile is regenerated by `pnpm install --lockfile-only` (pnpm 10.31.0) from main's lockfile, never by hand. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
`pnpm install --lockfile-only` keeps hono at 4.13.7: the workspace override `hono@<5.0.0` rewrites every declaration to `^4.13.5`, which 4.13.7 still satisfies, so lockfile inertia leaves CI testing a version below the `^4.13.9` that plugin-hono-server publishes. Re-resolved with `pnpm --filter <the three hono importers> update --lockfile-only --no-save hono`, which moves the single hono copy to 4.13.12 (what a downstream `^4.13.9` install resolves today) without touching the override or any manifest. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
…0.18.0 Every behaviour driver-turso documents as measured against @libsql/client 0.17.4 was re-measured on the resolved 0.18.0 and holds identically: @libsql/core, hrana-client 0.10.0 and native libsql 0.5.29 are byte-identical across the two releases apart from version strings, the client's http/ws/node entries are unchanged, and the only code delta (the local sqlite3 client's connection pool) touches none of the documented readings. The version pin, the docblocks and the refusal message text now name the version actually measured. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
…y ranges move Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 19 package(s): 2 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
⛔ 2 release-owned page(s) also name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 159 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin e0d43f711484d3e392c0c43663afeb276cf7b923 && git checkout e0d43f711484d3e392c0c43663afeb276cf7b923
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin e35c40a52597c8ca7527e6dd5bc753488dd52bbf 0f87e8488985230663c0d5ede5c0929d71da204a && git checkout -B drift-repro e35c40a52597c8ca7527e6dd5bc753488dd52bbf && git merge --no-ff 0f87e8488985230663c0d5ede5c0929d71da204a
node scripts/docs-audit/affected-docs.mjs --json e35c40a52597c8ca7527e6dd5bc753488dd52bbf
|
… 0.18.0 this tree now pins The TSDoc of CREDENTIAL_URL_QUERY_PARAMS says each entry is measured "in the versions pinned by this tree" and named @libsql/core 0.17.4; with the client lifted to ^0.18.0 the tree pins only core 0.18.0, so the label would have been false in the release that ships it. Its echo in driver-credential-refusal.test.ts moves with it. Re-measured on the installed @libsql/core 0.18.0 (expandConfig, with a config-level authToken 'BINDER'): - url ?authToken=URLTOK -> authToken URLTOK (the URL overrides) - url ?auth%54oken=URLTOK -> authToken URLTOK (key percent-decoded) - url ?AuthToken= / ?token= -> URL_PARAM_NOT_SUPPORTED - control, no query string -> authToken BINDER Identical to the 0.17.4 reading; core 0.17.4 and 0.18.0 differ only in their package.json version. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
Review: ACCEPT, patch round 1, PR #21162 (head
|
Contract reviewServed-tier: Inputs read: card #21094 (body and all 7 comments), PR #21162 (body, 54-file list, both PR comments), the net diff ① Derived judgments
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS |
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 36857772834 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
Merge-queue ejection: triage, PR #21162 (head
|
Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
…d regenerate the lockfile Main's driver-turso change added `"tsx": "^4.23.12"` with a lockfile importer at 4.23.12, while this branch lifts tsx to ^4.23.15 everywhere and drops the tsx@4.23.12 entries. The two lockfiles merged as text into one that `pnpm install --frozen-lockfile` refuses (ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY: no entry for 'tsx@4.23.12'), reproduced locally on the merge commit. The new declaration takes the same lift, and the lockfile is regenerated with `pnpm install --lockfile-only` (pnpm 10.31.0), never edited by hand: a fixed point, frozen install passes, one tsx copy (4.23.15) for all 27 declarations, and no resolved version goes down against main e35c40a. The regeneration also returns packages/apps/account's vitest snapshot to the esbuild 0.28.1 peer variant main carries, undoing the dedupe an earlier `pnpm update` on this branch had made there. Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X Co-authored-by: Claude <noreply@anthropic.com>
Review: ACCEPT, patch round 2, PR #21162 (head
|
Contract reviewServed-tier: Inputs read at 2026-10-01T12:58Z: card #21094 (body and all 9 comments, the three os-dev reports and the PM verdicts included), PR #21162 (body, 54-file list, all 6 PR comments, the round-1 record 5930638280 on the superseded head included), the net diff of the head against its merge base ① Derived judgments
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS |
Fixes #21094
Clause-②: no
Takes the 2026-10 production-dependency group that Dependabot opened as #21029 (closed in favour of this card), without the better-auth family and without
next. Maintainer ruling, verbatim:What lands
9b0de7de73to its headc0b7dd923e) were re-applied one line at a time onto currentmain. The 64th is thetsxdevDependency feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 added topackages/drivers/driver-turso/package.json, lifted from^4.23.12to^4.23.15after feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 was merged in. Each move matched the exact old spelling or the script refused. Excluded:apps/docs/package.json(nextbelongs to [finding] main's lockfile carries two new OSV advisories (next16.3.3 GHSA-vcvr-r3jv-pc5j, critical;dompurify3.4.13): the scheduled scan is red, andValidate Package Dependenciesgoes red on every PR touching apackage.json#21055 / fix(deps): take the fix for next GHSA-vcvr-r3jv-pc5j (critical) and dompurify GHSA-p98j-92pf-mc4p #21083) and the five better-auth family lines inpackages/plugins/plugin-auth/package.json, which stay at1.7.3.pnpm-workspace.yamlis not touched. Check, taken before the feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 merge: the sorted-/+lines of this branch's manifest diff equal chore(deps)(deps): bump the production-dependencies group with 27 updates #21029's lines minus those exclusions (diffexit 0, 126 lines).pnpm-lock.yaml, regenerated with the tooling in three steps (pnpm 10.31.0, thepackageManagerpin), never by hand:pnpm install --lockfile-only, starting from main's lockfile.pnpm --filter @objectstack/plugin-hono-server --filter @objectstack/plugin-auth --filter @objectstack/hono update --lockfile-only --no-save hono. Step 1 lefthonoat 4.13.7, below the^4.13.9thatplugin-hono-servernow publishes. The workspace override forhono(selector below 5.0.0) rewrites every declaration to^4.13.5, which 4.13.7 still satisfies, so lockfile inertia kept the old version. CI would have certified 4.13.7 while a downstream install gets 4.13.12. That is the declared-versus-tested split the card names for better-auth. Step 2 moves the singlehonocopy to 4.13.12 without editing the override or any manifest. An unfilteredpnpm update -rwas tried and discarded: it also droppedknex'smysql2/pg/tediouspeer links in two importers.main(e35c40a52), lift driver-turso's newtsxline, and runpnpm install --lockfile-onlyagain.pnpm install --lockfile-onlyleaves it byte-identical, andpnpm install --frozen-lockfilepasses. Lockfile blob30ba2147. The resolved set is unchanged from the set the OSV scan below covered: 0 names differ.packages/drivers/driver-turso/src/**: the item-4 restamp, 21 lines in 7 files (below).packages/spec/src/data/driver/common.zod.tsanddriver-credential-refusal.test.ts: the@libsql/coreversion label is restamped from 0.17.4 to 0.18.0. The TSDoc ofCREDENTIAL_URL_QUERY_PARAMSsays it was measured "in the versions pinned by this tree", so leaving 0.17.4 would have made it false. The behaviour was re-measured identical on the installed 0.18.0:?authToken=overrides the config token,auth%54okenis decoded,AuthTokenandtokengiveURL_PARAM_NOT_SUPPORTED, and the control without a query keeps the config token..changeset/21094-prod-deps-group.md:patchfor the 19 published packages whosedependenciesrange moves. The list was re-derived from this diff and matches the PM correction on the card,plugin-authincluded (@noble/hashes,jose).Resolved versions against the merge base
Every changed
name@versionpair in thepackages:section, compared withmainate35c40a52: 25 names change. DOWN: 0.@libsql/client/@libsql/corezodapps/docsonly)@modelcontextprotocol/sdkhonomongodbmongodb-memory-server-coreonly)jose@noble/hashes@noble/ciphersreact/react-dom/@types/react/@types/react-domapps/docsonly)tsxyamlapps/docsfumadocs tree only)chalksql.jspinyin-pro@hono/node-server2.0.12,ws8.21.1,@types/ws8.18.1,eventsource-parser3.1.0bson7.3.3 and@mongodb-js/saslprep1.5.5 (withmongodb7.7.0),scheduler0.28.0 (withreact-dom19.3.0)nodemailerstays at 10.0.13, main's version and at least the required 10.0.12. Dependabot's regeneration had moved it down to 10.0.11.Item 4:
@libsql/clientlifted to^0.18.0, because the premise holdsThe premise was measured before any driver edit, three ways.
npm packof both releases.@libsql/core0.17.4 and 0.18.0 differ only inpackage.json(the version).@libsql/clientdiffers only inlib-esm/sqlite3.js,lib-cjs/sqlite3.js,lib-esm/sqlite3.d.tsandpackage.json. The change is a connection pool for the localfile:client.http.js,ws.jsandnode.jsare byte-identical. Installed side by side,@libsql/hrana-client0.10.0 and nativelibsql0.5.29 (with@libsql/linux-x64-gnu) are byte-identical too.syncUrloccurrences insqlite3.jsgo from 3 to 4 (the new pool-size line).expected '0.18.0' to be '0.17.4'). After the restamp: 2210 passed, 33 skipped. At0f87e8488, with feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's tests merged in: 2218 passed, 33 skipped, 0 failed.turso-authtoken-url-channel.test.ts:17-18libsql0.5.29; range now^0.18.0. Answers 1-4 (live wire, child-process replica endpoint) pass, 7/7 non-pin cases, as 8/8 did on 0.17.4turso-authtoken-url-channel.test.ts:2810.18.0turso-driver-remote-url-replica-refusal.test.ts:28,turso-driver.ts:1288,:1384(message)syncUrllines:http.js0,ws.js0, controlauthTokenlines 6 / 6.httpsandwsclients'sync()rejectSYNC_NOT_SUPPORTED.:memory:+syncUrlthrowsURL_INVALID("Embedded replica must use file for local db"). File 27/27 on both versionsturso-driver-timeout.test.ts:9,turso-driver.ts:152Config.fetch; replicasync()is nativehttp.js(oneconfig.fetchsite) and hrana-client byte-identical. Timeout file 5/5, supplied-client refusal file 13/13 on bothturso-driver.ts:871Config.timeoutis the busy timeout; "remote clients ignore it"api.d.tsdocblock byte-identicalturso-driver-unrecognised-url-refusal.test.ts:26,turso-driver.ts:1313,:1417(message)URL_INVALIDfor./data/app.db,data/app.db,/abs/app.db,:MEMORY:, empty,libsql:host(bare paths "not in a valid format").URL_SCHEME_NOT_SUPPORTEDforsqlite:,memory://,C:\data\app.db. File 42/42 on bothturso-driver-uppercase-ws-scheme-timeout-refusal.test.ts:15,:26,turso-driver.ts:932expandConfiglowercases the scheme before the switchWSS://…giveswss,Ws://…givesws, controlLIBSQL://…giveshttps._createClient(expandConfig(config, true))present (1 hit). File 20/20 on bothturso-driver-ws-timeout-refusal.test.ts:10,turso-driver.ts:963,:1001(message)fetchand no timeoutws.js:fetch0,timeout0. hranaws/*.js+index.jstimeout0, controlfetchoverhttp/*.js15. File 11/11 on bothturso-driver.ts:1061(message)config.fetchis read once, inside_createClientinhttp.js(byte-identical)turso-driver.ts:1212FILE:./x.dbgivesfile,Wss://giveswss,LIBSQL://giveshttps.createClientopens each (http/ws/file)turso-driver.ts:1244:memory:expands tofile::memory:;isInMemoryConfigfile::memory:.trueforfile::memory:andfile::memory:?cache=shared, controlfalseforfile:./x.dbAfter the edit,
git grep -n -E "0\.17\.[0-9]" -- packages/drivers/driver-turso/srcreturns 0 lines (exit 1). The control is the 230.18.0occurrences in the same 7 files.What #21029 never measured
cf1d700b, before themainmerge:rest250 files, 4728 passed / 248 skipped.driver-sql205 files, 3303 passed / 188 skipped.plugin-email31 files, 510 passed.plugin-approvals52 files, 804 passed.plugin-webhooks13 files, 160 passed.trigger-schedule8 files, 170 passed.connector-mcp3 files, 23 passed.client-react3 files, 34 passed. Turbo ran 45 of 45 tasks, exit 0.Lint & Repo Gatesfromcheck:vendor-export-contracton:pnpm check:vendor-export-contractreadsVERDICT: PASS — vendor export contract (installed workspace), 1 edge(s) verified(better-auth 1.7.3), and the-resolvevariant passes on the registry. The 72 later steps of that job were not run here. They belong to CI's run on this PR. The families this diff derives are below.osv-scannerv2.3.8, built from the Go module proxy because this container's egress refusesapi.osv.dev. It ran on the offline npm database over lockfile blob70547c67(its resolved set is identical to the current30ba2147), with the repo'sosv-scanner.tomlloaded: 1388 packages,No issues found, exit 0. Positive control: the same lockfile withhonorewritten to 4.12.32 gives exit 1 and 8 advisories onhono, among them GHSA-8j4g-w8fx-2239. CI's online step is the authoritative reading.zod4.6.5 andz.properties():git grep -n -E "z\.properties\(" -- packages/returns 0 lines; controlz.object(, 1825 lines.mongodblive suites: NOT MEASURED. They need amongoddownload fromfastdl.mongodb.org, which this container's egress refuses (CONNECT 403). The defaultdriver-mongodbsuite passes: 30 files, 675 passed, 172 skipped (the five opt-in live files).Gates and tests
Gate families derived by
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands(no paths, change set from git) at HEAD0f87e8488(54 paths against merge basee35c40a52): 117 commands. All 117 exit 0, and so doespnpm check:vendor-export-contract. Exit codes were captured before any pipe.--ranreconciliation:117 derived, 117 run, 0 NOT-MEASURED, 0 UNRUN, a derived zero with an exit code on every line.Package suites, all exit 0:
cf1d700b:driver-mongodb,mcp32/344,plugin-hono-server27/324,plugin-auth115/2472,service-settings33/584,plugin-pinyin-search2/21,driver-sqlite-wasm36/675,driver-memory69/1613,service-analytics155/3526 (10 skipped),create-objectstack16/247,@objectstack/hono5/122. Also@objectstack/cli--project unit242/3432 and@objectstack/spec--project local591 files / 17368 passed.typecheck: the 19 moving packages plusclient-react,@objectstack/honoandlint. Turbo ran 80 of 80 tasks.0f87e8488, after the feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160 merge and a full rebuild: thedriver-tursosuite (82 files) gives 2218 passed / 33 skipped / 0 failed. That includes feat(driver-turso): the remote transport issues auto_number values from the shared persistent sequence (#21113) #21160's new tests, run on 0.18.0; its two-process concurrency test overlapped, with 400 writes and 400 distinct numbers.typecheckpasses, andpnpm install --frozen-lockfilepasses.Acceptance notes
zod4.6.1,react19.2.8 andyaml2.9.0 are kept only by the excludedapps/docstree.@noble/ciphers2.3.0 is kept only by the excluded better-auth 1.7.3.mongodb7.5.0 is kept only by the test harnessmongodb-memory-server-core11.3.0.:memory:and for embedded replicas. On a replica, a secondsync()therefore waits for the first to release the connection. On 0.17.4 the two ran at once on the same native handle. Withtimeoutset, a sync that outlives the window keeps running natively, uncancelled, so the next periodic sync queues behind it. No driver docblock claims either behaviour.CHANGELOG.md, onlyservice-packageindex.ts:192andmysql2-tuple.test.ts:172name 0.17.4 ("Measured on@libsql/client0.17.4"). That is a dated attestation and stays true; theresult.rowsshape was re-measured identical on 0.18.0.AGENTS.mdwhenever an agent runs a repository-scoped turbo command. It was restored after each turbo run withgit restore --source=HEAD --staged --worktree AGENTS.md. No commit on this branch touchesAGENTS.md.tsxat 4.23.12 while this branch removestsx@4.23.12. The two lockfiles merged into one thatpnpm install --frozen-lockfilerefuses. Fixed by mergingmainate35c40a52, lifting thattsxline, and regenerating the lockfile with pnpm.Generated by Claude Code