Skip to content
Merged
36 changes: 36 additions & 0 deletions .changeset/21094-prod-deps-group.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
---
'@objectstack/cli': patch
'create-objectstack': patch
'@objectstack/connector-mcp': patch
'@objectstack/core': patch
'@objectstack/objectql': patch
'@objectstack/rest': patch
'@objectstack/runtime': patch
'@objectstack/spec': patch
'@objectstack/driver-mongodb': patch
'@objectstack/driver-sqlite-wasm': patch
'@objectstack/driver-turso': patch
'@objectstack/mcp': patch
'@objectstack/metadata-core': patch
'@objectstack/metadata-protocol': patch
'@objectstack/metadata': patch
'@objectstack/plugin-auth': patch
'@objectstack/plugin-hono-server': patch
'@objectstack/plugin-pinyin-search': patch
'@objectstack/service-settings': patch
---

Raise the published dependency floors to the 2026-10 production dependency group. No API changes. A consumer install resolves these ranges:

Clause-②: no

- `zod` `^4.6.1` → `^4.6.5`: `@objectstack/spec`, `@objectstack/core`, `@objectstack/objectql`, `@objectstack/rest`, `@objectstack/runtime`, `@objectstack/cli`, `@objectstack/mcp`, `@objectstack/metadata`, `@objectstack/metadata-core`, `@objectstack/metadata-protocol`, `@objectstack/driver-turso`.
- `@libsql/client` `^0.17.3` → `^0.18.0`: `@objectstack/driver-turso`. Every behaviour the driver documents was re-measured on 0.18.0 and holds unchanged. That covers the URL scheme routing, the `URL_INVALID` and `URL_SCHEME_NOT_SUPPORTED` refusals, the WebSocket transport having no `fetch` or timeout seam, `syncUrl` being read only by the embedded-replica client, and the `?authToken=` precedence on `url` and `syncUrl`. The driver's refusal messages now name 0.18.0 as the measured version. 0.18.0 changes only the local `file:` client, which now pools connections. The driver creates that client only for an embedded replica, and calls only `sync()` on it.
- `@modelcontextprotocol/sdk` `^1.30.0` → `^1.30.1`: `@objectstack/connector-mcp`, `@objectstack/mcp`.
- `chalk` `^6.0.0` → `^6.0.1`: `@objectstack/cli`, `create-objectstack`. `yaml` `^2.9.0` → `^2.9.1` and `tsx` `^4.23.12` → `^4.23.15`: `@objectstack/cli`.
- `mongodb` `^7.5.0` → `^7.6.0`: `@objectstack/driver-mongodb`.
- `sql.js` `^1.14.1` → `^1.14.2`: `@objectstack/driver-sqlite-wasm`.
- `@noble/hashes` `^2.3.0` → `^2.4.0` and `jose` `^6.2.8` → `^6.2.12`: `@objectstack/plugin-auth`. The better-auth family stays at exactly `1.7.3`.
- `hono` `^4.13.5` → `^4.13.9`: `@objectstack/plugin-hono-server`.
- `pinyin-pro` `^3.29.1` → `^3.29.4`: `@objectstack/plugin-pinyin-search`.
- `@noble/ciphers` `^2.3.0` → `^2.4.0`: `@objectstack/service-settings`.
2 changes: 1 addition & 1 deletion examples/app-showcase/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
"test:smoke": "playwright test --config=playwright.config.ts"
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.30.0",
"@modelcontextprotocol/sdk": "^1.30.1",
"@objectstack/cloud-connection": "workspace:*",
"@objectstack/connector-mcp": "workspace:*",
"@objectstack/connector-openapi": "workspace:*",
Expand Down
2 changes: 1 addition & 1 deletion examples/app-todo/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@
"@objectstack/core": "workspace:*",
"@objectstack/service-automation": "workspace:*",
"@objectstack/trigger-record-change": "workspace:*",
"tsx": "^4.23.12",
"tsx": "^4.23.15",
"typescript": "^6.0.3",
"vitest": "^4.1.11"
}
Expand Down
4 changes: 2 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -230,10 +230,10 @@
"semver": "^7.8.5",
"svelte": "^5.57.1",
"tsup": "^8.5.1",
"tsx": "^4.23.12",
"tsx": "^4.23.15",
"turbo": "^2.11.5",
"typescript": "^6.0.3",
"yaml": "^2.9.0"
"yaml": "^2.9.1"
},
"engines": {
"node": ">=22.0.0"
Expand Down
2 changes: 1 addition & 1 deletion packages/adapters/hono/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
},
"devDependencies": {
"@objectstack/runtime": "workspace:*",
"hono": "^4.13.5",
"hono": "^4.13.9",
"typescript": "^6.0.3",
"vitest": "^4.1.11"
},
Expand Down
8 changes: 4 additions & 4 deletions packages/cli/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -110,15 +110,15 @@
"@objectstack/verify": "workspace:*",
"@oclif/core": "^4.13.3",
"bundle-require": "^5.1.0",
"chalk": "^6.0.0",
"chalk": "^6.0.1",
"chokidar": "^5.0.0",
"create-objectstack": "workspace:*",
"dotenv-flow": "^4.1.0",
"esbuild": "^0.28.2",
"ts-morph": "^28.0.0",
"tsx": "^4.23.12",
"yaml": "^2.9.0",
"zod": "^4.6.1"
"tsx": "^4.23.15",
"yaml": "^2.9.1",
"zod": "^4.6.5"
},
"peerDependencies": {
"@objectstack/driver-turso": "workspace:^"
Expand Down
8 changes: 4 additions & 4 deletions packages/client-react/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -28,11 +28,11 @@
},
"devDependencies": {
"@testing-library/react": "^16.3.3",
"@types/react": "^19.2.18",
"@types/react-dom": "^19.2.4",
"@types/react": "^19.3.0",
"@types/react-dom": "^19.3.0",
"jsdom": "^30.1.1",
"react": "^19.2.8",
"react-dom": "^19.2.8",
"react": "^19.3.0",
"react-dom": "^19.3.0",
"typescript": "^6.0.3",
"vitest": "^4.1.11"
},
Expand Down
2 changes: 1 addition & 1 deletion packages/client/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@
"@objectstack/runtime": "workspace:*",
"@objectstack/service-analytics": "workspace:*",
"@objectstack/service-automation": "workspace:*",
"tsx": "^4.23.12",
"tsx": "^4.23.15",
"typescript": "^6.0.3",
"vitest": "^4.1.11"
},
Expand Down
2 changes: 1 addition & 1 deletion packages/connectors/connector-mcp/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
"typecheck": "tsc --noEmit && pnpm check:test-typecheck"
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.30.0",
"@modelcontextprotocol/sdk": "^1.30.1",
"@objectstack/core": "workspace:*",
"@objectstack/spec": "workspace:*"
},
Expand Down
2 changes: 1 addition & 1 deletion packages/core/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@
"dependencies": {
"@objectstack/spec": "workspace:*",
"@objectstack/types": "workspace:*",
"zod": "^4.6.1"
"zod": "^4.6.5"
},
"keywords": [
"objectstack",
Expand Down
4 changes: 2 additions & 2 deletions packages/create-objectstack/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
"author": "Steedos",
"license": "Apache-2.0",
"dependencies": {
"chalk": "^6.0.0",
"chalk": "^6.0.1",
"commander": "^15.0.0"
},
"devDependencies": {
Expand All @@ -36,7 +36,7 @@
"tsup": "^8.5.1",
"typescript": "^6.0.3",
"vitest": "^4.1.11",
"yaml": "^2.9.0"
"yaml": "^2.9.1"
},
"repository": {
"type": "git",
Expand Down
2 changes: 1 addition & 1 deletion packages/drivers/driver-memory/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
"devDependencies": {
"@types/node": "^26.6.3",
"@types/sql.js": "^1.4.11",
"sql.js": "^1.14.1",
"sql.js": "^1.14.2",
"typescript": "^6.0.3",
"vitest": "^4.1.11"
},
Expand Down
4 changes: 2 additions & 2 deletions packages/drivers/driver-mongodb/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,14 +23,14 @@
"@objectstack/core": "workspace:*",
"@objectstack/spec": "workspace:*",
"@objectstack/types": "workspace:*",
"mongodb": "^7.5.0",
"mongodb": "^7.6.0",
"nanoid": "^6.0.1"
},
"devDependencies": {
"@objectstack/objectql": "workspace:*",
"@types/node": "^26.6.3",
"mongodb-memory-server": "^11.3.0",
"tsx": "^4.23.12",
"tsx": "^4.23.15",
"typescript": "^6.0.3",
"vitest": "^4.1.11"
},
Expand Down
2 changes: 1 addition & 1 deletion packages/drivers/driver-sqlite-wasm/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@
"@objectstack/spec": "workspace:*",
"knex": "^3.3.0",
"nanoid": "^6.0.1",
"sql.js": "^1.14.1"
"sql.js": "^1.14.2"
},
"devDependencies": {
"@objectstack/formula": "workspace:*",
Expand Down
6 changes: 3 additions & 3 deletions packages/drivers/driver-turso/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -29,12 +29,12 @@
"typecheck": "tsc --noEmit"
},
"dependencies": {
"@libsql/client": "^0.17.3",
"@libsql/client": "^0.18.0",
"@objectstack/core": "workspace:*",
"@objectstack/driver-sql": "workspace:*",
"@objectstack/spec": "workspace:*",
"nanoid": "^6.0.1",
"zod": "^4.6.1"
"zod": "^4.6.5"
},
"peerDependencies": {
"better-sqlite3": "^13.0.3"
Expand All @@ -47,7 +47,7 @@
"devDependencies": {
"@types/node": "^26.6.3",
"better-sqlite3": "^13.0.3",
"tsx": "^4.23.12",
"tsx": "^4.23.15",
"typescript": "^6.0.3",
"vitest": "^4.1.11"
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,8 @@
*
* # What was measured (all four answers are on the wire, not inferred)
*
* Measured against **`@libsql/client@0.17.4`** (`@libsql/core@0.17.4`, native
* `libsql@0.5.29`) — the range in `package.json` is `^0.17.3`, so the resolved
* Measured against **`@libsql/client@0.18.0`** (`@libsql/core@0.18.0`, native
* `libsql@0.5.29`) — the range in `package.json` is `^0.18.0`, so the resolved
* version is part of the result and this file asserts it.
*
* 1. **`url` + `?authToken=` → HONOURED.** The token becomes a real
Expand Down Expand Up @@ -278,7 +278,7 @@ describe('[#8860] `?authToken=` as a credential channel in an authored URL', ()
}
// Answer 4. A caret range means this can move without anyone editing a file;
// when it does, re-run the legs below rather than bumping this line blind.
expect(version).toBe('0.17.4');
expect(version).toBe('0.18.0');
});

describe('remote mode — the `url` channel', () => {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
* file: + syncUrl + client stub (CONTROL) -> knex on the file, 1 row, 1 after restart
* ```
*
* `@libsql/client@0.17.4` builds no embedded replica for a remote url:
* `@libsql/client@0.18.0` builds no embedded replica for a remote url:
* `lib-esm/node.js` routes http/https to its HTTP client and ws/wss to its
* WebSocket client, `syncUrl` is read only in `lib-esm/sqlite3.js` (a `syncUrl`
* grep over `http.js` / `ws.js` returns zero, while `authToken` returns six in
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* timeout in milliseconds for remote operations. Effective in replica and
* remote modes."), delivered by no code until the ADR-0049 enforce-or-remove
* ruling on it. Two arms, two seams, both measured against
* `@libsql/client@0.17.4`:
* `@libsql/client@0.18.0`:
*
* - REMOTE over HTTP: the hrana transport takes a custom `fetch`
* (`Config.fetch`) and routes EVERY request through it, the protocol-version
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
* file:<tmp>/ctl.db (CONTROL) -> local, 1 row, 1 after restart, file created
* ```
*
* `@libsql/core@0.17.4` routes on `uri.scheme.toLowerCase()`
* `@libsql/core@0.18.0` routes on `uri.scheme.toLowerCase()`
* (`lib-esm/config.js`), so the client reads `LIBSQL://` as `https` and
* `FILE:` as `file`. The host's own url sniffers select this driver
* case-insensitively too (`/^libsql:\/\//i` in the CLI's
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
* reading only that switch says an uppercase url can never reach the WebSocket
* arm. It can: `expandConfig` runs BEFORE the switch and has already lowercased
* the scheme, so the switch never sees the original casing. Measured against
* `@libsql/core@0.17.4`, whose `lib-esm/config.js` does it on one line —
* `@libsql/core@0.18.0`, whose `lib-esm/config.js` does it on one line —
* `const originalUriScheme = uri.scheme.toLowerCase();`:
*
* ```
Expand All @@ -23,7 +23,7 @@
* (and the control that makes those two a reading rather than a coincidence:
* `'LIBSQL://db.example.turso.io'` expands to `'https'`, so the same call is
* observably capable of answering something other than the input's own letters.)
* `@libsql/client@0.17.4`'s node entry is `_createClient(expandConfig(config,
* `@libsql/client@0.18.0`'s node entry is `_createClient(expandConfig(config,
* true))`, so that lowercased scheme IS what the switch reads. An uppercase
* `WSS://` url therefore reaches the WebSocket client, which has no window seam
* at all — the reading `refuseWebSocketTimeout` already stands on.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
*
* # What was measured (the reading this refusal stands on)
*
* `@libsql/client@0.17.4` routes on scheme: `wss` / `ws` go to its WebSocket
* `@libsql/client@0.18.0` routes on scheme: `wss` / `ws` go to its WebSocket
* client (`lib-esm/ws.js`), which opens `hrana.openWs(url, authToken)` and reads
* neither `Config.fetch` — the seam the HTTP arm's window rides — nor any
* timeout option: over `@libsql/hrana-client@0.10.0`'s `lib-esm/ws/*.js` and
Expand Down
24 changes: 12 additions & 12 deletions packages/drivers/driver-turso/src/turso-driver.ts
Original file line number Diff line number Diff line change
Expand Up @@ -150,7 +150,7 @@ export interface TursoDriverConfig {
* Operation timeout in milliseconds for remote operations.
* Effective in replica and remote modes; `0` or unset means no bound.
*
* What it bounds, per arm (measured against `@libsql/client@0.17.4`):
* What it bounds, per arm (measured against `@libsql/client@0.18.0`):
*
* - **Remote mode over HTTP** (`libsql://`, `https://`, `http://`): every
* request the client's HTTP transport makes, when THIS driver creates the
Expand Down Expand Up @@ -934,7 +934,7 @@ function remoteOperationTimedOut(what: string, timeoutMs: number): Error & { cod
* set.
*
* Why this seam and not `Config.timeout`: measured against
* `@libsql/client@0.17.4` (`@libsql/core@0.17.4`), that option is the BUSY
* `@libsql/client@0.18.0` (`@libsql/core@0.18.0`), that option is the BUSY
* timeout for lock contention on local `file:` databases — its own docblock
* says "remote clients ignore it" — so forwarding the driver's key to it would
* have left remote mode exactly as inert as before while giving replica mode a
Expand Down Expand Up @@ -995,7 +995,7 @@ function timeoutWindow(config: TursoDriverConfig): number | undefined {
* `wss` / `ws` → its ws client, `https` / `http` → its HTTP client), but it
* never sees the url as the author spelled it: the node entry is
* `_createClient(expandConfig(config, true))`, and `expandConfig` has ALREADY
* lowercased the scheme by then — `@libsql/core@0.17.4`,
* lowercased the scheme by then — `@libsql/core@0.18.0`,
* `lib-esm/config.js`: `const originalUriScheme = uri.scheme.toLowerCase();`.
* Executed against that version:
* `expandConfig({ url: 'WSS://db.example.turso.io' }, true).scheme === 'wss'`
Expand Down Expand Up @@ -1026,7 +1026,7 @@ function ridesWebSocketTransport(url: string): boolean {
/**
* `timeout` beside a `wss://` / `ws://` url — refused at construction.
*
* On those two schemes the window reaches nothing. `@libsql/client@0.17.4`'s
* On those two schemes the window reaches nothing. `@libsql/client@0.18.0`'s
* WebSocket client (`lib-esm/ws.js` → `hrana.openWs(url, authToken)`) consults
* neither `Config.fetch` — the seam {@link fetchBoundedBy} rides — nor any
* timeout option of its own: over `@libsql/hrana-client@0.10.0`'s
Expand Down Expand Up @@ -1064,7 +1064,7 @@ function refuseWebSocketTimeout(url: string, timeoutMs: number): never {
const err = new Error(
`\`TursoDriverConfig.timeout\` (${timeoutMs} ms) is set beside a \`${scheme}\` url, and on that ` +
`scheme it bounds nothing: a \`${scheme}\` url rides @libsql/client's WebSocket transport, which ` +
`takes no fetch and no timeout option (measured against @libsql/client 0.17.4), so the window would ` +
`takes no fetch and no timeout option (measured against @libsql/client 0.18.0), so the window would ` +
`be accepted and never delivered. Either omit \`timeout\` and run this remote unbounded, or keep it ` +
`and spell the url \`libsql://\` or \`https://\` — the client resolves \`libsql://\` to HTTPS — ` +
`where every request IS bounded and a stalled endpoint fails as TIMEOUT / 504.`,
Expand Down Expand Up @@ -1124,7 +1124,7 @@ function refuseSuppliedClientTimeout(timeoutMs: number): never {
`\`TursoDriverConfig.timeout\` (${timeoutMs} ms) is set beside \`TursoDriverConfig.client\` in remote ` +
`mode, and on that pair it bounds nothing: the window is the \`fetch\` this driver hands ` +
`@libsql/client while CREATING the remote client, and a pre-configured client is already built — ` +
`its transport is not the driver's to replace (measured against @libsql/client 0.17.4), so the ` +
`its transport is not the driver's to replace (measured against @libsql/client 0.18.0), so the ` +
`window would be accepted and never delivered. Either drop \`client\` and let the driver create the ` +
`remote client, where every request IS bounded and a stalled endpoint fails as TIMEOUT / 504, or ` +
`keep \`client\` and omit \`timeout\`, building the bound into that client yourself when you call ` +
Expand Down Expand Up @@ -1275,7 +1275,7 @@ function refuseIgnoredSyncKey(message: string): never {
* comparing the scheme's letters in any case?
*
* A url's scheme is case-insensitive, and `@libsql/client` reads it that way:
* `@libsql/core@0.17.4` `lib-esm/config.js` routes on
* `@libsql/core@0.18.0` `lib-esm/config.js` routes on
* `uri.scheme.toLowerCase()`. Executed against that version, `expandConfig`
* answers `https` for `LIBSQL://…`, `wss` for `Wss://…` and `file` for
* `FILE:./x.db`, and `createClient` opens each of them. Every reader of the url
Expand Down Expand Up @@ -1307,7 +1307,7 @@ function isFileUrl(url: string): boolean {
/**
* Does this url name an in-memory database, by `@libsql/client`'s own reading?
*
* `@libsql/core@0.17.4` `lib-esm/config.js` expands a bare `:memory:` to
* `@libsql/core@0.18.0` `lib-esm/config.js` expands a bare `:memory:` to
* `file::memory:`, and `isInMemoryConfig` then answers true for a `file` scheme
* whose path is `:memory:` or starts with `:memory:?`. Mirrored here so the
* replica refusal below covers exactly the urls the client's own embedded
Expand Down Expand Up @@ -1351,7 +1351,7 @@ type LocalEngineDefect = 'remote-url' | 'unrecognised-url' | 'in-memory-replica'
* `URL_INVALID` ("Embedded replica must use file for local db"). So:
*
* - `'remote-url'`: a url {@link TursoDriver.detectMode} would call remote, in
* a local or replica mode. `@libsql/client@0.17.4` builds no embedded replica
* a local or replica mode. `@libsql/client@0.18.0` builds no embedded replica
* for it: `lib-esm/node.js` routes `http`/`https` to its HTTP client and
* `ws`/`wss` to its WebSocket client, and `syncUrl` is read by
* `lib-esm/sqlite3.js` alone (a `syncUrl` grep over `http.js` and `ws.js`
Expand All @@ -1376,7 +1376,7 @@ type LocalEngineDefect = 'remote-url' | 'unrecognised-url' | 'in-memory-replica'
*
* The scheme is now matched in any letter case (see {@link startsWithScheme}),
* so an uppercase remote url is remote, as the client routes it. What is left
* has no durable reading at all: `@libsql/client@0.17.4` refuses a bare path
* has no durable reading at all: `@libsql/client@0.18.0` refuses a bare path
* as `URL_INVALID` ("not in a valid format") and an unsupported scheme as
* `URL_SCHEME_NOT_SUPPORTED`. Treating a bare path as `file:` instead was
* rejected: that invents a url spelling the client refuses, so the same
Expand Down Expand Up @@ -1447,7 +1447,7 @@ function refuseNonDurableLocalEngine(
`read back, then be lost on restart, and none of them would reach the remote. ` +
(mode === 'replica'
? '(@libsql/client builds a plain remote client for a remote url and ignores `syncUrl` beside ' +
'it, measured against @libsql/client 0.17.4, so there is no embedded replica to sync.) '
'it, measured against @libsql/client 0.18.0, so there is no embedded replica to sync.) '
: '') +
`To use the remote database, ${toRemote}. ${toLocal}`;
} else if (defect === 'unrecognised-url') {
Expand Down Expand Up @@ -1480,7 +1480,7 @@ function refuseNonDurableLocalEngine(
'local SQLite engine that can open only a `file:` url or `:memory:`. On this url it would run ' +
'on a private in-memory database instead: writes would succeed and read back, then be lost on ' +
'restart. (@libsql/client refuses such a url itself: a bare path as URL_INVALID, an unsupported ' +
`scheme as URL_SCHEME_NOT_SUPPORTED, measured against @libsql/client 0.17.4.) ${toFile} ${toRemote}`;
`scheme as URL_SCHEME_NOT_SUPPORTED, measured against @libsql/client 0.18.0.) ${toFile} ${toRemote}`;
} else {
const drop = config.mode
? "`mode: 'replica'`" + (config.syncUrl ? ' and `syncUrl`' : '')
Expand Down
Loading
Loading