Skip to content

chore(deps): move the CLI to @oclif/core 5, with plugin-help 7 and plugin-plugins 7 in one commit (#21125) - #21212

Merged
objectstack-fleet[bot] merged 4 commits into
mainfrom
claude/issue-21125-oclif-core-5
Oct 1, 2026
Merged

objectstack-fleet[bot] merged 4 commits into
mainfrom
claude/issue-21125-oclif-core-5

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #21125
Clause-②: no

What this does

Moves @objectstack/cli to the @oclif/core 5 line, under the maintainer's ruling:

三组大版本升级:同意

  • oclif:关三个 PR,立卡(推荐)。
  • One commit bumps all three (7649ab48b), all in packages/cli/package.json: @oclif/core ^4.13.3 → ^5.1.2 in dependencies, and @oclif/plugin-help ^6.2.58 → ^7.0.2 and @oclif/plugin-plugins ^5.4.87 → ^7.0.3 in devDependencies.
  • pnpm-lock.yaml is regenerated, not hand-edited. It was produced with pnpm install --lockfile-only on top of origin/main and then installed with --frozen-lockfile.
  • Every site that recorded a behaviour as measured on 4.13.3 was re-measured on 5.1.2, then restamped (20b92f56d). The premise held at every site. The readings are below.
  • Changeset. Adds .changeset/21125-oclif-core-5.md: a patch for @objectstack/cli saying that the exported Command classes now build on @oclif/core 5 and that Node 22 or later is required.
  • Out of scope. oclif.plugins in packages/cli/package.json is unchanged; that question is with the maintainer. Both plugins stay in devDependencies.

Lockfile against the merge base (0d421041d)

The pnpm-lock.yaml diff is +45/-65. In importers, only the three packages/cli entries move. The resolved packages compare like this:

package before after
@oclif/core 4.13.3 5.1.2
@oclif/plugin-help 6.2.58 7.0.2
@oclif/plugin-plugins 5.4.87 7.0.3
ejs 3.1.10 6.0.1
jake, filelist 10.9.4, 1.0.6 removed (dependencies of ejs 3 only)
is-wsl, is-docker 2.2.0 + 3.1.1, 2.2.1 + 3.0.0 3.1.1, 3.0.0 (the 2.x copies were @oclif/core 4's only)
wsl-utils 0.1.0 0.1.0 + 0.4.0
powershell-utils none 0.1.0
npm 11.19.0 11.21.0 (under @oclif/plugin-plugins 7, which asks for ^11.19.1)
  • 11 package names changed, and every one is in the oclif subtree.
  • 0 resolved versions went DOWN.
  • The lockfile holds exactly one @oclif/core copy, 5.1.2.
  • nodemailer does not move: it is 10.0.13 on both sides.

Item 3: the premise holds, so the bump lands

The premise was verified before any site was touched.

Upstream. The changelog from 4.13.3 to 5.1.2 lists one BREAKING change, in 5.0.0: "require Node >=22, drop EOL Node versions". After that come OCLIF_STDIN_TIMEOUT_MS in 5.1.0 (the default stays 10 ms) and lint-driven refactors. Every 5.x release declares engines.node >=22.0.0, and packages/cli already declares the same floor.

Packages. I diffed the npm tarballs of 4.13.3 and 5.1.2 file by file: 33 lib/*.js files differ. Apart from the Node floor, these are the behavioural changes. None of them touches a surface this tree depends on.

  • Help templates render through ejs 6 instead of 3.
  • is-wsl is replaced by a dynamic import('wsl-utils'), which makes getPlatform() and getShell() async. Neither is in the package's exports map.
  • readStdin() resolves undefined instead of null.
  • loadHelpClass() now falls back to the compiled path. This CLI configures no helpClass.
  • Plugin holds the value of the warning's module: line in a #private field.

Per-site readings

Each probe was run from this package on 4.13.3 (base fbcc05f40) and on 5.1.2, with the same source tree.

site recorded behaviour reading on 5.1.2 verdict
bin/run.js:8, bin/run-dev.js:8 inlined execute() is verbatim apart from the added lines lib/execute.js is byte-identical in 4.13.3, 5.0.0 and 5.1.2 (sha256 5ef58b0a…) held, restamped
bin/run.js:34; published-entry-node-env-source-reroute.test.ts:9; the three serve-*.e2e.test.ts docblocks; check-cli-test-child-env.mjs:187,1093,1600 tsPath() skips the lookup only when isProd(); enableAutoTranspile is read ahead of it; four-row NODE_ENV table Config.load() on this package resolves dist/commands for an unset or production NODE_ENV and src/commands for development and test, identical to 4.13.3. The isProd() body is identical. In ts-path.js only one split('.', 1) changed. held, restamped. The pinned line moves from util.js:66 to :65.
port-contract.ts:38,98,104 a flag's parse and its min/max never run over a default (seven-row table) Driving Parser.parse reproduces all seven rows. parse.js:420-426 is unchanged. held, restamped
port-contract.ts:375 the integer parser is /^-?\d+$/ lib/flags.js and lib/args.js are byte-identical. 18 Flags.integer readings (14 inputs, 4 of them also against min/max) and 7 Parser.parse legs come out identical, for example 03000 → 3000. held, restamped
check-cli-command-ids.mjs:385 a module without a command class produces Warning: Error with module, task, plugin and message lines the same lines, now reading module: @oclif/core@5.1.2 held, restamped
unbuilt-workspace-lead.test.ts:62,160 module: line of two transcripts 5.1.2 builds the detail from the same lines in the same order (addErrorScope differs only in _base → #base). The classifier reads message: only. held, kept verbatim: they are transcripts of a 4.13.3 run, and the docblock now says so
bin/run-dev.js:470-476 (no version stamp) displayWarnings() runs before the first await in Config.load() load() still opens with it. run-dev-unbuilt-workspace.e2e is green. held
bin/run.js:89-92 (no version stamp) oclif.plugins loads from dependencies only, so os --help lists no plugins loadCorePlugins is identical, and the root help lists neither plugins nor help held

Help output. All 139 rendered help pages are byte-identical between 4.13.3 and 5.1.2: the root page, 64 commands and 74 topics, rendered in process from the same tree. This also covers the ejs 3 → 6 change.

Published entry (node bin/run.js). Six invocations return the same exit code, stdout sha256 and stderr sha256 on both versions:

  • --version
  • --help
  • an unknown command (exit 2)
  • dev --no-ui (exit 2, with the INVOCATION ERROR lead)
  • serve --port abc (exit 1)
  • serve --port 3e3 (exit 1)

Packed tarball. pnpm pack writes @oclif/core ^5.1.2, ^7.0.2 and ^7.0.3 into the tarball's manifest. Run from the extracted package, bin/run.js --version and --help both exit 0. The install-from-tarball smoke belongs to needs:pack-smoke.

Tests and gates

  • Bump commit 7649ab48b (base fbcc05f40):
    • pnpm --filter @objectstack/cli typecheck is green. The test-layer ledger holds at 3 files, 28 errors and 6 signatures.
    • --project unit: 242 files, 3435 tests, all pass.
    • --project integration: 68 of 69 files pass. The 1 red is the environment-only CONTROL leg described below.
    • OS_TEST_TIERS=nightly (the e2e tier): 76 files, 775 tests, all pass.
  • Merged head cdfd7fd72:
    • typecheck is green.
    • --project unit: 242 files, 3436 tests, all pass.
    • --project integration: 69 of 70 files pass, including validate-lint-mapping-connector-source.test.ts. The 1 red is the same CONTROL leg.
    • e2e subset: 6 files, 25 tests, all pass. These are the three edited serve-* files, build-json-undeclared-key-parity, run-dev-unbuilt-workspace and serve-node-env-production-default.
  • Final head ee3dbc6b4. Its merge brought no packages/cli, lockfile or pnpm-workspace.yaml change.
    • dispatch-gates --commands derives 95 commands. All 95 exit 0.
    • --ran reconciles them as 95 derived, 95 run, 0 NOT-MEASURED, 0 UNRUN.
    • An earlier pass on 20b92f56d read check:dual-build-cjs-loads and check:i18n-coverage as PREREQUISITE NOT MET (exit 3). Both turned green after a full build, and both are green on this head.

Acceptance notes

  • An environment-only red, the same on base and branch. One test fails in this container: published-entry-node-env-source-reroute.test.ts, the leg "CONTROL: neutralising the declaration in the child reproduces the card verbatim". It fails identically on base fbcc05f40, which runs @oclif/core 4.13.3, with 1 failed and 4 passed and the same assertion.
    • The cause is tsx registration. registerTsx() in oclif imports tsx/dist/esm/api/index.cjs. Its register() throws ERR_MODULE_NOT_FOUND for …/tsx/dist/esm/api/esm/index.mjs, so tsx is never registered and the trap is never reached. The CLI prints its version and exits 0.
    • The reroute itself still fires: the neutralised output names packages/cli/src/commands. CI's reading of this leg decides. Nothing was filed for it.
  • oclif.plugins is untouched. It still lists two plugins that are only devDependencies, so neither ever loads. That question is with the maintainer.

Generated by Claude Code

claude added 4 commits October 1, 2026 13:45
…in-plugins 7.0.3

All three ranges move in one commit in packages/cli/package.json:
@oclif/core ^5.1.2 (dependencies), @oclif/plugin-help ^7.0.2 and
@oclif/plugin-plugins ^7.0.3 (devDependencies). Both plugins depend on
@oclif/core ^5.0.0, so the lockfile resolves exactly one core copy.

pnpm-lock.yaml regenerated with `pnpm install --lockfile-only`; only the
oclif subtree moves (ejs 3 -> 6 with jake/filelist gone, is-wsl 2 ->
wsl-utils 0.4, npm 11.19.0 -> 11.21.0 under plugin-plugins), and no
resolved version goes down against the merge base.

Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X
Co-authored-by: Claude <noreply@anthropic.com>
….1.2

Every behaviour the tree recorded as measured against @oclif/core 4.13.3
was re-measured on the 5.1.2 the lockfile now resolves, and each holds:

- `lib/execute.js` is byte-identical across 4.13.3, 5.0.0 and 5.1.2, so
  the `execute()` inlined in bin/run.js and bin/run-dev.js is still
  verbatim apart from the added lines.
- `tsPath()` still reads `settings.enableAutoTranspile` ahead of
  `isProd()`, `isProd()` keeps its body (now at `lib/util/util.js:65`),
  and `Config.load()` on this package resolves `dist/commands` for an
  unset or `production` NODE_ENV and `src/commands` for `development`
  and `test`, the same four rows.
- The integer flag parser is unchanged (`/^-?\d+$/`), and driving
  `Parser.parse` reproduces the port-contract table row for row: a
  flag's `parse` and `min`/`max` never run over a `default`, and do run
  over argv and the `env:` option.
- A command module that fails to load or exports no command class still
  produces a `module/task/plugin/root/(code)/message` warning detail.

The two `module:` lines in unbuilt-workspace-lead.test.ts are
transcripts of a 4.13.3 run and stay as recorded; the docblock now says
why. Adds the patch changeset for @objectstack/cli.

Claude-Session: https://claude.ai/code/session_018gA1pE6eJtwHhqx72G8U9X
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added the size/s label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

⚠️ 4 changed file(s) yielded no anchor (packages/cli/bin/run-dev.js, packages/cli/bin/run.js, packages/cli/package.json, …), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files. Nothing else in this diff resolved to a documentable surface (no symbol, route or SDK anchor derived from 1 changed package(s)).

What this run could not see
  • 4 changed file(s) yielded no anchor (packages/cli/bin/run-dev.js, packages/cli/bin/run.js, packages/cli/package.json, …) — pages documenting those are invisible to this run
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 25 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json b42e03467361dc07dd9c3586897c6496f839253c → packageMentionDocs.

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation tests tooling labels Oct 1, 2026
@objectstack-fleet objectstack-fleet Bot added the needs:pack-smoke Opt-in pre-merge pack smoke: self-declared breaking auth/audience change (see CONTRIBUTING.md) label Oct 1, 2026
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Review: ACCEPT, PR #21212 (head ee3dbc6b4a), card #21125

Reviewed 2026-10-01T16:54Z by the PM seat (session_018gA1pE6eJtwHhqx72G8U9X) against GitHub, the branch and the npm tarballs.

Verified at the head:

  • Shape. The PR is a draft against main. Its body opens Fixes #21125, with no other closing keyword. The assignee is os-bill, and the PR is subscribed to the dispatching session. The history is two commits (7649ab48b bump, 20b92f56d restamps) plus two merges of main; nothing was rebased, amended or force-pushed.
  • Scope. 13 files, +81/−86. check-governed-merges reads NOT governed, 167 changed lines.
  • Manifest. packages/cli/package.json changes exactly three lines: @oclif/core ^5.1.2 (dependencies), @oclif/plugin-help ^7.0.2 and @oclif/plugin-plugins ^7.0.3 (devDependencies). oclif.plugins is untouched, as the card rules.
  • Lockfile against the merge base 0d421041d.
    • 11 names change, and 0 resolved versions go down.
    • There is one @oclif/core copy, 5.1.2.
    • Every non-oclif move traces to the oclif subtree. ejs 6.0.1 and wsl-utils 0.4.0 come from @oclif/core@5.1.2; npm 11.21.0 comes from @oclif/plugin-plugins@7.0.3; powershell-utils comes from wsl-utils@0.4.0. filelist, jake, is-docker and is-wsl 2.x drop out.
  • Item 3: the premise held, re-checked independently by the seat.
  • The three remaining 4.13.3 lines are the two module: transcript literals in test/unbuilt-workspace-lead.test.ts, plus the docblock sentence that explains them. They record a 4.13.3 run, nothing reads them (the classifier reads message:), and restamping them would fabricate a transcript. They stay.
  • Changeset. .changeset/21125-oclif-core-5.md is a patch for @objectstack/cli. It names the move to @oclif/core 5 for code extending the exported Command classes, and the Node ≥ 22 floor. Its byte-for-byte claims are backed by the os-dev's measurement: all 139 rendered help pages are identical, and --version, --help, an unknown command, dev --no-ui, serve --port abc and serve --port 3e3 give the same exit codes and output hashes on both versions.
  • Docs. No page, example, skill or other package pins an @oclif/core range. The plugin-authoring page imports @oclif/core unversioned, so nothing published becomes false.

Contract review: waived by the maintainer for this PR. Verbatim: 「不需要 独立契约复核」 (given in session session_018gA1pE6eJtwHhqx72G8U9X, 2026-10-01). No CONTRACT_REVIEW_TIER record is owed on this PR. The seat checked the changeset prose against the measurements above in its place.

Noted from the report: the CONTROL leg of published-entry-node-env-source-reroute.test.ts reds in the dev container. It reds identically on the base with 4.13.3, because tsx's ESM API path is missing there. CI's Test Core on this head decides it.

Landing: needs:pack-smoke is applied, so the packed-tarball install runs in CI. The PR is flipped to ready and queued once every check on this head is green, or a skip on the expected-skips roster. The packed-tarball smoke must actually run, not skip.


Generated by Claude Code

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 1, 2026 17:24
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 1, 2026 17:24
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit e2ed61a Oct 1, 2026
41 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-21125-oclif-core-5 branch October 1, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation needs:pack-smoke Opt-in pre-merge pack smoke: self-declared breaking auth/audience change (see CONTRIBUTING.md) size/s tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cli: move to the @oclif/core 5 line, with plugin-help 7 and plugin-plugins 7 in the same commit (replaces Dependabot #21034, #21031, #21035)

2 participants