chore(deps): resolve @objectstack/* 17.5.0, and the zod 4.6.5 it requires, in pnpm-lock.yaml (objectui#11073) - #11086
Conversation
…i#11073) Regenerated by pnpm 10.31.0, not by hand: every @objectstack/* specifier was raised to ^17.5.0 for one `pnpm install`, then every manifest was restored to HEAD and a second `pnpm install` reconciled the importers back to their declared ranges. No manifest range moves in this commit. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
… @objectstack/spec@17.5.0 uses (objectui#11073)
@objectstack/spec@17.5.0 and @objectstack/core@17.5.0 raise their zod floor
from ^4.4.3 to ^4.6.1. With only the @objectstack/* entries moved, the lock
resolved spec's zod to 4.6.5 while objectui's own direct `zod ^4.4.3`
importers (types, app-shell, components, plugin-timeline, test-support) stayed
on 4.4.3. Zod stamps its minor version into its types
(`_zod.version.minor`), so the two copies are type-incompatible and
`pnpm --filter @object-ui/types build` failed with TS2345 in
src/zod/views.zod.ts ("Type '4' is not assignable to type '6'").
Regenerated by pnpm 10.31.0, not by hand: the five direct `zod` ranges were
raised to ^4.6.1 for one `pnpm install`, then restored to HEAD and reconciled
by a second `pnpm install`. No manifest range moves; ^4.4.3 already admits
4.6.5.
Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh
Co-authored-by: Claude <noreply@anthropic.com>
|
changeset-claim-re-read
|
❌ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. Which half objected:
📦 Bundle Size Report
Size Limits
|
…ne zod 4 copy (objectui#11073) `pnpm dedupe --check` named exactly one change after the zod move: fumadocs-mdx's own `zod ^4.4.3` dependency, 4.4.3 -> 4.6.5, which removes the last zod@4.4.3. Without it `node scripts/check-lockfile-integrity.mjs` reports "zod gained a physical copy: 2 -> 3" (the Lockfile Integrity Check). Applied with `pnpm dedupe`, not by hand; the resolution census against the base lock is now the seven @objectstack/* 17.4.0 -> 17.5.0 and zod 4.4.3 -> 4.6.5, nothing else. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
❌ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. Which half objected:
📦 Bundle Size Report
Size Limits
|
…ectstack/spec 17.5.0's zod ^4.6.1 (objectui#11073) - imported-defaults-describe-9034: a ZodDefault now answers `optin: 'defaulted'` (zod 4.4.3 answered 'optional'). The census asks the UNWALKED source node, so "already omissible" counts either rung; the corpus figure (5) is unchanged. - mirror-partial-record-narrowing-8516: zod 4.6 reports a partialRecord's out-of-vocabulary key as a non-aborting `unrecognized_keys`, so the `GridSchema.columns` union returns that arm's issue alone: the key is named at `columns` (in `keys` and the message) instead of inside an `invalid_union`. The pin's intent, that the author is shown the key, holds. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
…he published @objectstack/spec 17.5.0 (objectui#11073) Each re-pin follows the spec's own new answer, or a tripwire's written instruction for the pin bump; no objectui accept set is decided here. - detail-view-field-options-10296 + zod-mirror-parity: 17.5.0 requires a non-blank `source` on the `visibleWhen` envelope. Both tripwire rows flip to refusals, and the spec-version gate SpecEnvelopeAdmitsSourceless, its gated WiderThanDeclared entries (DetailViewFieldSchema `options`, DetailViewSchema `fields`/`sections`, DetailViewSectionSchema `fields`) and their WIDER_ARMS rows are deleted, as the gate's docblock instructed; the header figures move 6/7/7 - 5/2/0/0 -> 3/3/3 - 2/1/0/0. - element-number-arm-10872 + imported-defaults-8317 + imported-defaults.ts docblock: ElementDataSourceSchema.filter is the ViewFilterRule array now, which reaches no z.lazy, so REBUILT_CLEAN is empty and the boundary hands back the spec's own object; the filter rows follow the spec's verdicts. - imported-defaults-8317 "no member became REQUIRED": zod 4.6's `'defaulted'` rung; the strip must turn it into `'optional'`. - record-highlights-layout-9187: the contract gained requiredPermissions, redactFields, enforceFieldSecurity; `layout` did not move. - calendar-doc-key-set-8830 + calendar-flat-color-allday-8466 + plugin-calendar.mdx: CalendarConfigSchema declares `allDayField`; the doc fence tracks the SPEC type, so it lists five keys, and the sentences that said the spec refuses `allDayField` are corrected. - spec-object-refinements-7715: checkListViewPageMount is no longer exported; its ListView row entry and measurement leave, as its message instructed. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
…onsole patch (objectui#11073) `patch` on @object-ui/console: the only published artifact whose bytes move is the console bundle, which inlines its @objectstack/* and zod devDependencies. No manifest range and no @object-ui/* source API moves; the @object-ui/types edits are re-read test pins and one comment. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
❌ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. Which half objected:
📦 Bundle Size Report
Size Limits
|
…ctui#11073) Six commits, none touching pnpm-lock.yaml or a manifest; merged so the patch round measures the tree the merge queue will build. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
❌ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. Which half objected:
📦 Bundle Size Report
Size Limits
|
…s terminally, restoring the objectui#9256 / #11022 refusals; DashboardWidgetSchema attaches the spec's two new checks (objectui#11073) zod 4.6 (forced by @objectstack/spec 17.5.0's zod ^4.6.1) made a strict object's `unrecognized_keys` non-aborting. A plain `z.union` whose one non-aborted failing arm is that strict object returns ITS issues alone, so the widget-slot `metric-card` lost its by-name content-channel refusal and had its registered `value` reported as unrecognized. `closedObject` / `closeStrictUnionArms` (node-derivation.ts) are the spec's own mechanism (its ZodClosedObject marks `unrecognized_keys` continue:false; not exported, so spelled here), applied only to strict arms of PLAIN unions, as closed twins: the widgets slot (DashboardComponentSchema), the calendar selection union (form.zod.ts) and every plain union on the strict authoring face. Blast radius measured over every objectui union before landing: 29 plain unions with a strict arm, none left open, 1106 probes, 0 accept-set moves, 187 error-shape moves (each a single arm's `unrecognized_keys` becoming zod 4.4's `invalid_union` with every arm). Seat ruling Q3 → A. complex.zod.ts also re-attaches the two object-level checks @objectstack/spec 17.5.0 added to DashboardWidgetSchema (checkDashboardWidgetStageOrder, checkDashboardWidgetMetricMeasureArity), under the objectui#7715 B1 ruling; the census and the parity pin for it land in the next commit with the rest of the test re-reads. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
…l refusal can no longer let run (objectui#8355, objectui#10321; objectui#11073) @objectstack/spec 17.5.0 marks a closed object's unrecognized_keys continue:false, so zod skipped ObjectViewSchema's when-guarded superRefine (checkNamedViewCalendarAliases, checkNamedViewKanbanStrayGroupBy) on exactly the documents it existed for. The document is still refused by the protocol at listViews.KEY.calendar / .kanban, naming the key. The two checks and their helper are removed; the list-view route keeps objectui's pointers. The pins re-read the protocol's refusal. Seat ruling Q2 -> A (objectui#8934 principle), no upstream card. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
…he retired page view kind, as @objectstack/spec 17.5.0 did (objectui#11073) The spec retired type: 'page', pageName and the list view's own tabs (ADR-0049). NamedListView declared pageName/tabs as 'declared inert' under objectui#8980, whose premise (the protocol declares them) is falsified; both are ?: never tombstones now with the protocol's prescriptions. The derived ViewType faces already follow the spec; core's UNDRAWABLE_VIEW_KINDS page row was deleted as its own note said it would be once the residual pins were converted, and they are (objectui#8429 now pins the closed state). The plugin-list README record drops page. Seat ruling Q4 -> A. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
…17.5.0 began exporting under check:spec-symbols (objectui#11073)
Per symbol, measured (seat ruling Q6 -> A):
- core isRefusedTextComparand / textComparandRefusalReason: the spec's are byte-identical ports of core's module, so core re-exports them from @objectstack/spec/data (describeComparand stays local; the spec does not export it). They are 17.5.0-only exports, so @object-ui/core's spec floor rises ^17.3.0 -> ^17.5.0 (core declares no zod).
- components ActionButtonProps / ActionIconProps: the spec's are the AUTHORED props bags; these are the React envelope and were never on the package's published entry, so renamed ActionButtonRendererProps / ActionIconRendererProps (objectui#7265 precedent), reason pinned in a tripwire test.
- plugin-dashboard / plugin-report DatasetTotals: the spec's is the REQUEST side ({ groupings }); these are file-local RESULT groupings, renamed DatasetResultTotals, reason pinned per package.
- plugin-gantt / plugin-map / plugin-timeline / plugin-tree ObjectXProps: React props envelope vs the spec's authored bag, measured unequal, and PUBLISHED exports, so not renamed (a public-name change): ALLOW rows carrying the measured member lists.
@object-ui/types' floors rise to @objectstack/spec ^17.5.0 and zod ^4.6.1 together (Q8): its DashboardWidgetSchema now imports two 17.5.0-only checks. pnpm-lock.yaml moves only those three importer specifiers.
Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh
Co-authored-by: Claude <noreply@anthropic.com>
…rdWidget checks; the objectui#10916 tripwire is flipped (objectui#11073) - spec-object-refinements-7715: the DashboardWidgetSchema row names checkDashboardWidgetStageOrder and checkDashboardWidgetMetricMeasureArity as attached, with a parity pin that is objectui#9111's executable criterion (a non-funnel widget with options.stageOrder refused at options.stageOrder with the spec's own message; a funnel accepted on both). - imported-defaults-8317: the two checks join the named REFINEMENT_EXCEPTIONS. - report-chart-query-spec-parity: the JoinedReportBlock state pin loses its erased arm and the tripwire row flips to typed, its version row retired, as the tripwire instructed. The published-type burn-down stays on objectui#10940. - .changeset/7715-mirrors-carry-spec-object-checks.md: a dated note (prose only, frontmatter untouched) on the two sentences 17.5.0 made false. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
✅ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. 📦 Bundle Size Report
Size Limits
|
…jectui#4795) Brings in PR #11086 (objectui#11073), which moves the workspace to @objectstack/spec 17.5.0 and zod 4.6.5. The textual merge is clean; the CLI importer's lockfile entry still names the 17.4.0 snapshot main no longer carries, and the next commit regenerates it. Claude-Session: https://claude.ai/code/session_012UwY3ahMixEFkfTUxMVkYm Co-authored-by: Claude <noreply@anthropic.com>
…he 17.5.0 snapshot (objectui#4795) `pnpm install` after merging origin/main: the `packages/cli` importer's `@objectstack/spec` (`^17.1.0`) now resolves the same `17.5.0(ai@7.0.65(zod@4.6.5))` snapshot as the rest of the workspace. The 17.4.0 snapshot it named is gone from main since PR #11086, which is what broke `pnpm install --frozen-lockfile` in the merge group. Generated, not hand-edited; no manifest moved. Claude-Session: https://claude.ai/code/session_012UwY3ahMixEFkfTUxMVkYm Co-authored-by: Claude <noreply@anthropic.com>
…keys Brings in the @objectstack/spec 17.5.0 resolution (objectui#11073, #11086), whose ElementDataSourceSchema.filter takes the ViewFilterRule array, so this branch's pins can be measured on the tree the merge queue builds. No conflicts; six files auto-merged. Refs objectui#11070 Claude-Session: https://claude.ai/code/session_012UwY3ahMixEFkfTUxMVkYm Co-authored-by: Claude <noreply@anthropic.com>
Fixes #11073
Clause-②: no — consumes the already-published
@objectstack17.5.0 contract by version; objectui adds no key, export or flag of its own, and every accept-set movement arriving through spec-by-reference pairs is enumerated in the PR for reviewWhat this PR is, at this head
pnpm-lock.yamlnow resolves@objectstack/*17.5.0 (was 17.4.0), plus thezod4.6.5 that 17.5.0 requires. No manifest range moves in this PR and no objectui packageversionmoves. The PM asked for the draft to open at the first compilable step, so this body records the readings taken on the lockfile-only head. Commits that adapt objectui to the published contract follow on this branch. The final gate readings, commit by commit, go into theos-dev-reportcomment on objectui#11073. Any later change to this body is for the seat to write.It is expected to be RED on this head, for measured reasons (below). ⛔ No red here is waved through or re-run.
H1 — premise (measured)
origin/mainc80236e: the lock resolved@objectstack/{spec,types,sdui-parser,lint,formula,core,client}at 17.4.0, and npmlatestfor all seven is 17.5.0.@objectstack/specat^17.0.0in 23 places,^17.4.0in 6,^17.1.0in 2 and^17.3.0in 1;@objectstack/clientat^17.3.0in 2;formulaandlintat^17.0.0in 2 each.pnpm.overrides(rootpackage.json) andpnpm-workspace.yamlhold no@objectstackentry.H2 — how the lock was regenerated, and everything that moved
Regenerated by pnpm 10.31.0 only. ⛔ Not edited by hand.
pnpm update -r "@objectstack/*"was tried first and REJECTED. It rewrote 30 manifests (every range raised to^17.5.0, and script keys reordered), and it re-resolved unrelated packages:seroval,seroval-plugins,bson,@mongodb-js/saslprep,@microsoft/tsdoc-config,is-core-module,fast-uri,brace-expansion,use-sync-external-store, and a seconddompurify. None of those is@objectstack-caused.@objectstack/*specifier to^17.5.0for ONEpnpm install; restore every manifest byte-for-byte to HEAD; run a secondpnpm install, which reconciles the importers back to their declared ranges. The same raise-and-restore was then applied to the five directzodspecifiers (see below).@objectstack/*at 17.4.0;@objectstack/*at 17.5.0, andzod@4.6.5;specifierline changes.zod@4.6.5(same versions, new snapshot keys):ai@7.0.65,@ai-sdk/gateway,@ai-sdk/mcp,@ai-sdk/provider-utils,@ai-sdk/react, and thefumadocs-core/fumadocs-mdx/fumadocs-uisnapshots ofapps/site.zod@4.4.3stays in the lock ONLY asfumadocs-mdx's own dependency, unchanged from base.@object-ui/sitetype-checks green with it.Why
zodmoves (forced by the published 17.5.0 contract, not drift)@objectstack/spec@17.5.0and@objectstack/core@17.5.0raise theirzodrange from^4.4.3to^4.6.1. With only the@objectstack/*entries moved, the lock resolved spec'szodto 4.6.5 while objectui's own directzod ^4.4.3importers (types,app-shell,components,plugin-timeline,test-support) stayed on 4.4.3. Zod stamps its minor version into its types, so the two copies do not type-check against each other:pnpm --filter @object-ui/types buildfailed with TS2345 insrc/zod/views.zod.ts, bottoming out at "The types of '_zod.version.minor' are incompatible between these types. Type '4' is not assignable to type '6'."zod ^4.4.3to the same 4.6.5 (a range it already admits; no manifest edit), the same build exits 0.Gates read on this head (
b732e17)pnpm install --frozen-lockfilepnpm --filter @object-ui/types buildzodresolution)turbo run build --filter=!@object-ui/site --concurrency=2turbo run type-check --concurrency=2(unfiltered, 45 packages incl.@object-ui/site)vitest run packages/types/c80236e)So every one of the 56 reds is caused by the bump. The full suite is being read in four shards; its result is in the report comment.
H3 / H4 — what the bump moves, by cause
The reds fall into three causes. Each row names the upstream change that forced it.
Cause A — zod 4.4 to 4.6 internals (forced by the spec's
zod ^4.6.1).default()member now reports_zod.optin === 'defaulted', a rung zod 4.4.3 did not have (it answered'optional').imported-defaults-8317.test.ts("no member became REQUIRED", 26 rows) compares the rung by equality, and the 9034 census counts a default-under-default as already optional. The production walker is NOT affected:walk()turns an inner'defaulted'into'optional'beforeisAlreadyOptionalreads it, and the probe row "answers every probe exactly as the spec does" stays green for every imported schema. Adaptation: test-only, re-expressing "omissible" as either rung.unrecognized_keysis nowcontinue: true(non-aborting). In a union where the other arm aborts, the non-aborted arm is returned ALONE (handleUnionResults, whose code is unchanged).GridSchema.columns(8516): the out-of-vocabulary key is now reported directly, asunrecognized_keysnamingxxlatcolumns, instead of inside aninvalid_union. The test's intent (the key is named) holds, and the author's message is better. Mechanical re-pin.content-channel-public-blocks-9256.test.ts;strict-widget-slot-registered-inputs-11022.test.ts):{ type: 'metric-card', value: 42, body: [] }now yields ONEunrecognized_keysnamingvalueandbody. The by-name refusal ("metric-cardreads NEITHER content channel") is GONE, andvalue, a registered input, is misreported as unrecognized. Base yieldsinvalid_unioncarrying both arms. This is a regression in what an author (or an AI) is told, and restoring it is a design choice → left red, taken to the seat as a decision.Cause B — spec 17.5.0 makes an unknown-key refusal terminal
17.5.0's closed objects mark every
unrecognized_keysissuecontinue: false(markUnknownKeyRefusalTerminalin the spec's dist). zod skips even awhen-guarded check once the payload is explicitly aborted, so the twosuperRefinepointers (each carrying awhenthat always answers true) onObjectViewSchemano longer run:checkNamedViewCalendarAliases(objectui#8355) andcheckNamedViewKanbanStrayGroupBy(objectui#10321).listViews.KEY.calendar/.kanban).dateFieldcorrectly ("does not say which end of the range it binds … Write the one you mean").endFieldandkanban.groupByit is a generic unrecognized-key message, so objectui's specific pointer is lost on the named-view route.Cause C — the published contract moved, read by reference (the accept sets the seat's review reads)
DetailViewFieldSchema.options[].visibleWhen(specSelectOptionSchema){ dialect, ast }envelope acceptedelement:numberdataSource.filter(specElementDataSourceSchema)$and/$or) and a CEL envelope acceptedViewFilterRulearray[{ field, operator, value }]calendarblock (specCalendarConfigSchema)allDayFieldrefused by nameallDayFieldacceptedrecord:highlightsprops (specRecordHighlightsProps)aria,fields,layoutrequiredPermissions,redactFields,enforceFieldSecuritylistViews.KEY(specViewSchema)pageName,tabsliveListViewSchemaobject-level checkscheckListViewPageMountpresentDashboardWidgetSchemaobject-level checkscheckDashboardWidgetStageOrder,checkDashboardWidgetMetricMeasureArity.shapemirror does not carry them, so objectui's door is now WIDER than the spec on both rulesJoinedReportBlockSchemaunknown)z.ZodObject)H4 — consumer breaks
waitnode.defaultNodeExtras('wait')seeds{ waitEventConfig: { eventType: 'timer' } }. Spec 17.5.0'sFlowNodeSchemarefuses a timer wait with notimerDuration(its message: a timer wait with no duration "parks the run forever while reporting success"). So a node the designer just created is refused at save. Failing check:flow-canvas-seeds.spec-parse.test.tsx, row "wait: a freshly added node parses as a spec FlowNode" (base: parses). Which default to seed is a product decision → left red.What the follow-up commits on this branch do, and what they leave red
Mechanical, each forced by a named upstream change (Cause A1, A2 for
GridSchema.columns, and the Cause C re-pins that follow the spec by reference or follow a tripwire's own written instruction):optinrung re-expression (8317, 9034);GridSchema.columnsissue-shape re-pin (8516);WIDER_ARMSentries and theSpecEnvelopeAdmitsSourcelessgate;element:numberdataSource.filterrows re-pinned to the spec's verdicts, andREBUILT_CLEANemptied (the spec's schema no longer reaches az.lazy);record:highlightsPREMISE member list;allDayField) and the nested key list;checkListViewPageMount, as its own message instructs.Left RED on purpose, each with options in the report (
needs_decision):pageName/tabsstill declared on objectui's TypeScript named-view face while the protocol now retires them (7779; the objectui#8980 ruling kept them "declared inert" under a protocol that still declared them);waitseed (H4);Floors
This PR raises no floor. No code in it imports a 17.5.0-only export. The
^17.5.0floors are left to the consuming cards, each at the moment it first imports a 17.5.0-only export: objectui#11013, objectui#11021, objectui#10188, objectui#7759, objectui#7347, objectui#8649, objectui#9217, objectui#10107 and objectui#9830. Each is unblocked by this landing; none is concluded by it.Acceptance notes
zodskew. A consumer whose own lock holdszod4.4.x and resolves@objectstack/spec17.5.0 through objectui's^17.xranges gets the same two-copy split measured above. That state already exists for any consumer today; it is not created here. Whether objectui'szodfloor should rise to^4.6.1beside the consuming cards' spec floors is an open question in the report, not an edit here.checkDashboardWidgetStageOrderis still not exported on 17.5.0)". Measured here: it IS exported on 17.5.0 from@objectstack/spec/ui, and not from the root entry. The 7715 census sees it through/ui.Generated by Claude Code