You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Feature] Dependency sweep 2026-09: every manifest to latest, and off the deprecated nats package #1520
Every manifest in the repository is behind, in four separate dependency closures that no single
command covers: the root (runtime + dev + 28 optional peers), tests/integration/brokers/, docs/, devtools-ui/, benchmarks/comparison/, and eight example frontends. Dependabot sees
only some of them and never touches a bun.lock, so drift accumulates silently.
Five optional peers have shipped a new major since they were pinned, one of them
(nats) is deprecated on npm in favour of a renamed package set.
Proposed behaviour
One branch, one commit per manifest group, each keeping typecheck + bun test green.
Peer-floor rule for this sweep
peerDependencies ranges are not raised. A higher floor is consumer-visible — npm 7+ reports
ERESOLVE against an already-installed older peer — and buys nothing while no adapter needs a newer
API. What moves is the installed and tested version: devDependencies, the brokers manifest and
the lockfiles. A new major is widened into the range with ||, never swapped in.
One constraint worth writing down: tests/unit/runtime/HonoRunnerFrameCap.test.ts parses the @hono/node-ws peer with a single-caret regex, so that entry can never grow a ||.
Root + brokers manifest
fastify -> ^5.12.3. Three files quote this range verbatim and tests/unit/ci/SecurityPolicy.test.ts enforces the bijection: package-health.yml's audit comment (which also quotes the bun.lock pins for fastify and find-my-way) and operations/security/supply-chain.mdx EN+DE. scripts/build-devtools-ui.mjs folds the root dependencies into the check:ui source hash, so bun run build:ui belongs in the same commit.
mongodb^6.21.0 || ^7.6.0 — closes [Feature] Widen the mongodb optional peer to ^6 || ^7 — v7 imports cleanly on Bun 1.4 #1340. v7 needs Node >= 20.19 and drops useNewUrlParser and friends; the Bun caveat becomes conditional ("v7 requires Bun >= 1.4") rather than disappearing, because the support floor stays at 1.3. Docs EN+DE plus the pin rationale in src/persistence/journals/MongoClient.ts's header.
ioredis^5.10.1 || ^6.0.0 — v6 defaults to RESP3. RedisStreamsActor constructs its own client and parses xreadgroup replies in RESP2 array shape; if the live suite shows a different shape, the fix is protocol: 2 at construction, not a second parser.
nodemailer^9.0.4 || ^10.0.1 and imapflow^1.7.1 || ^2.0.0 — both rewritten in TypeScript with dual ESM/CJS builds; EmailBridgeActor already resolves default vs named createTransport.
@libsql/client^0.15.15 || ^0.17.0 || ^0.18.0 — no release notes upstream, so the Docker suite is the check.
Coverage of the old major: after this, the Docker suites exercise only the new major of each of the five. The old one stays admissible but is then covered by nothing. Stated per driver here and in the CHANGELOG rather than left implicit.
NATS: migrate off the deprecated nats package
nats@2.29.3 is the last v2 and npm-deprecated ("moved to @nats-io/transport-node"). Four
adapters load it, not two — NatsActor, JetStreamActor, JetStreamKeyValueActor, JetStreamObjectStoreActor, all through lazyImportModule('nats').
@nats-io/jetstream ^3.4.0 — nc.jetstream() / nc.jetstreamManager() became free functions
@nats-io/kv ^3.4.0 — js.views.kv() became new Kvm(js); bindOnly maps to .open()
@nats-io/obj ^3.4.0 — js.views.os() became new Objm(js)
The one real break: v3 removed push consumers, so js.subscribe(subject, { stream, consumer }) has no equivalent. The replacement is consumer.consume({ max_messages, expires }) with messages.status() surfacing heartbeats_missed. JetStreamConsumerConfig.mode therefore stops meaning 'push' | 'pull' and becomes 'consume' | 'fetch' — a BREAKING rename, refusing the retired spellings at startup the way [Feature] Convert the last camelCase HOCON leaves to kebab-case — http.client, http.websocket, cache.in-memory #1405 did, rather than silently accepting a word the client no longer honours.
jsm "already exists / in use" detection moves from a regex over e.message to v3's typed JetStreamApiError.code (10058 / 10148), keeping the regex as fallback
KV/Object-Store watch entries carry isUpdate in v3; initializedFn is gone
The four exported *Like stubs keep their names (they are public API through src/io/index.ts); the duplicate NatsConnectionLike declaration in two files collapses into one
docker-compose.nats.yml starts the server without -js, so JetStream, KV and Object Store have no live coverage at all today. Add -js and four scenarios: a driver-shape probe (the NATS equivalent of cassandra/scenarios/01-driver-shape.ts, since OptionalPeerModuleShapes.test.ts never covers NATS), consume+fetch with ack/nak/term, KV, Object Store.
Deno stays ⚠ in the compatibility matrix and finally gets a footnote saying why: @nats-io/transport-deno is JSR-only, so one npm specifier serves all three runtimes.
Docs site, DevTools UI, example frontends
docs/: astro ^7.3.2, starlight ^0.42.0 (needs astro >= 7.2.10 and markdown-remark >= 7.3.0; the exact @astrojs/markdown-remark pin follows what astro declares, per c85688cf), starlight-typedoc ^0.23.1, typedoc-plugin-markdown ^4.13.0, sharp, fontsource, playwright. Starlight 0.42's breaking changes (mobile-menu markup, removed tagline config option) were checked against custom.css and astro.config.mjs — neither is affected.
devtools-ui/: Angular 22.1.5/22.1.7, jsdom ^30. Not vitest 5 (@angular/build peers ^4.0.8) and not TypeScript 7 (Angular peers >=6.0 <6.1). bun run build:ui in the same commit.
Eight frontends: Angular 22.1.x, next ^16.3.4, react ^19.2.8, vite ^8.2.2, svelte ^5.57.0, zone.js ^0.16.3. Both lockfiles regenerated per directory — the bun.lock half is what build(deps): bump the npm_and_yarn group across 4 directories with 4 updates #1518 left stale, and bun install --frozen-lockfile --dry-run cannot see a merely outdated transitive.
Alternatives considered
Letting Dependabot do it: it never writes bun.lock, does not see the brokers manifest, opens
group PRs that bundle unrelated drift, and would raise peer floors as a side effect.
Acceptance criteria
Every manifest at its chosen version with a written reason for each deliberate hold (@types/node
24, vitest 4, TypeScript 6 in the UI, xstate/nact frozen until the #1331 re-measure); bun install --frozen-lockfile --dry-run exits 0 in all twelve directories; lint:audit no worse and no new --ignore; the five widened peers each green against their live Docker suite; NATS migrated with
JetStream coverage that did not exist before; CHANGELOG Changed covering the consumer-visible
range widenings and the BREAKING mode rename.
Use case
Every manifest in the repository is behind, in four separate dependency closures that no single
command covers: the root (runtime + dev + 28 optional peers),
tests/integration/brokers/,docs/,devtools-ui/,benchmarks/comparison/, and eight example frontends. Dependabot seesonly some of them and never touches a
bun.lock, so drift accumulates silently.Five optional peers have shipped a new major since they were pinned, one of them
(
nats) is deprecated on npm in favour of a renamed package set.Proposed behaviour
One branch, one commit per manifest group, each keeping
typecheck+bun testgreen.Peer-floor rule for this sweep
peerDependenciesranges are not raised. A higher floor is consumer-visible — npm 7+ reportsERESOLVE against an already-installed older peer — and buys nothing while no adapter needs a newer
API. What moves is the installed and tested version:
devDependencies, the brokers manifest andthe lockfiles. A new major is widened into the range with
||, never swapped in.One constraint worth writing down:
tests/unit/runtime/HonoRunnerFrameCap.test.tsparses the@hono/node-wspeer with a single-caret regex, so that entry can never grow a||.Root + brokers manifest
fastify-> ^5.12.3. Three files quote this range verbatim andtests/unit/ci/SecurityPolicy.test.tsenforces the bijection:package-health.yml's audit comment (which also quotes thebun.lockpins forfastifyandfind-my-way) andoperations/security/supply-chain.mdxEN+DE.scripts/build-devtools-ui.mjsfolds the rootdependenciesinto thecheck:uisource hash, sobun run build:uibelongs in the same commit.hono^4.13.7,@hono/node-server^2.1.1,ws^8.21.3,better-sqlite3^13.0.3,@fastify/static^10.1.3,protobufjs^8.8.0,publint^0.3.24,knip^6.35.1,@arethetypeswrong/cli^0.18.5; brokers-side@aws-sdk/*^3.1128.0,@grpc/grpc-js^1.14.4,mariadb^3.5.4,mqtt^5.15.2,mssql^12.7.1,pg^8.23.0,cassandra-driver^4.9.0.mongodb^6.21.0 || ^7.6.0— closes [Feature] Widen the mongodb optional peer to ^6 || ^7 — v7 imports cleanly on Bun 1.4 #1340. v7 needs Node >= 20.19 and dropsuseNewUrlParserand friends; the Bun caveat becomes conditional ("v7 requires Bun >= 1.4") rather than disappearing, because the support floor stays at 1.3. Docs EN+DE plus the pin rationale insrc/persistence/journals/MongoClient.ts's header.ioredis^5.10.1 || ^6.0.0— v6 defaults to RESP3.RedisStreamsActorconstructs its own client and parsesxreadgroupreplies in RESP2 array shape; if the live suite shows a different shape, the fix isprotocol: 2at construction, not a second parser.nodemailer^9.0.4 || ^10.0.1andimapflow^1.7.1 || ^2.0.0— both rewritten in TypeScript with dual ESM/CJS builds;EmailBridgeActoralready resolvesdefaultvs namedcreateTransport.@libsql/client^0.15.15 || ^0.17.0 || ^0.18.0— no release notes upstream, so the Docker suite is the check.@types/nodestays on 24 (Dependabot re-proposes @types/node majors against the deliberate engines-floor pin (4th round: #481) #906).NATS: migrate off the deprecated
natspackagenats@2.29.3is the last v2 and npm-deprecated ("moved to @nats-io/transport-node"). Fouradapters load it, not two —
NatsActor,JetStreamActor,JetStreamKeyValueActor,JetStreamObjectStoreActor, all throughlazyImportModule('nats').@nats-io/transport-node^3.4.0 replacesnats(connect,headers)@nats-io/jetstream^3.4.0 —nc.jetstream()/nc.jetstreamManager()became free functions@nats-io/kv^3.4.0 —js.views.kv()becamenew Kvm(js);bindOnlymaps to.open()@nats-io/obj^3.4.0 —js.views.os()becamenew Objm(js)js.subscribe(subject, { stream, consumer })has no equivalent. The replacement isconsumer.consume({ max_messages, expires })withmessages.status()surfacingheartbeats_missed.JetStreamConsumerConfig.modetherefore stops meaning'push' | 'pull'and becomes'consume' | 'fetch'— a BREAKING rename, refusing the retired spellings at startup the way [Feature] Convert the last camelCase HOCON leaves to kebab-case — http.client, http.websocket, cache.in-memory #1405 did, rather than silently accepting a word the client no longer honours.jsm"already exists / in use" detection moves from a regex overe.messageto v3's typedJetStreamApiError.code(10058 / 10148), keeping the regex as fallbackisUpdatein v3;initializedFnis gone*Likestubs keep their names (they are public API throughsrc/io/index.ts); the duplicateNatsConnectionLikedeclaration in two files collapses into onedocker-compose.nats.ymlstarts the server without-js, so JetStream, KV and Object Store have no live coverage at all today. Add-jsand four scenarios: a driver-shape probe (the NATS equivalent ofcassandra/scenarios/01-driver-shape.ts, sinceOptionalPeerModuleShapes.test.tsnever covers NATS), consume+fetch with ack/nak/term, KV, Object Store.⚠in the compatibility matrix and finally gets a footnote saying why:@nats-io/transport-denois JSR-only, so one npm specifier serves all three runtimes.Docs site, DevTools UI, example frontends
docs/: astro ^7.3.2, starlight ^0.42.0 (needs astro >= 7.2.10 and markdown-remark >= 7.3.0; the exact@astrojs/markdown-remarkpin follows what astro declares, perc85688cf), starlight-typedoc ^0.23.1, typedoc-plugin-markdown ^4.13.0, sharp, fontsource, playwright. Starlight 0.42's breaking changes (mobile-menu markup, removedtaglineconfig option) were checked againstcustom.cssandastro.config.mjs— neither is affected.devtools-ui/: Angular 22.1.5/22.1.7, jsdom ^30. Not vitest 5 (@angular/buildpeers^4.0.8) and not TypeScript 7 (Angular peers>=6.0 <6.1).bun run build:uiin the same commit.bun.lockhalf is what build(deps): bump the npm_and_yarn group across 4 directories with 4 updates #1518 left stale, andbun install --frozen-lockfile --dry-runcannot see a merely outdated transitive.Alternatives considered
Letting Dependabot do it: it never writes
bun.lock, does not see the brokers manifest, opensgroup PRs that bundle unrelated drift, and would raise peer floors as a side effect.
Acceptance criteria
Every manifest at its chosen version with a written reason for each deliberate hold (
@types/node24, vitest 4, TypeScript 6 in the UI, xstate/nact frozen until the #1331 re-measure);
bun install --frozen-lockfile --dry-runexits 0 in all twelve directories;lint:auditno worse and no new--ignore; the five widened peers each green against their live Docker suite; NATS migrated withJetStream coverage that did not exist before; CHANGELOG
Changedcovering the consumer-visiblerange widenings and the BREAKING
moderename.