Skip to content

[Feature] Dependency sweep 2026-09: every manifest to latest, and off the deprecated nats package #1520

Description

@pathosDev

Use case

Every manifest in the repository is behind, in four separate dependency closures that no single
command covers: the root (runtime + dev + 28 optional peers), tests/integration/brokers/,
docs/, devtools-ui/, benchmarks/comparison/, and eight example frontends. Dependabot sees
only some of them and never touches a bun.lock, so drift accumulates silently.

Five optional peers have shipped a new major since they were pinned, one of them
(nats) is deprecated on npm in favour of a renamed package set.

Proposed behaviour

One branch, one commit per manifest group, each keeping typecheck + bun test green.

Peer-floor rule for this sweep

peerDependencies ranges are not raised. A higher floor is consumer-visible — npm 7+ reports
ERESOLVE against an already-installed older peer — and buys nothing while no adapter needs a newer
API. What moves is the installed and tested version: devDependencies, the brokers manifest and
the lockfiles. A new major is widened into the range with ||, never swapped in.

One constraint worth writing down: tests/unit/runtime/HonoRunnerFrameCap.test.ts parses the
@hono/node-ws peer with a single-caret regex, so that entry can never grow a ||.

Root + brokers manifest

  • fastify -> ^5.12.3. Three files quote this range verbatim and tests/unit/ci/SecurityPolicy.test.ts enforces the bijection: package-health.yml's audit comment (which also quotes the bun.lock pins for fastify and find-my-way) and operations/security/supply-chain.mdx EN+DE. scripts/build-devtools-ui.mjs folds the root dependencies into the check:ui source hash, so bun run build:ui belongs in the same commit.
  • Patch/minor: hono ^4.13.7, @hono/node-server ^2.1.1, ws ^8.21.3, better-sqlite3 ^13.0.3, @fastify/static ^10.1.3, protobufjs ^8.8.0, publint ^0.3.24, knip ^6.35.1, @arethetypeswrong/cli ^0.18.5; brokers-side @aws-sdk/* ^3.1128.0, @grpc/grpc-js ^1.14.4, mariadb ^3.5.4, mqtt ^5.15.2, mssql ^12.7.1, pg ^8.23.0, cassandra-driver ^4.9.0.
  • New majors, widened:
    • mongodb ^6.21.0 || ^7.6.0 — closes [Feature] Widen the mongodb optional peer to ^6 || ^7 — v7 imports cleanly on Bun 1.4 #1340. v7 needs Node >= 20.19 and drops useNewUrlParser and friends; the Bun caveat becomes conditional ("v7 requires Bun >= 1.4") rather than disappearing, because the support floor stays at 1.3. Docs EN+DE plus the pin rationale in src/persistence/journals/MongoClient.ts's header.
    • ioredis ^5.10.1 || ^6.0.0 — v6 defaults to RESP3. RedisStreamsActor constructs its own client and parses xreadgroup replies in RESP2 array shape; if the live suite shows a different shape, the fix is protocol: 2 at construction, not a second parser.
    • nodemailer ^9.0.4 || ^10.0.1 and imapflow ^1.7.1 || ^2.0.0 — both rewritten in TypeScript with dual ESM/CJS builds; EmailBridgeActor already resolves default vs named createTransport.
    • @libsql/client ^0.15.15 || ^0.17.0 || ^0.18.0 — no release notes upstream, so the Docker suite is the check.
  • @types/node stays on 24 (Dependabot re-proposes @types/node majors against the deliberate engines-floor pin (4th round: #481) #906).
  • Coverage of the old major: after this, the Docker suites exercise only the new major of each of the five. The old one stays admissible but is then covered by nothing. Stated per driver here and in the CHANGELOG rather than left implicit.

NATS: migrate off the deprecated nats package

nats@2.29.3 is the last v2 and npm-deprecated ("moved to @nats-io/transport-node"). Four
adapters load it, not two — NatsActor, JetStreamActor, JetStreamKeyValueActor,
JetStreamObjectStoreActor, all through lazyImportModule('nats').

  • @nats-io/transport-node ^3.4.0 replaces nats (connect, headers)
  • @nats-io/jetstream ^3.4.0 — nc.jetstream() / nc.jetstreamManager() became free functions
  • @nats-io/kv ^3.4.0 — js.views.kv() became new Kvm(js); bindOnly maps to .open()
  • @nats-io/obj ^3.4.0 — js.views.os() became new Objm(js)
  • The one real break: v3 removed push consumers, so js.subscribe(subject, { stream, consumer }) has no equivalent. The replacement is consumer.consume({ max_messages, expires }) with messages.status() surfacing heartbeats_missed. JetStreamConsumerConfig.mode therefore stops meaning 'push' | 'pull' and becomes 'consume' | 'fetch' — a BREAKING rename, refusing the retired spellings at startup the way [Feature] Convert the last camelCase HOCON leaves to kebab-case — http.client, http.websocket, cache.in-memory #1405 did, rather than silently accepting a word the client no longer honours.
  • jsm "already exists / in use" detection moves from a regex over e.message to v3's typed JetStreamApiError.code (10058 / 10148), keeping the regex as fallback
  • KV/Object-Store watch entries carry isUpdate in v3; initializedFn is gone
  • The four exported *Like stubs keep their names (they are public API through src/io/index.ts); the duplicate NatsConnectionLike declaration in two files collapses into one
  • docker-compose.nats.yml starts the server without -js, so JetStream, KV and Object Store have no live coverage at all today. Add -js and four scenarios: a driver-shape probe (the NATS equivalent of cassandra/scenarios/01-driver-shape.ts, since OptionalPeerModuleShapes.test.ts never covers NATS), consume+fetch with ack/nak/term, KV, Object Store.
  • Deno stays ⚠ in the compatibility matrix and finally gets a footnote saying why: @nats-io/transport-deno is JSR-only, so one npm specifier serves all three runtimes.

Docs site, DevTools UI, example frontends

  • docs/: astro ^7.3.2, starlight ^0.42.0 (needs astro >= 7.2.10 and markdown-remark >= 7.3.0; the exact @astrojs/markdown-remark pin follows what astro declares, per c85688cf), starlight-typedoc ^0.23.1, typedoc-plugin-markdown ^4.13.0, sharp, fontsource, playwright. Starlight 0.42's breaking changes (mobile-menu markup, removed tagline config option) were checked against custom.css and astro.config.mjs — neither is affected.
  • devtools-ui/: Angular 22.1.5/22.1.7, jsdom ^30. Not vitest 5 (@angular/build peers ^4.0.8) and not TypeScript 7 (Angular peers >=6.0 <6.1). bun run build:ui in the same commit.
  • Eight frontends: Angular 22.1.x, next ^16.3.4, react ^19.2.8, vite ^8.2.2, svelte ^5.57.0, zone.js ^0.16.3. Both lockfiles regenerated per directory — the bun.lock half is what build(deps): bump the npm_and_yarn group across 4 directories with 4 updates #1518 left stale, and bun install --frozen-lockfile --dry-run cannot see a merely outdated transitive.

Alternatives considered

Letting Dependabot do it: it never writes bun.lock, does not see the brokers manifest, opens
group PRs that bundle unrelated drift, and would raise peer floors as a side effect.

Acceptance criteria

Every manifest at its chosen version with a written reason for each deliberate hold (@types/node
24, vitest 4, TypeScript 6 in the UI, xstate/nact frozen until the #1331 re-measure); bun install --frozen-lockfile --dry-run exits 0 in all twelve directories; lint:audit no worse and no new
--ignore; the five widened peers each green against their live Docker suite; NATS migrated with
JetStream coverage that did not exist before; CHANGELOG Changed covering the consumer-visible
range widenings and the BREAKING mode rename.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency fileenhancementNew feature or requestpriority: mediumUseful, not urgent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions