Skip to content

chore: cleanup deps - #486

Merged
vicb merged 2 commits into
masterfrom
vicb/clean-deps
Oct 2, 2026
Merged

vicb merged 2 commits into
masterfrom
vicb/clean-deps

Conversation

@vicb

@vicb vicb commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary by Sourcery

Clean up and consolidate project dependencies across the workspace.

Enhancements:

  • Reclassify app-specific tooling dependencies and remove unused workspace-level dependency declarations.

Build:

  • Clean up dependency declarations and update the pnpm lockfile accordingly.

Summary by CodeRabbit

  • Chores
    • Updated how development and build tools are categorized in the app’s dependency configuration. Some tools are now listed as development-only dependencies, and selected build-related tools are no longer listed in the root development dependencies. These configuration updates do not change the app’s functionality or introduce end-user-visible changes.

@sourcery-ai

sourcery-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Cleans up dependency ownership by removing an unused root package, moving front-end-only tooling into apps/fxc-front devDependencies, removing an unused app dependency, and synchronizing the pnpm lockfile.

File-Level Changes

Change Details Files
Remove unused or misplaced package dependencies and update the lockfile accordingly.
  • Remove the PWA assets generator from the workspace root.
  • Move front-end build and analysis plugins into the front-end app’s devDependencies.
  • Remove the JSONC ESLint parser from the front-end app and retain it at the workspace level.
  • Regenerate pnpm-lock.yaml to reflect the dependency changes.
apps/fxc-front/package.json
package.json
pnpm-lock.yaml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 02c5dc5b-0e8d-4d42-bf0e-bff494ec6ec5

📥 Commits

Reviewing files that changed from the base of the PR and between a07f808 and 61ca0f3.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • apps/fxc-front/package.json

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


Walkthrough

The frontend package manifest moves selected tools to devDependencies. The root package manifest removes three development dependencies.

Changes

Dependency declarations

Layer / File(s) Summary
Update package manifests
apps/fxc-front/package.json, package.json
The frontend manifest moves five packages from dependencies to devDependencies. The root manifest removes @vite-pwa/assets-generator, rollup-plugin-visualizer, and vite-plugin-pwa from devDependencies.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~4 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 61ca0

The frontend tooling is now scoped to the frontend package, and the removed root declarations have no uncovered consumers. No actionable merge risk is evident.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 61ca0

The changes do not show expanded runtime privileges or altered service-worker behavior. Build tooling remains declared by the frontend, and its deployment task depends on a build. Risk is low because external hosting installation settings could not be verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The evidenced exposure is frontend tooling availability during installation and building, rather than a new attacker-controlled runtime path. The declaration moves do not establish increased browser or service-worker authority.

Trust Boundaries and Controls

  • observed — The service-worker runtime/build separation remains explicit: workbox-build is a type-only source, while Workbox routing and strategy packages remain runtime dependencies. The credential-related dotenvx declaration is only reordered.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the pull request's main change: cleaning up and reorganizing dependency declarations.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the manifest with care,
Five tools hop to the dev list there.
Three leave the root, their entries done,
The package lists now match the run.
Then softly thumps beneath the sun.

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Fixed security issues:

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="apps/fxc-front/package.json" line_range="21" />
<code_context>
     "@stencil/core": "^4.45.1",
     "d3-array": "^3.2.4",
     "geolib": "catalog:default",
-    "jsonc-eslint-parser": "catalog:default",
     "lit": "catalog:default",
     "mapbox-vector-tile": "catalog:default",
</code_context>
<issue_to_address>
**issue (bug_risk):** The fxc-front ESLint configuration directly imports `jsonc-eslint-parser`, but the fxc-front package no longer declares it. An isolated install or package-level dependency deployment therefore fails to load `eslint.config.js` with a module-not-found error.

**Triggers:** When fxc-front is linted or installed outside the workspace root's hoisted dependency graph.

**Suggested fix:** Add `jsonc-eslint-parser` to fxc-front's devDependencies, or ensure the package is never expected to run with an isolated dependency graph.
</issue_to_address>

Sourcery assessment

Approval pending. 1 finding to address first.

Blocking findings: apps/fxc-front/package.json:21


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread apps/fxc-front/package.json
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
flyxc-workers 61ca0f3 Commit Preview URL

Branch Preview URL
Oct 02 2026, 04:37 PM

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

@vicb
vicb merged commit 3396e03 into master Oct 2, 2026
7 checks passed
@vicb
vicb deleted the vicb/clean-deps branch October 2, 2026 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant