chore: update dependencies 2026-09-08 - #709
claude[bot] wants to merge 1 commit into
Conversation
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@squide/core
@squide/env-vars
@squide/fakes
@squide/firefly
@squide/firefly-module-federation
@squide/firefly-rsbuild-configs
@squide/firefly-storybook
@squide/firefly-webpack-configs
@squide/i18next
@squide/launch-darkly
@squide/msw
@squide/react-router
commit: |
| "postcss": "^8.5.26", | ||
| "webpack": "^5.110.3", | ||
| "webpack-dev-server": "^5.2.4" | ||
| "webpack-dev-server": "^6.0.0" |
There was a problem hiding this comment.
High — dependency compatibility: this peer range is now unsatisfiable for every consumer.
@squide/firefly-webpack-configs has a hard dependencies entry on @workleap/webpack-configs@^1.6.16 (line 47), and that package declares its own peer requirement as webpack-dev-server: ^5.2.4 — confirmed in the lockfile:
# pnpm-lock.yaml:7434
'@workleap/webpack-configs@1.6.16':
peerDependencies:
webpack-dev-server: ^5.2.4^5.2.4 and ^6.0.0 are disjoint, so no single webpack-dev-server install satisfies both. pnpm silently resolved it here (@workleap/webpack-configs@1.6.16(...)(webpack-dev-server@6.0.0) at pnpm-lock.yaml:19357) only because the peer is marked optional and this repo doesn't enable strict-peer-dependencies; consumers who do will fail to install, and everyone else gets an unmet-peer warning plus a defineDevConfig implementation written against the v5 API.
This is also the one dependency in the batch that no validation step exercised. Steps 2c/2d cover the endpoints and storybook samples, both Rsbuild-based — webpack-dev-server is never started. CI only builds the webpack sample (.github/workflows/ci.yml:80), so the dev server never runs there either.
Per .github/prompts/update-dependencies.md (line 66) — "If a breaking change cannot be resolved by a clean migration, revert that specific package to its previous version, open an issue" — this should be reverted until @workleap/webpack-configs supports v6, and tracked in an issue alongside #708.
| "webpack-dev-server": "^6.0.0" | |
| "webpack-dev-server": "^5.2.4" |
The devDependencies pin on line 68 and the four samples/basic-webpack/* packages need the same revert to 5.2.4.
| @@ -0,0 +1,12 @@ | |||
| --- | |||
| "@squide/firefly-webpack-configs": minor | |||
There was a problem hiding this comment.
Medium — semver: minor understates a change the changeset body itself describes as breaking ("Consumers still on webpack-dev-server 5 must upgrade", line 10). Dropping an entire major from a peer range forces consumers to upgrade a peer dependency, which is a major bump — a consumer on webpack-dev-server 5 who takes ^5.2.13 → 5.3.0 gets a broken peer graph from what npm presents as a backwards-compatible release.
This repo already has the precedent: @squide/firefly-webpack-configs 5.0.0 was released as a Major Change for exactly this reason — "Updated dependencies to React Router v7" (packages/firefly-webpack-configs/CHANGELOG.md:173).
Fix depends on how the webpack-dev-server comment on packages/firefly-webpack-configs/package.json:43 is resolved:
- If the
^6.0.0bump is reverted (recommended, since it also conflicts with@workleap/webpack-configs' own^5.2.4peer), drop this topatch— the remaining changes for this package are the@swc/core/browserslistpatch narrowing and thepackageDirectoryfix. - If the bump is kept, this must be
major.
| "@rslib/core": "0.23.2", | ||
| "@types/node": "26.4.1", | ||
| "@rsbuild/core": "2.2.3", | ||
| "@rslib/core": "1.0.0", |
There was a problem hiding this comment.
Medium — /workleap-web-configs (dependency compatibility): @rslib/core 1.0.0 falls outside the peer range supported by the shared Rslib config this repo builds every package with.
@workleap/rslib-configs@1.2.1 — pinned in this file's devDependencies and used by every rslib.build.ts — declares:
# pnpm-lock.yaml:7383
'@workleap/rslib-configs@1.2.1':
peerDependencies:
'@rslib/core': ^0.23.2^0.23.2 resolves to >=0.23.2 <0.24.0, so 1.0.0 is not covered. Per ODR-0002, all packages build through @workleap/rslib-configs, so this unsupported major is now driving the build that produces every published dist/.
The new URL(..., import.meta.url) asset rewrite fixed in packages/firefly-rsbuild-configs/src/defineConfig.ts and packages/firefly-webpack-configs/src/defineConfig.ts is one observed symptom of that mismatch, and it was only caught because it produced a hard "Module not found" at sample-app build time. Other Rslib 1.0 output changes would not surface that loudly — pnpm lint/pnpm test run against raw .ts source via the JIT exports (ODR-0001), so they never exercise the built artifacts at all.
Recommend reverting @rslib/core to 0.23.2 across the workspace until @workleap/rslib-configs widens its peer range, and tracking it in an issue as was done for TypeScript 7 in #708. The defineConfig.ts change is a genuine improvement and worth keeping either way.
| "@rslib/core": "1.0.0", | |
| "@rslib/core": "0.23.2", |
The same pin needs reverting in the 9 other packages/*/package.json files and samples/storybook/host/package.json.
|
Superseded by a newer dependency update run. |
Summary
@rsbuild/core:^2.2.2→^2.2.3(peerDependencies, devDependencies) — (range narrowed — may break consumers)@swc/core:^1.16.1→^1.16.2(peerDependencies, devDependencies) — (range narrowed — may break consumers)browserslist:^4.28.8→^4.28.9(peerDependencies, devDependencies) — (range narrowed — may break consumers)i18next:^26.4.1→^26.4.2(peerDependencies, dependencies, devDependencies) — (range narrowed — may break consumers)react-error-boundary:^6.1.4→^6.1.5(peerDependencies, dependencies) — (range narrowed — may break consumers)storybook:^10.5.10→^10.6.0(peerDependencies, dependencies, devDependencies) — (range narrowed — may break consumers)webpack-dev-server:^5.2.4→^6.0.0(peerDependencies, devDependencies) — (range narrowed — may break consumers; drops the entire v5 range)@storybook/addon-a11y:10.5.10→10.6.0(dependencies)@types/react-dom:^19.2.5→^19.2.7(dependencies, devDependencies)@changesets/changelog-github:1.0.0→1.0.1(devDependencies)@changesets/cli:3.0.1→3.0.2(devDependencies)@rslib/core:0.23.2→1.0.0(devDependencies)@types/node:26.4.1→26.5.0(devDependencies)happy-dom:20.12.2→20.14.0(devDependencies)netlify-cli:27.4.2→27.5.0(devDependencies)stylelint:17.14.1→17.15.0(devDependencies)vitest:4.1.11→5.0.0(devDependencies)Breaking changes handled
Three updates in this batch required code changes rather than a plain version bump.
@rslib/core0.23.2 → 1.0.0 — Module Federation runtime plugins failed to resolve.Rslib 1.0 treats
new URL(..., import.meta.url)as an asset reference. It rewrotenew URL(".", import.meta.url)indefineConfig.tstonew URL("./static/assets/index.ts", import.meta.url)and emitted a straydist/static/assets/index.ts, sopackageDirectorypointed at a non-existent directory and the endpoints remote module failed to build:@squide/firefly-rsbuild-configsand@squide/firefly-webpack-configsnow derive the directory withpath.dirname(url.fileURLToPath(import.meta.url)), which Rslib leaves alone. This matches the form already used forapplicationDirectoryinfirefly-webpack-configs.vitest4.1.11 → 5.0.0 —clearMocksnow defaults totrue.Vitest 5 flipped the
clearMocksdefault fromfalsetotrue. Because it clears every mock before each test, it wiped the call history oftest.concurrenttests that were still in flight, producing 18 nondeterministicNumber of calls: 0failures across@squide/core. Every test in this repository creates its own mocks, so the global auto-clear provides no benefit under concurrency.clearMocks: falseis now set explicitly in all 11vitest.config.tsfiles.typescript6.0.3 → 7.0.2 — reverted.TypeScript 7 is the native port and its API shape differs enough that
@typescript-eslint/typescript-estreecrashes on load (TypeError: Cannot read properties of undefined (reading 'Cjs')), taking down ESLint entirely. No releasedtypescript-eslintsupports it —8.70.0still declarestypescript: ">=4.8.4 <6.1.0"— andtypescript-eslintis deliberately excluded fromupdate-outdated-deps. TypeScript was reverted to6.0.3across all 35 workspacepackage.jsonfiles. Tracked in #708.Validation checklist
🤖 Generated with Claude Code