chore: update dependencies 2026-09-15 - #711
claude[bot] wants to merge 1 commit into
Conversation
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@squide/core
@squide/env-vars
@squide/fakes
@squide/firefly
@squide/firefly-module-federation
@squide/firefly-rsbuild-configs
@squide/firefly-storybook
@squide/firefly-webpack-configs
@squide/i18next
@squide/launch-darkly
@squide/msw
@squide/react-router
commit: |
| "webpack": "^5.110.3", | ||
| "webpack-dev-server": "^5.2.4" | ||
| "webpack": "^5.111.0", | ||
| "webpack-dev-server": "^6.0.0" |
There was a problem hiding this comment.
High — peer dependency conflict (/pnpm)
This package moves its webpack-dev-server peer to ^6.0.0, but its own runtime dependency @workleap/webpack-configs (^1.6.16, line 47) still declares webpack-dev-server: ^5.2.4 as a peer. The two ranges are disjoint, so a consumer can never satisfy both:
@squide/firefly-webpack-configs → webpack-dev-server ^6.0.0
└── @workleap/webpack-configs@1.6.16 → webpack-dev-server ^5.2.4 (optional peer)
This is already visible in this PR's own lockfile, where the optional peer resolved out of range:
'@workleap/webpack-configs@1.6.16(...)(webpack-dev-server@6.0.0)(webpack@5.111.0)':
Impact on consumers:
- pnpm —
unmet peer webpack-dev-server@^5.2.4: found 6.0.0warning on every install (this repo has nostrict-peer-dependencies, so it only warns here). - npm / Yarn classic — hard
ERESOLVEinstall failure, since the conflicting peer is not optional from their resolver's point of view.
auto-install-peers does not rescue this: it only installs missing peers, and webpack-dev-server is present — just at the wrong major.
Note that every other peer in this block narrows within the range @workleap/webpack-configs accepts (@swc/core ^1.16.2 ⊂ ^1.16.1, browserslist ^4.28.9 ⊂ ^4.28.8, webpack ^5.111.0 ⊂ ^5.110.2), so webpack-dev-server is the only incompatible one.
Fix: hold the webpack-dev-server peer (and the matching devDependency + the basic-webpack sample) at ^5.2.4 until a @workleap/webpack-configs release supports v6. If you want to ship v6 support now, widen the range so both majors resolve and add a peerDependencyRules.allowedVersions entry documenting why v6 against @workleap/webpack-configs@1.x is safe — the /pnpm skill's guidance is to keep library peer ranges wide (.agents/skills/pnpm/references/features-peer-deps.md):
| "webpack-dev-server": "^6.0.0" | |
| "webpack-dev-server": "^5.2.4 || ^6.0.0" |
| @@ -0,0 +1,13 @@ | |||
| --- | |||
| "@squide/firefly-webpack-configs": minor | |||
There was a problem hiding this comment.
Medium — release correctness
The changeset body states the reason for this bump is that the webpack-dev-server peer range "moved from ^5.2.4 to ^6.0.0, which requires consumers to upgrade." Requiring consumers to upgrade is the definition of a breaking change, so this should be major, not minor.
Concretely: @squide/firefly-webpack-configs is at 5.2.13. A minor publishes 5.3.0, which every consumer on ^5.x picks up on a routine pnpm update — silently landing a package that now demands a webpack-dev-server major they haven't migrated to. Under a major (6.0.0) the same consumers stay pinned until they opt in.
This is moot if you take the fix suggested on packages/firefly-webpack-configs/package.json:43 and hold the peer at ^5.2.4 — then patch is the correct level for the remaining in-range bumps.
| "@squide/firefly-webpack-configs": minor | |
| "@squide/firefly-webpack-configs": major |
Summary
@rsbuild/core:2.2.2→2.2.6(peerDependencies, devDependencies)@rspack/core:2.2.2→2.2.4(peerDependencies, dependencies, devDependencies)@swc/core:1.16.1→1.16.2(peerDependencies, devDependencies)browserslist:4.28.8→4.28.9(peerDependencies, devDependencies)i18next:26.4.1→26.4.2(peerDependencies, dependencies, devDependencies)react:19.2.8→19.3.0(peerDependencies, dependencies, devDependencies)react-dom:19.2.8→19.3.0(peerDependencies, dependencies, devDependencies)react-error-boundary:6.1.4→6.1.5(peerDependencies, dependencies)react-i18next:17.0.13→17.0.14(peerDependencies, dependencies, devDependencies)storybook:10.5.10→10.6.0(peerDependencies, dependencies, devDependencies) — (range narrowed — may break consumers)webpack:5.110.3→5.111.0(peerDependencies, devDependencies)webpack-dev-server:5.2.4→6.0.0(peerDependencies, devDependencies) — (range narrowed — may break consumers)@formatjs/intl-localematcher:0.8.13→0.9.0(dependencies)@storybook/addon-a11y:10.5.10→10.6.0(dependencies)@types/react:19.2.18→19.3.0(dependencies, devDependencies)@types/react-dom:19.2.5→19.3.0(dependencies, devDependencies)@changesets/changelog-github:1.0.0→1.0.1(devDependencies)@changesets/cli:3.0.1→3.0.2(devDependencies)@rslib/core:0.23.2→1.0.0(devDependencies)@types/node:26.4.1→26.5.1(devDependencies)@typescript-eslint/parser:8.69.0→8.70.0(devDependencies)agent-browser:0.36.0→0.37.1(devDependencies)happy-dom:20.12.2→20.14.5(devDependencies)netlify-cli:27.4.2→27.6.0(devDependencies)stylelint:17.14.1→17.15.0(devDependencies)vitest:4.1.11→5.0.0(devDependencies)Migrations applied
Three updates required code or configuration changes:
new URL(..., import.meta.url)into an asset reference. In@squide/firefly-rsbuild-configsand@squide/firefly-webpack-configsthis madepackageDirectoryresolve todist/static/assets/index.ts, so the Module Federation runtime plugin paths pointed at files that do not exist and theendpointsremote module failed to build. Both packages now derive the directory withpath.dirname(fileURLToPath(import.meta.url)).clearMocksdefault fromfalsetotrue. Because this repository's tests are written withtest.concurrent, a test that completed was clearing the mocks of the sibling tests still running, which failed 18 tests in@squide/core,@squide/fireflyand@squide/firefly-module-federation.clearMocks: falseis now set explicitly in all 11 packagevitest.config.tsfiles.basic-webpacksample was additionally validated in a browser (login, navigation, federated remote modules) on top of the required validation steps.Update not applied
typescript6.0.3→7.0.2was reverted. TypeScript 7 breaks@typescript-eslint/typescript-estree@8.54.0(TypeError: Cannot read properties of undefined (reading 'Cjs')), andtypescript-eslintis deliberately excluded fromupdate-outdated-deps. This is already tracked in #708, which has been updated with this run's recurrence.Validation checklist
🤖 Generated with Claude Code