fix(deps): update compatible workspace dependencies - #1991
Conversation
--- updated-dependencies: - dependency-name: "@changesets/cli" dependency-version: 3.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@typescript-eslint/parser" dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@vitest/coverage-v8" dependency-version: 5.0.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: prettier dependency-version: 3.9.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: tsx dependency-version: 4.23.15 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: typescript-eslint dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: verdaccio dependency-version: 6.10.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: vitest dependency-version: 5.0.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: openai dependency-version: 7.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: zod dependency-version: 4.6.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@modelcontextprotocol/client" dependency-version: 2.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@blaxel/core" dependency-version: 0.3.22 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@daytonaio/sdk" dependency-version: 0.216.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@e2b/code-interpreter" dependency-version: 2.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@openai/codex-sdk" dependency-version: 0.156.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@runloop/api-client" dependency-version: 1.32.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: e2b dependency-version: 2.51.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: modal dependency-version: 0.10.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: next dependency-version: 16.3.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: react dependency-version: 19.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@types/react" dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: react-dom dependency-version: 19.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@types/react-dom" dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@types/react" dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@types/react-dom" dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@valibot/to-json-schema" dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: valibot dependency-version: 1.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.30.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: "@tanstack/react-query" dependency-version: 5.103.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: tailwind-merge dependency-version: 3.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@tailwindcss/postcss" dependency-version: 4.3.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: tailwindcss dependency-version: 4.3.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@tailwindcss/vite" dependency-version: 4.3.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: react-native dependency-version: 0.87.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@fastify/websocket" dependency-version: 11.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: fastify dependency-version: 5.12.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: "@astrojs/mdx" dependency-version: 8.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: "@astrojs/starlight" dependency-version: 0.42.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: astro dependency-version: 7.3.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: starlight-llms-txt dependency-version: 0.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: starlight-typedoc dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: typedoc dependency-version: 0.28.20 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: typedoc-plugin-markdown dependency-version: 4.13.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-minor-patch - dependency-name: "@astrojs/markdown-remark" dependency-version: 7.3.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch - dependency-name: typedoc-plugin-frontmatter dependency-version: 1.3.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
🦋 Changeset detectedLatest commit: 0fd0446 The changes in this PR will be included in the next version bump. This PR includes changesets to release 5 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1dcecc9a53
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
dpiet-oai
left a comment
There was a problem hiding this comment.
Current head has three verified blocking dependency regressions. Exact-head CI reproduces each failure; see the inline findings for the smallest fixes.
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed all 32 changed files at f450b7b0, including manifest/lockfile consistency, provider peers, Expo alignment, and the preserved install/security controls. The earlier Expo and provider-peer findings are resolved, and I found no structural or file-size regression.
Three compatibility issues remain: the Zod update breaks saved run-state restoration, MCP 2.1 breaks the existing emitted-declaration check, and TypeDoc 0.23 rejects the current docs output layout. Details and exact-head hosted evidence are inline; I am leaving feedback without approval.
Validation: source-only review plus hosted CI logs. Coverage reports 29 failing and 7,467 passing tests; Node 24 distribution checking and docs build fail as described. Changeset validation and CodeQL passed; Node 22 was cancelled. No local installs, tests, builds or remote workloads were run. Dependency review covered the manifests, lock changes, peers and configured install controls, not a complete audit of upstream package source or provenance.
jbeckwith-oai
left a comment
There was a problem hiding this comment.
The known OpenAI/Modal compilation, provider peer-range, Expo alignment, Zod state-restoration, docs-plugin, and changeset problems have been repaired and pushed. Both original inline findings were replied to and resolved. The current revision still fails the required extensions declaration check: @ai-sdk/provider-utils imports eventsource-parser/stream, whose types do not resolve under the existing moduleResolution setting (TS7016). A baseline-parser lockfile experiment and fresh install did not correct it, so the experiment was discarded. Keep this group unmerged until declaration compatibility is addressed or the remaining update is split into smaller passing changes; do not relax the check merely to merge.
|
Confirmed on current-head CI at eb045ae: the Node 24 declaration step fails with TS7016 for eventsource-parser/stream in @ai-sdk/provider-utils (job 110482091981). This matches local verification, so it is not solely a macOS/sandbox problem. The other compatibility repairs remain pushed. After repeated dependency-compatibility findings and the narrower version-retention attempt, this group is held for a deliberate declaration-compatibility fix or split; the failing check has not been disabled. |
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed all 31 changed files at eb045ae9, including the repairs since my previous review, manifest/lockfile consistency, provider peers and install/security controls.
The lockfile again selects MCP 2.0.0, SDK Zod 4.3.5 and starlight-typedoc 0.22.0. The current-head docs build passes, and core/openai/realtime/agents pass their declaration checks. Expo and provider peer alignment remain intact. No new structural or file-size regression found.
One declaration-compatibility blocker remains in extensions: the selected eventsource-parser package no longer supplies the legacy subpath type mapping used by the existing check. The inline comment includes the verified package-level cause and hosted failure. I am leaving feedback without approval.
Validation was source-only, with current-head hosted CI and integrity-verified published parser/provider-utils declarations. Node 24 fails as described; Node 22 was cancelled; coverage was still running. Changeset validation, Windows and CodeQL passed. No local installs, tests, builds or remote workloads were run; this was not a complete audit of every upstream dependency. These rollbacks preserve the current locked versions, rather than establishing permanent upper bounds in the existing ranges.
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed the complete 30-file diff at 0fd0446, including the previous compatibility findings, manifests, complete lockfile, provider peers, and install-policy boundaries. No remaining actionable findings.
The repaired graph preserves baseline MCP, SDK Zod, TypeDoc, and Expo selections. Parser dependency edges now match current main, and both Node 22 and 24.3 have passed the original strict generated-declaration check. The manifest/lockfile pairs are consistent; retained package versions preserve their integrity records, and release-age, build allowlist, overrides, and patch controls are unchanged. The five-package patch changeset covers the SDK manifest updates.
Validation: source-only review. Exact-head Node 24 tests, documentation build, Windows sandbox checks, CodeQL, and changeset validation passed. Node 22 and coverage were still running at the final check. No local installs, builds, or tests were run. This was a focused dependency-change review, not a complete audit of every upstream release or native binary.
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Reviewed complete dependency/manifests/lockfile changes at 0fd0446 with independent compatibility and supply-chain reviews. Current main is integrated, the coordinated Expo 57 upgrade and dependency removals are preserved, and incompatible dependency migrations are excluded. A fresh install and the original strict declaration checks pass, including the prior eventsource-parser/stream failure. All current-head CI is green: Node 22/24, coverage, Windows, docs, changesets and security. Node 24 ran all 7,496 tests successfully; local 299 focused tests and the 5,025-page docs build also passed. Prior inline findings have fix explanations and are resolved. Approved on the maintainer's behalf as requested.
Updates compatible workspace dependencies and adds a patch changeset for all five changed SDK packages. Preserves main’s coordinated Expo 57 migration and dependency removals.
Retains OpenAI 7.2.0, MCP client 2.0.0, SDK Zod 4.3.5, starlight-typedoc 0.22.0, and sandbox provider versions within existing peer ranges. Keeps the MCP example at 1.30.0 and regenerates the lockfile from current main. A fresh install passes the existing strict extensions declaration check, including eventsource-parser/stream, without changing module resolution or skipLibCheck.
Validation at 0fd0446: two independent compatibility and supply-chain reviews passed; all current-head CI passed (Node 22/24, coverage, Windows, docs, changesets, and security). Node 24 ran all 7,496 tests successfully. Local validation passed 299 focused tests, all builds/types/declarations/lint/format, changeset validation, and the 5,025-page docs build. The local full suite had eight host-only failures from injected proxy stderr or inaccessible Docker; passing current-head CI covers those paths.
Reviewed manifest/lockfile consistency, retained-version integrity, provider compatibility, install hooks, and preserved release-age/build controls. Requested maintainer dependency/security review in the root sdk-reviews channel. All prior inline findings have fix explanations and are resolved. Approved and merged after current-head CI passed.