Skip to content

chore(deps): bump all outdated dependencies - #1264

Merged
Makisuo merged 9 commits into
mainfrom
chore/deps-bump-2026-10-05
Oct 5, 2026
Merged

Makisuo merged 9 commits into
mainfrom
chore/deps-bump-2026-10-05

Conversation

@Makisuo

@Makisuo Makisuo commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Bumps every outdated dependency except a few held back (below). One commit per group, so each can be reverted on its own.

What changed

  • In-range patch/minor bumps (router, query, vite/vitest, wrangler, clerk, ai sdk, streamdown, rrweb, turbo, knip, oxfmt, ...). The published SDKs (@maple-dev/browser, @maple-dev/effect-sdk) keep their dependency floors, so customers' allowed ranges don't narrow.
  • effect + @effect/* 4.0.0 → 4.0.1. All three patches apply at zero fuzz, so only their version keys move.
    • 4.0.1 flags HttpApiSchemaError with [ErrorReporter.ignore]. The effect-sdk span buffer dropped ignore-flagged spans before checking anticipated identifiers, so request-decode 400s would have vanished instead of exporting as Ok. An anticipated identifier now wins over the flag, and a test pins the real upstream error.
  • @tanstack/db 0.11, react-db 0.5, electric-db-collection 0.5.
    • They pin @tanstack/db exactly, so lib/unitflow moves with them; a second db copy throws DuplicateDbInstanceError in dev.
    • Electric deprecated returning { txid } from mutation handlers, so the effect-db converters await the txid themselves.
    • tx.isPersisted.promise becomes tx.when("settled").
  • @tanstack/charts 1.0, motion 14, @streamdown/code 2, @tanstack/react-hotkeys 0.13. No source changes:
    • charts 1.0 removes no exports.
    • motion 14 only drops internal motion-dom APIs.
    • @streamdown/code 2 moves to Shiki 4, which leaves one Shiki copy in the tree.
  • @cloudflare/workers-types 5. v5 still declares Buffer, process and global as any, which strips node's Buffer under "types": ["node", "@cloudflare/workers-types"]. A bun patch deletes those three lines until workerd#7539 lands.
  • @types/node 24 (matches the node major in mise.toml, not 26), portless 0.15, gpt-tokenizer 4.
  • vitest-evals 0.17. The scorer-first API moved to vitest-evals/legacy. It peers vitest <5; the legacy entry loads under vitest 5.

Held back

  • oxlint / @oxlint/plugins stay at 1.86. @effect/tsgo 0.48.1 patches the oxlint binding in prepare and refuses 1.87.
  • atmn 2. The config format changed, and each plan needs a versionSlug that must match the live version row. That needs an atmn pull against the org first.
  • @cloudflare/sandbox 1.0. It's a rewrite: no Sandbox/getSandbox, a donor image, and a new backup API. It goes in its own PR.

Verification

  • tsc --noEmit is clean in db, backend, infra, ui, effect-sdk, effect-db, unitflow, api, ai, alerting, chat-bot, electric-sync, sandbox, web, cli, examples/alchemy-maple and tsconfig.alchemy.json, on a clean node_modules.
  • bun run lint is clean.
  • Targeted tests:
    • effect-sdk tracer (31)
    • unitflow (141)
    • ui plot (170)
    • web collections, dashboard store and shortcuts (50)
    • cli under CI=true (675)

alchemy beta.81 comes in from main (#1263) via a merge; its patch applies to the merged tree.

Not run locally: the full suite, bun dev, a real eval run (needs an OpenRouter key), and the chart perf specs.

🤖 Generated with Claude Code

oxlint and @oxlint/plugins stop at 1.86.0: @effect/tsgo 0.48.1 patches
the oxlint binding and refuses 1.87. Drops two disable directives that
oxlint 1.86 reports as unused.
…tion 0.5

The three pin @tanstack/db exactly, and lib/unitflow moves with them or a
second db instance throws DuplicateDbInstanceError in dev. Electric
deprecated returning { txid } from mutation handlers, so the effect-db
converters await it instead, and isPersisted.promise becomes
when("settled").
…, react-hotkeys 0.13

All four are API-compatible for Maple's usage: charts 1.0 removes no
exports, motion 14 only drops internal motion-dom APIs, @streamdown/code
2 moves to Shiki 4 (one Shiki copy now), react-hotkeys only bumps its core.
All three patches apply to 4.0.1 at zero fuzz; only their version keys move.

4.0.1 flags HttpApiSchemaError with [ErrorReporter.ignore], so the
effect-sdk span buffer dropped request-decode 400 spans before the
anticipated-identifier check could export them as Ok. An anticipated
identifier now wins over the flag.
…-tokenizer 4

workers-types v5 still declares Buffer/process/global as any, which
strips node's Buffer under "types": ["node", ...]. A patch drops the
three lines until workerd#7539 lands. @types/node goes to 24 to match
the node major mise pins, not 26.
The scorer-first API Maple uses moved to vitest-evals/legacy. 0.17 peers
vitest <5; the legacy entry loads under vitest 5.
The unused-directive errors were an artifact of a stale effect 4.0.0
peer-variant left in node_modules; on a clean install the rule fires.
@maple-review-bot

maple-review-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Maple review

🟢 Confidence 4/5 · likely safe to merge
The tracer fix is pinned by a real-error test and the txid await preserves the existing rejection path; the unreviewed effect-db await path has no test of its own.
quality 100/100 · no findings · tests partial · risk medium

Bumps the outdated dependency set across the monorepo (effect 4.0.1, @tanstack/db 0.11, charts 1.0, workers-types 5, vitest-evals 0.17) with three matching source adjustments. The source edits hold up against the code around them; safe to merge.

  • effect/@effect/* 4.0.1: an anticipated identifier now beats ErrorReporter.ignore in the span buffer
  • electric mutation handlers await the txid themselves instead of returning it
  • tx.isPersisted.promise becomes tx.when("settled") in the dashboard store
  • workers-types 5 patched to drop its Buffer/process/global declarations
What was checked
  • awaitTxids awaits the same utils.awaitTxId the collection already used, so the txid-timeout toast path (use-dashboard-store.browser.test.tsx:180) is unchanged
  • bun.lock holds a single @tanstack/db@0.11.3, so libs and apps cannot split into two db copies
  • every @effect/* resolves to 4.0.1 and the patchedDependencies keys match the renamed patch files

a4b8a30 · Updated on every push. Reply "won't fix" to dismiss a finding, or mention @maple-review-bot to ask about one.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

📝 Walkthrough

Walkthrough

The pull request updates workspace dependencies and patches, changes transaction settlement handling in database adapters and dashboard hooks, and adjusts tracer filtering for anticipated errors.

Changes

TanStack DB transaction handling

Layer / File(s) Summary
Electric mutation settlement
lib/effect-db/src/electric/handlers.ts, lib/effect-db/package.json, lib/unitflow/package.json
The insert, update, and delete adapters await each transaction ID and resolve with void. Related TanStack DB dependency versions change.
Dashboard transaction settlement
apps/web/src/hooks/use-dashboard-store.ts, apps/web/src/hooks/use-dashboard-store.browser.test.tsx
Dashboard updates and deletions await tx.when("settled"). The test mocks now return persistence callbacks through when().

Tracer anticipated-error filtering

Layer / File(s) Summary
Anticipated errors in span filtering
packages/effect-sdk/src/shared/flushable-tracer.ts, packages/effect-sdk/src/shared/flushable-tracer.test.ts
The span filter receives configured anticipated error identifiers and does not ignore an error solely because it has ErrorReporter.ignore set when the error is anticipated. A test checks that an anticipated schema error exports with Ok status.

Dependency and evaluation compatibility updates

Layer / File(s) Summary
Workspace catalogs and worker types
package.json, patches/@cloudflare%2Fworkers-types@5.20261005.1.patch
Root dependency catalogs and patch targets change. The Cloudflare worker types patch removes the ambient Buffer, process, and global declarations.
AI evaluation compatibility
apps/ai/package.json, apps/ai/src/chat/__evals__/*, apps/ai/src/mcp/__evals__/*
AI evaluation-related development dependency ranges change. Evaluation imports now resolve from vitest-evals/legacy.
Application and example dependency versions
apps/api/package.json, apps/landing/package.json, apps/local-ui/package.json, apps/web/package.json, examples/effect-todo/package.json
Dependency versions change across the API, landing, local UI, web, and effect-todo packages.
Library dependency versions
packages/auth/package.json, packages/backend/package.json, packages/browser-session/package.json, packages/db/package.json, lib/effect-router/package.json, packages/sdk-core/package.json, packages/ui/package.json
Dependency versions change across authentication, backend, browser-session, database, router, SDK core, and UI packages.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Merge Risk: 🔵 Low · up to 69fd7

AI evaluations use a dependency pairing outside its declared compatibility range. Align the versions or confirm the evaluation workflow before relying on it; no broader failure is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 69fd7

The inspected changes do not establish a new privileged operation or authorization bypass. The main remaining uncertainty is whether the upgraded transaction libraries preserve failure, timeout, and rollback behavior at the new completion boundary.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected mutation changes alter acknowledgement and client-visible failure handling, not the dashboard producer's API destination or collection ownership. They do not establish expanded tenant reachability or additional privileges; organization-scoped client collections alone are not proof of server-side authorization.

Trust Boundaries and Controls

  • observed — The tracer's revised filtering still respects disabled collection, sampling, explicit span dropping, and the 10,000-span buffer limit. Failures containing defects cannot be dropped solely through the ignore flag or classified as fully anticipated.

Resilience and Maintainability Implications

  • observed — The new completion helper starts transaction-ID waits concurrently and requires all promises to fulfil. Rejection prevents adapter fulfilment, but the helper does not inspect fulfilled values or cancel sibling waits. Whether timeout, interruption, repetition, or partial settlement leaves optimistic state correctly recoverable depends on unavailable external implementations.

Hardening Proposals

  • proposed — Validate the upgraded transaction contract before relying on equivalent acknowledgement behavior: confirm timeout and interruption outcomes, repeated and concurrent waits, fulfilled-false behavior, and when("settled") rejection and optimistic-state recovery after partial synchronization. This is a validation proposal, not an observed defect.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 13 files. (17 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: updating outdated dependencies. It is concise and specific to the pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 13 files. (17 skipped: 17 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…esolves

Nothing in the workspace depends on it; main only had it through
alchemy's optional peer, and re-resolving for effect 4.0.1 dropped it.
alchemy's WorkerBridge imports it, so measure-tokens (Token Cost CI)
died at import.
@maple-review-bot

maple-review-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Maple review

🟢 Confidence 4/5 · likely safe to merge
Only two inert dependency lines changed at the head, but they re-resolve the tree: undici moves 7.30.0 to 8.11.2 at the top level and redis 6.3.0 is now installed.
quality 100/100 · no findings · tests not needed · risk low

The head of this dependency-bump PR adds @effect/platform-node to the root devDependencies and the effect catalog, so alchemy's WorkerBridge import resolves again after the effect 4.0.1 re-resolution. That declaration is correct and nothing in the workspace regresses; safe to merge.

  • @effect/platform-node declared in root devDependencies as catalog:effect
  • @effect/platform-node: 4.0.1 added to the effect catalog
What was checked
  • Nothing else in the workspace imports platform-node, so the root declaration is the right place (sandbox_grep over **/package.json)
  • Catalog pin 4.0.1 matches the root effect 4.0.1, so the peer dedupes to one effect copy (bun.lock:1262)
  • redis@6.3.0 satisfies the >=5.0.0 <7.0.0 peer of @effect/platform-node, so install does not leave an unmet peer

69fd70c · Updated on every push. Reply "won't fix" to dismiss a finding, or mention @maple-review-bot to ask about one.

coderabbitai[bot]

This comment was marked as resolved.

…10-05

# Conflicts:
#	bun.lock
#	package.json
@maple-review-bot

maple-review-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Maple review

🟢 Confidence 4/5 · likely safe to merge
The dependency bumps are consistent in bun.lock; the one place to look is whether tx.when("settled") still rejects on a failed persist the way isPersisted.promise did.
quality 100/100 · no findings · tests partial · risk medium

A dependency-only bump (effect 4.0.1, tanstack db 0.11 / charts 1 / motion 14, workers-types 5, vitest-evals 0.17) plus three small code adaptations. The adaptations follow the new upstream contracts and nothing in the diff contradicts them; safe to merge.

  • effect/@effect/* 4.0.1: span buffer no longer drops ignore-flagged anticipated failures
  • effect-db handlers await each returned txid and resolve void
  • dashboard mutations await tx.when("settled") for persistence
  • workers-types 5 patched to drop its Buffer/process/global shadows
What was checked
  • awaitTxids awaits utils.awaitTxId per id before the handler resolves (lib/effect-db/src/electric/handlers.ts:16)
  • only HttpApiSchemaError is both ignore-flagged and anticipated, so the RouteNotFound 404 drop is unchanged (flushable-tracer.ts:84)
  • @tanstack/db resolves to one 0.11.3 copy and effect to one 4.0.1 in bun.lock, so no duplicate instance

ff2de67 · Updated on every push. Reply "won't fix" to dismiss a finding, or mention @maple-review-bot to ask about one.

@Makisuo
Makisuo merged commit db78ed6 into main Oct 5, 2026
43 checks passed
@Makisuo
Makisuo deleted the chore/deps-bump-2026-10-05 branch October 5, 2026 22:14

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment on lines +81 to +84
const isIgnoredFailure = (error: unknown, anticipated: ReadonlySet<string> | undefined): boolean =>
Predicate.hasProperty(error, ErrorReporter.ignore) &&
error[ErrorReporter.ignore] === true &&
!(anticipated !== undefined && isAnticipatedFailure(error, anticipated))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mixed expected failures enter error tracking

When a span contains an ignored failure and an anticipated failure, isIgnoredFailure keeps it despite both being expected. isFullyAnticipated rejects the ignored failure, so the span enters error tracking as an Error.

Learn more

The tracer drops a span only when every failure is ignored, then marks it Ok only when every failure is anticipated. The new exception to ignoring anticipated failures leaves a cause containing both kinds in neither category. isFullyAnticipated returns false because the ignored error is not anticipated, and makeOtlpSpan emits Error status and an exception event. Such mixed causes can arise when an Effect finalizer fails after a handled failure.

Example: Configure HttpApiSchemaError as anticipated. If a span fails with an ignore-flagged RouteNotFound and a HttpApiSchemaError, the new guard retains it, but the resulting OTLP span is Error rather than Ok or dropped.

Recommended fix: Classify the entire cause consistently: when all failures are either ignored or anticipated, emit Ok if any failure is anticipated; otherwise drop the all-ignored span. Preserve the existing defect and unexpected-failure handling.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant