Repository navigation
chore(deps): bump all outdated dependencies - #1264
Conversation
oxlint and @oxlint/plugins stop at 1.86.0: @effect/tsgo 0.48.1 patches the oxlint binding and refuses 1.87. Drops two disable directives that oxlint 1.86 reports as unused.
…tion 0.5
The three pin @tanstack/db exactly, and lib/unitflow moves with them or a
second db instance throws DuplicateDbInstanceError in dev. Electric
deprecated returning { txid } from mutation handlers, so the effect-db
converters await it instead, and isPersisted.promise becomes
when("settled").
…, react-hotkeys 0.13 All four are API-compatible for Maple's usage: charts 1.0 removes no exports, motion 14 only drops internal motion-dom APIs, @streamdown/code 2 moves to Shiki 4 (one Shiki copy now), react-hotkeys only bumps its core.
All three patches apply to 4.0.1 at zero fuzz; only their version keys move. 4.0.1 flags HttpApiSchemaError with [ErrorReporter.ignore], so the effect-sdk span buffer dropped request-decode 400 spans before the anticipated-identifier check could export them as Ok. An anticipated identifier now wins over the flag.
…-tokenizer 4 workers-types v5 still declares Buffer/process/global as any, which strips node's Buffer under "types": ["node", ...]. A patch drops the three lines until workerd#7539 lands. @types/node goes to 24 to match the node major mise pins, not 26.
The scorer-first API Maple uses moved to vitest-evals/legacy. 0.17 peers vitest <5; the legacy entry loads under vitest 5.
The unused-directive errors were an artifact of a stale effect 4.0.0 peer-variant left in node_modules; on a clean install the rule fires.
Maple review🟢 Confidence 4/5 · likely safe to merge Bumps the outdated dependency set across the monorepo (effect 4.0.1, @tanstack/db 0.11, charts 1.0, workers-types 5, vitest-evals 0.17) with three matching source adjustments. The source edits hold up against the code around them; safe to merge.
What was checked
|
📝 WalkthroughWalkthroughThe pull request updates workspace dependencies and patches, changes transaction settlement handling in database adapters and dashboard hooks, and adjusts tracer filtering for anticipated errors. ChangesTanStack DB transaction handling
Tracer anticipated-error filtering
Dependency and evaluation compatibility updates
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Other Merge Risk: 🔵 Low · up to AI evaluations use a dependency pairing outside its declared compatibility range. Align the versions or confirm the evaluation workflow before relying on it; no broader failure is established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The inspected changes do not establish a new privileged operation or authorization bypass. The main remaining uncertainty is whether the upgraded transaction libraries preserve failure, timeout, and rollback behavior at the new completion boundary. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 13 files. (17 skipped: 17 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…esolves Nothing in the workspace depends on it; main only had it through alchemy's optional peer, and re-resolving for effect 4.0.1 dropped it. alchemy's WorkerBridge imports it, so measure-tokens (Token Cost CI) died at import.
Maple review🟢 Confidence 4/5 · likely safe to merge The head of this dependency-bump PR adds
What was checked
|
…10-05 # Conflicts: # bun.lock # package.json
Maple review🟢 Confidence 4/5 · likely safe to merge A dependency-only bump (effect 4.0.1, tanstack db 0.11 / charts 1 / motion 14, workers-types 5, vitest-evals 0.17) plus three small code adaptations. The adaptations follow the new upstream contracts and nothing in the diff contradicts them; safe to merge.
What was checked
|
| const isIgnoredFailure = (error: unknown, anticipated: ReadonlySet<string> | undefined): boolean => | ||
| Predicate.hasProperty(error, ErrorReporter.ignore) && | ||
| error[ErrorReporter.ignore] === true && | ||
| !(anticipated !== undefined && isAnticipatedFailure(error, anticipated)) |
There was a problem hiding this comment.
🟡 Mixed expected failures enter error tracking
When a span contains an ignored failure and an anticipated failure, isIgnoredFailure keeps it despite both being expected. isFullyAnticipated rejects the ignored failure, so the span enters error tracking as an Error.
Learn more
The tracer drops a span only when every failure is ignored, then marks it Ok only when every failure is anticipated. The new exception to ignoring anticipated failures leaves a cause containing both kinds in neither category. isFullyAnticipated returns false because the ignored error is not anticipated, and makeOtlpSpan emits Error status and an exception event. Such mixed causes can arise when an Effect finalizer fails after a handled failure.
Example: Configure HttpApiSchemaError as anticipated. If a span fails with an ignore-flagged RouteNotFound and a HttpApiSchemaError, the new guard retains it, but the resulting OTLP span is Error rather than Ok or dropped.
Recommended fix: Classify the entire cause consistently: when all failures are either ignored or anticipated, emit Ok if any failure is anticipated; otherwise drop the all-ignored span. Preserve the existing defect and unexpected-failure handling.
Was this helpful? React with 👍 or 👎 to provide feedback.
Bumps every outdated dependency except a few held back (below). One commit per group, so each can be reverted on its own.
What changed
@maple-dev/browser,@maple-dev/effect-sdk) keep their dependency floors, so customers' allowed ranges don't narrow.@effect/*4.0.0 → 4.0.1. All three patches apply at zero fuzz, so only their version keys move.HttpApiSchemaErrorwith[ErrorReporter.ignore]. The effect-sdk span buffer dropped ignore-flagged spans before checking anticipated identifiers, so request-decode 400s would have vanished instead of exporting asOk. An anticipated identifier now wins over the flag, and a test pins the real upstream error.@tanstack/db0.11,react-db0.5,electric-db-collection0.5.@tanstack/dbexactly, solib/unitflowmoves with them; a second db copy throwsDuplicateDbInstanceErrorin dev.{ txid }from mutation handlers, so the effect-db converters await the txid themselves.tx.isPersisted.promisebecomestx.when("settled").@tanstack/charts1.0,motion14,@streamdown/code2,@tanstack/react-hotkeys0.13. No source changes:@streamdown/code2 moves to Shiki 4, which leaves one Shiki copy in the tree.@cloudflare/workers-types5. v5 still declaresBuffer,processandglobalasany, which strips node'sBufferunder"types": ["node", "@cloudflare/workers-types"]. A bun patch deletes those three lines until workerd#7539 lands.@types/node24 (matches the node major inmise.toml, not 26),portless0.15,gpt-tokenizer4.vitest-evals0.17. The scorer-first API moved tovitest-evals/legacy. It peersvitest <5; the legacy entry loads under vitest 5.Held back
@oxlint/pluginsstay at 1.86.@effect/tsgo0.48.1 patches the oxlint binding inprepareand refuses 1.87.versionSlugthat must match the live version row. That needs anatmn pullagainst the org first.@cloudflare/sandbox1.0. It's a rewrite: noSandbox/getSandbox, a donor image, and a new backup API. It goes in its own PR.Verification
tsc --noEmitis clean in db, backend, infra, ui, effect-sdk, effect-db, unitflow, api, ai, alerting, chat-bot, electric-sync, sandbox, web, cli, examples/alchemy-maple andtsconfig.alchemy.json, on a cleannode_modules.bun run lintis clean.CI=true(675)alchemy beta.81 comes in from
main(#1263) via a merge; its patch applies to the merged tree.Not run locally: the full suite,
bun dev, a real eval run (needs an OpenRouter key), and the chart perf specs.🤖 Generated with Claude Code