Skip to content

chore(deps)(deps-dev): bump typescript from 5.9.3 to 6.0.3 in /canvas - #2226

Closed
dependabot[bot] wants to merge 3 commits into
stagingfrom
dependabot/npm_and_yarn/canvas/typescript-6.0.3
Closed

chore(deps)(deps-dev): bump typescript from 5.9.3 to 6.0.3 in /canvas#2226
dependabot[bot] wants to merge 3 commits into
stagingfrom
dependabot/npm_and_yarn/canvas/typescript-6.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 28, 2026

Copy link
Copy Markdown
Contributor

Bumps typescript from 5.9.3 to 6.0.3.

Release notes

Sourced from typescript's releases.

TypeScript 6.0.3

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0 Beta

For release notes, check out the release announcement.

Downloads are available on:

Commits
  • 050880c Bump version to 6.0.3 and LKG
  • eeae9dd 🤖 Pick PR #63401 (Also check package name validity in...) into release-6.0 (#...
  • ad1c695 🤖 Pick PR #63368 (Harden ATA package name filtering) into release-6.0 (#63372)
  • 0725fb4 🤖 Pick PR #63310 (Mark class property initializers as...) into release-6.0 (#...
  • 607a22a Bump version to 6.0.2 and LKG
  • 9e72ab7 🤖 Pick PR #63239 (Fix missing lib files in reused pro...) into release-6.0 (#...
  • 35ff23d 🤖 Pick PR #63163 (Port anyFunctionType subtype fix an...) into release-6.0 (#...
  • e175b69 Bump version to 6.0.1-rc and LKG
  • af4caac Update LKG
  • 8efd7e8 Merge remote-tracking branch 'origin/main' into release-6.0
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Apr 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, npm. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

HongmingWang-Rabbit pushed a commit that referenced this pull request Apr 28, 2026
…dabot wave

Consolidates 11 of the 17 open Dependabot PRs (#2215, #2217, #2219-#2225,
#2227, #2229) into one PR. Every entry is a patch / minor / floor bump
where the impact surface is small and CI carries the proof.

Same pattern as the 2026-04-15 batch.

Go (workspace-server/go.mod + go.sum, regenerated via `go mod tidy`):
  - golang.org/x/crypto                    0.49.0  → 0.50.0   (#2225)
  - github.com/golang-jwt/jwt/v5           5.2.2   → 5.3.1    (#2222)
  - github.com/gin-contrib/cors            1.7.2   → 1.7.7    (#2220)
  - github.com/docker/go-connections       0.6.0   → 0.7.0    (#2223)
  - github.com/redis/go-redis/v9           9.7.3   → 9.19.0   (#2217)

Python floor bumps (workspace/requirements.txt; current pip-resolved
versions don't change unless they happen to be below the new floor):
  - httpx                                  >=0.27  → >=0.28.1 (#2221)
  - uvicorn                                >=0.30  → >=0.46   (#2229)
  - temporalio                             >=1.7   → >=1.26   (#2227)
  - websockets                             >=12    → >=16     (#2224)
  - opentelemetry-sdk                      >=1.24  → >=1.41.1 (#2219)

GitHub Actions (SHA-pinned per existing convention):
  - dorny/paths-filter@d1c1ffe (v3) → @fbd0ab8 (v4.0.1)        (#2215)

REMOVED from this batch (lockfile platform mismatch):
  - #2231 @types/node ^22 → ^25.6   (npm install on macOS strips
    Linux-only @emnapi/* entries from package-lock.json that CI's
    `npm ci` then refuses; needs a Linux-side install to land cleanly)
  - #2230 jsdom ^25 → ^29.1          (same)

NOT included in this batch (deferred to per-PR human review):
  - #2228 github/codeql-action     v3 → v4   (CodeQL CLI alignment risk)
  - #2218 actions/setup-node       v4 → v6   (default Node version drift)
  - #2216 actions/upload-artifact  v4 → v7   (3 major versions)
  - #2214 actions/setup-python     v5 → v6   (action major)

NOT merged (CI failing on dependabot's own PR):
  - #2233 next 15 → 16
  - #2232 tailwindcss 3 → 4
  - #2226 typescript 5 → 6

Verified:
  - workspace-server: `go mod tidy && go build ./... && go test ./...` — green
  - workspace requirements.txt: floor bumps only
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/canvas/typescript-6.0.3 branch from bc9238a to 87b3633 Compare April 29, 2026 00:54

@HongmingWang-Rabbit HongmingWang-Rabbit left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MAJOR bump typescript 5.9.3 → 6.0.3 in /canvas. Failing on Canvas (Next.js) and Canvas tabs E2E. TS 6 tightens inference; expect new errors in code that relied on permissive narrowing. Run pnpm typecheck against the diff and fix the new errors before merge.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/canvas/typescript-6.0.3 branch from 87b3633 to e48dde5 Compare May 3, 2026 01:34
@HongmingWang-Rabbit

Copy link
Copy Markdown
Contributor

Deferring. TS 5→6 introduces stricter type narrowing, changed --isolatedModules defaults, and removes several deprecations. Canvas typebase is hundreds of files — likely surfaces real type errors that need fixing in the same PR. Doing this in isolation will break next build and require many cleanup commits — bad atomic unit.

Defer until canvas-rebuild slice (task #31).

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/canvas/typescript-6.0.3 branch 2 times, most recently from 128f20a to 8257de0 Compare May 3, 2026 09:32
@HongmingWang-Rabbit

Copy link
Copy Markdown
Contributor

@dependabot rebase

Tailwind v4 + canvas overhaul just landed in #2555 (merged 2026-05-03 09:31). Rebase against the new staging head — TS 6 may green up against the freshly migrated canvas TypeScript surface.

Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 6.0.3.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v6.0.3)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/canvas/typescript-6.0.3 branch from 8257de0 to 92bbb8a Compare May 3, 2026 09:43
@HongmingWang-Rabbit

Copy link
Copy Markdown
Contributor

Auto-merge disarmed — TS 6.0 breaks the canvas build.

The Canvas (Next.js) check failed at 09:45Z this morning with:

```
./src/app/layout.tsx:3:8
Type error: Cannot find module or type declarations for side-effect import of './globals.css'.
```

TS 6.0 tightened side-effect import handling — it no longer infers a default declaration for non-JS modules imported for side effects. Fix is small but requires landing in the same PR (or just before):

  • Add `declare module "*.css";` to a `canvas/global.d.ts` (or extend `next-env.d.ts`)
  • Or use `/// ` if Next ships an updated declaration

Since this requires a code change in the canvas dir (not a pure version bump), let it sit until we have a coordinated upgrade window with the other TS-6 PRs across repos.

Closing tracks: would prefer a single migration commit that handles all repos (or an issue tracking the upgrade).

@molecule-ai molecule-ai Bot closed this May 20, 2026
@molecule-ai
molecule-ai Bot deleted the dependabot/npm_and_yarn/canvas/typescript-6.0.3 branch May 20, 2026 06:21
HongmingWang-Rabbit pushed a commit that referenced this pull request Jun 12, 2026
The standalone molecule-ai/canvas image previously only built+pushed
:latest + :sha-<sha> with no deploy step, and docker-compose referenced
canvas:latest UNPINNED. Tenants/hosts picked up new canvas only as a side
effect of the platform fleet-redeploy pulling :latest — non-deterministic
and unverifiable, hence the advisory "Canvas Deploy Reminder".

Mirror the platform's ordered deploy (publish-workspace-server-image.yml):

- publish-canvas-image.yml: build job now pushes :staging-<sha> +
  :staging-latest (+ legacy :sha-<sha>) and no longer moves :latest. New
  promote-canvas job waits for green main CI on the SHA (same
  prod-auto-deploy wait-ci SSOT the platform deploy uses), then re-points
  :latest to the verified :staging-<sha> by digest (imagetools create).
  So :latest == last CI-green canvas, and platform+canvas advance off the
  identical signal/SHA. Honors the PROD_AUTO_DEPLOY_DISABLED kill-switch.

- docker-compose.yml: canvas image pins via CANVAS_IMAGE_TAG (default
  latest = prod-blessed; set staging-<sha> or staging-<sha>@<digest> for a
  reproducible deploy). Resolves the standing TODO: pin canvas ECR digest.
  Local-dev `build:` context unchanged.

- ci.yml: replace the advisory "Canvas Deploy Reminder" (prescribed a
  manual docker compose pull) with "Canvas Deploy Status" recording that
  the ordered deploy is handling it.

Closes #2226

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant