Skip to content

fix: pin file-type to resolve CI flake #1740 - #1753

Merged
LucasSantana-Dev merged 10 commits into
mainfrom
fix/1740-file-type-ci-flake
Jul 10, 2026
Merged

LucasSantana-Dev merged 10 commits into
mainfrom
fix/1740-file-type-ci-flake

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Jul 9, 2026 •

Copy link
Copy Markdown
Owner

Problem

Issue #1740 reports an intermittent CI flake in the bot test suite: Cannot find module 'file-type' from '@discord-player/extractor'. The root cause is duplicate versions of file-type in the dependency tree:

  • @discord-player/extractor@7.2.0 requires file-type@^16.5.4
  • Other packages require file-type@^21.3.0

This version ambiguity causes npm to sometimes hoist different versions depending on install order, leading to runtime failures.

Solution

  • Add file-type@^21.3.4 as an explicit root-level dependency
  • This ensures npm hoists a consistent version (21.3.4) at the root, which @discord-player/extractor will use

The fix doesn't break anything: even though @discord-player/extractor declares a requirement for ^16.5.4, npm will use the hoisted 21.x version, which is compatible.

Verification

Type check and bot test suite should pass consistently across multiple fresh installs.

Closes #1740


Summary by cubic

Pin file-type to ^21.3.4 and enforce a single resolution via npm overrides to remove hoisting ambiguity that caused CI flakes and the vulnerable 16.x copy. Fixes #1740.

  • Bug Fixes
    • Add root file-type@^21.3.4 and set overrides: { "file-type": "$file-type" } to force one version for all consumers, including @discord-player/extractor.
    • Regenerate the lockfile so npm ci consistently installs file-type@21.3.4.

Written for commit e9f062b. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Updated package configuration to ensure consistent handling of file type detection.
    • Refined dependency override settings for improved version alignment.

- Add file-type@^21.3.4 as explicit root dependency
- Pin override to 21.3.4 (instead of >=21.3.2)
- Resolves #1740: @discord-player/extractor requires ^16.5.4 but npm will hoist the root-level 21.3.4 package, reducing install-time hoisting ambiguity that causes CI flakes

Closes #1740
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Jul 9, 2026
@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

package.json now declares file-type directly at ^21.3.4 and makes its override reference that declaration, removing the previous standalone version constraint.

Changes

Dependency resolution

Layer / File(s) Summary
Direct file-type dependency and override
package.json
Adds file-type at ^21.3.4, references it through the override configuration, and removes the prior >=21.3.2 override entry.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The package.json changes add a root file-type dependency and override, matching the issue's goal to eliminate duplicate versions.
Out of Scope Changes check ✅ Passed The diff only touches package.json for the file-type pin and override, with no obvious unrelated changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: pinning file-type to eliminate the CI flake.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/1740-file-type-ci-flake

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread package.json
LucasSantana-Dev and others added 2 commits July 9, 2026 15:08
package.json bumped the file-type override to ^21.3.4 but
package-lock.json wasn't regenerated, so npm ci failed with EUSAGE
(lock out of sync). npm install resyncs it.
@github-actions github-actions Bot added size/m and removed size/xs labels Jul 9, 2026
@socket-security

socket-security Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedfile-type@​21.3.2 ⏵ 21.3.4100 +12100100 +185100

View full report

@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Size Change: 0 B

Total Size: 493 kB

ℹ️ View Unchanged
Filename Size
packages/frontend/dist/assets/AddStyledRoleForm-C3Hh34pr.js 3.11 kB
packages/frontend/dist/assets/Admin-DQMEWb36.js 2.3 kB
packages/frontend/dist/assets/AdminSupport-BWie-gy3.js 1.6 kB
packages/frontend/dist/assets/api-B1lHOZZ9.js 4.01 kB
packages/frontend/dist/assets/AutoMessages-CY1s3puD.js 2.65 kB
packages/frontend/dist/assets/AutoMod-6IIp64ik.js 4.19 kB
packages/frontend/dist/assets/badge-BRy27WLt.js 503 B
packages/frontend/dist/assets/BatchJobs-CuAhGRXh.js 3.72 kB
packages/frontend/dist/assets/Card-DmknBHp9.js 507 B
packages/frontend/dist/assets/Changelog-Dkf1uPiy.js 55.9 kB
packages/frontend/dist/assets/CommandsConfig-DQYezFQe.js 1.51 kB
packages/frontend/dist/assets/Config-C_BYJIO6.js 1.98 kB
packages/frontend/dist/assets/CustomCommands-BfrVGSDM.js 2.12 kB
packages/frontend/dist/assets/DashboardOverview-DxA-wmz-.js 3.95 kB
packages/frontend/dist/assets/dialog-CryXol77.js 959 B
packages/frontend/dist/assets/Docs-YIhMA3Y3.js 17.6 kB
packages/frontend/dist/assets/DocsShell-CnVN0iz0.js 1.42 kB
packages/frontend/dist/assets/EmbedBuilder-UyLAUnQ9.js 3.28 kB
packages/frontend/dist/assets/Features-B_M6ECN-.js 757 B
packages/frontend/dist/assets/GuildAutomation-DamcXB5T.js 2.88 kB
packages/frontend/dist/assets/index-BFJIknuY.js 70.9 kB
packages/frontend/dist/assets/index-DY6JagVQ.css 17.6 kB
packages/frontend/dist/assets/input-DYohlqBm.js 464 B
packages/frontend/dist/assets/label-B6cL3Efn.js 477 B
packages/frontend/dist/assets/Landing-BaskhfZB.js 5.2 kB
packages/frontend/dist/assets/LastFm-COePF4ei.js 1.74 kB
packages/frontend/dist/assets/legalNav-B6k3CWsW.js 274 B
packages/frontend/dist/assets/Levels-CmdX-T8r.js 2.27 kB
packages/frontend/dist/assets/Login-BKulZbhs.js 2.5 kB
packages/frontend/dist/assets/Lyrics-v7xtclHR.js 1.34 kB
packages/frontend/dist/assets/Moderation-C-CNb-BJ.js 3.77 kB
packages/frontend/dist/assets/Music-Cn5z8c6U.js 5.97 kB
packages/frontend/dist/assets/MusicConfig-43O-gwu7.js 1.65 kB
packages/frontend/dist/assets/PreferredArtists-Bzf_siH3.js 3.72 kB
packages/frontend/dist/assets/PrivacyPolicy-BWyTCmeV.js 1.77 kB
packages/frontend/dist/assets/ReactionRoles-C0qSzisB.js 7.04 kB
packages/frontend/dist/assets/RoleGroups-5BU73tAT.js 2.24 kB
packages/frontend/dist/assets/Roles-DSkXFb-f.js 3.34 kB
packages/frontend/dist/assets/rolldown-runtime-Cyuzqnbw.js 471 B
packages/frontend/dist/assets/routeMeta-BZjtwMbs.js 595 B
packages/frontend/dist/assets/SectionHeader-DXnUkNXd.js 895 B
packages/frontend/dist/assets/select-DptaWMC7.js 1.23 kB
packages/frontend/dist/assets/sentry-DhXOA89y.js 3.76 kB
packages/frontend/dist/assets/ServerLogs-CtjfDLvO.js 3.04 kB
packages/frontend/dist/assets/ServerSettings--3JFBplD.js 3.99 kB
packages/frontend/dist/assets/ServersPage-ZWP9Aam-.js 3.04 kB
packages/frontend/dist/assets/Skeleton-D2FHRO2A.js 236 B
packages/frontend/dist/assets/Spotify-nMoPlkGj.js 1.75 kB
packages/frontend/dist/assets/Starboard-CMIvczPt.js 1.82 kB
packages/frontend/dist/assets/StatTile-C33joOfm.js 640 B
packages/frontend/dist/assets/Support-mVoJ_pGn.js 1.56 kB
packages/frontend/dist/assets/switch-BJAW5k8F.js 543 B
packages/frontend/dist/assets/TermsOfService-CCefpvyN.js 1.59 kB
packages/frontend/dist/assets/TrackHistory-DCkbE815.js 2.31 kB
packages/frontend/dist/assets/TwitchNotifications-DL9QVQXs.js 2.44 kB
packages/frontend/dist/assets/useActiveHeading-CXIIWu8V.js 1.36 kB
packages/frontend/dist/assets/useFeatures-ZFQsQ5k6.js 2.07 kB
packages/frontend/dist/assets/usePageMetadata-DTv-6eVb.js 327 B
packages/frontend/dist/assets/vendor-forms-C-bof8GF.js 25.9 kB
packages/frontend/dist/assets/vendor-radix-qkfmDH9H.js 39.9 kB
packages/frontend/dist/assets/vendor-react-B7C34xnu.js 55.7 kB
packages/frontend/dist/assets/vendor-state-Dw4-MN6C.js 24.2 kB
packages/frontend/dist/assets/vendor-ui-BBN61NBD.js 66.2 kB

compressed-size-action

Comment thread package-lock.json Fixed
@LucasSantana-Dev
LucasSantana-Dev enabled auto-merge (squash) July 9, 2026 18:56
LucasSantana-Dev and others added 2 commits July 9, 2026 16:12
The prior commit added file-type as a direct ^21.3.4 dependency but
dropped the >=21.3.2 override, so npm still hoisted file-type@16.5.4
nested under @discord-player/extractor (its own dependency range),
reintroducing the duplicate-version issue that caused the original
CI flake plus a known DoS CVE (CVE-2026-31808) at the vulnerable
nested version. Restoring the override as "$file-type" (referencing
the direct dependency, since a literal range conflicts with npm's
override validation) forces one resolved copy tree-wide.
@github-actions github-actions Bot added size/s and removed size/m labels Jul 9, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 2 files (changes from recent commits).

Auto-approved: Pins file-type version to fix CI flake. Safe dependency management change with no logic or API impact.

Re-trigger cubic

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit 6b8e527 into main Jul 10, 2026
45 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/1740-file-type-ci-flake branch July 10, 2026 02:05
LucasSantana-Dev added a commit that referenced this pull request Jul 10, 2026
🤖 I have created a release *beep* *boop*
---


<details><summary>2.34.0</summary>

##
[2.34.0](v2.33.1...v2.34.0)
(2026-07-10)


### Features

* **twitch:** use Promise.allSettled for per-event subscription error
logging ([#1749](#1749))
([6691305](6691305))


### Bug Fixes

* [#1699](#1699)
([eef5aee](eef5aee))
* **backend:** migrate webhooks to use canonical timingsafekey
comparison
([#1747](#1747))
([eef5aee](eef5aee))
* **backend:** wrap lastfm routes with asynchandler
([#1726](#1726))
([ce51d86](ce51d86))
* **batch-move:** graceful attachment-fetch degradation + mid-loop
client re-check
([#1750](#1750))
([f21a0ce](f21a0ce))
* **bot:** approve @discordjs/opus install script — P0 music playback
outage ([#1757](#1757))
([9d894e4](9d894e4))
* **ci:** add missing packages field to pnpm-workspace.yaml
([#1760](#1760))
([a4c585d](a4c585d))
* **ci:** remove pnpm shim from bundle-size workflow
([#1759](#1759))
([eaf676f](eaf676f))
* **deploy:** increase validation timeout to 10min
([#1743](#1743))
([07891ec](07891ec))
* **docker:** copy+chown [@prisma](https://github.com/prisma) engines in
production-backend — P0 deploy pipeline blocker
([#1758](#1758))
([a70d0e8](a70d0e8))
* eliminate mock state pollution in bot tests and remove resetMocks
config ([#1741](#1741))
([2e5fd94](2e5fd94))
* **frontend:** prevent state updates after unmount
([#1748](#1748))
([f4e7c45](f4e7c45))
* pin file-type to resolve CI flake
[#1740](#1740)
([#1753](#1753))
([6b8e527](6b8e527))
* reduce Jest maxWorkers and add DB pool config for test stability
([#1751](#1751))
([cfead33](cfead33))
* use fake timers in ReminderService.spec to prevent race condition
([#1745](#1745))
([ba2908c](ba2908c))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
This was referenced Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size/s

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: Test — bot intermittently fails with Cannot find module 'file-type' from @discord-player/extractor

2 participants