Repository navigation
fix: pin file-type to resolve CI flake #1740 - #1753
Conversation
📝 WalkthroughWalkthrough
ChangesDependency resolution
Estimated code review effort: 1 (Trivial) | ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
Failed to generate code suggestions for PR |
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
package.json bumped the file-type override to ^21.3.4 but package-lock.json wasn't regenerated, so npm ci failed with EUSAGE (lock out of sync). npm install resyncs it.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Size Change: 0 B Total Size: 493 kB ℹ️ View Unchanged
|
The prior commit added file-type as a direct ^21.3.4 dependency but dropped the >=21.3.2 override, so npm still hoisted file-type@16.5.4 nested under @discord-player/extractor (its own dependency range), reintroducing the duplicate-version issue that caused the original CI flake plus a known DoS CVE (CVE-2026-31808) at the vulnerable nested version. Restoring the override as "$file-type" (referencing the direct dependency, since a literal range conflicts with npm's override validation) forces one resolved copy tree-wide.
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Auto-approved: Pins file-type version to fix CI flake. Safe dependency management change with no logic or API impact.
Re-trigger cubic
|
🤖 I have created a release *beep* *boop* --- <details><summary>2.34.0</summary> ## [2.34.0](v2.33.1...v2.34.0) (2026-07-10) ### Features * **twitch:** use Promise.allSettled for per-event subscription error logging ([#1749](#1749)) ([6691305](6691305)) ### Bug Fixes * [#1699](#1699) ([eef5aee](eef5aee)) * **backend:** migrate webhooks to use canonical timingsafekey comparison ([#1747](#1747)) ([eef5aee](eef5aee)) * **backend:** wrap lastfm routes with asynchandler ([#1726](#1726)) ([ce51d86](ce51d86)) * **batch-move:** graceful attachment-fetch degradation + mid-loop client re-check ([#1750](#1750)) ([f21a0ce](f21a0ce)) * **bot:** approve @discordjs/opus install script — P0 music playback outage ([#1757](#1757)) ([9d894e4](9d894e4)) * **ci:** add missing packages field to pnpm-workspace.yaml ([#1760](#1760)) ([a4c585d](a4c585d)) * **ci:** remove pnpm shim from bundle-size workflow ([#1759](#1759)) ([eaf676f](eaf676f)) * **deploy:** increase validation timeout to 10min ([#1743](#1743)) ([07891ec](07891ec)) * **docker:** copy+chown [@prisma](https://github.com/prisma) engines in production-backend — P0 deploy pipeline blocker ([#1758](#1758)) ([a70d0e8](a70d0e8)) * eliminate mock state pollution in bot tests and remove resetMocks config ([#1741](#1741)) ([2e5fd94](2e5fd94)) * **frontend:** prevent state updates after unmount ([#1748](#1748)) ([f4e7c45](f4e7c45)) * pin file-type to resolve CI flake [#1740](#1740) ([#1753](#1753)) ([6b8e527](6b8e527)) * reduce Jest maxWorkers and add DB pool config for test stability ([#1751](#1751)) ([cfead33](cfead33)) * use fake timers in ReminderService.spec to prevent race condition ([#1745](#1745)) ([ba2908c](ba2908c)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).



Problem
Issue #1740 reports an intermittent CI flake in the bot test suite:
Cannot find module 'file-type' from '@discord-player/extractor'. The root cause is duplicate versions offile-typein the dependency tree:@discord-player/extractor@7.2.0requiresfile-type@^16.5.4file-type@^21.3.0This version ambiguity causes npm to sometimes hoist different versions depending on install order, leading to runtime failures.
Solution
file-type@^21.3.4as an explicit root-level dependencyThe fix doesn't break anything: even though
@discord-player/extractordeclares a requirement for^16.5.4, npm will use the hoisted 21.x version, which is compatible.Verification
Type check and bot test suite should pass consistently across multiple fresh installs.
Closes #1740
Summary by cubic
Pin
file-typeto^21.3.4and enforce a single resolution via npmoverridesto remove hoisting ambiguity that caused CI flakes and the vulnerable 16.x copy. Fixes #1740.file-type@^21.3.4and setoverrides: { "file-type": "$file-type" }to force one version for all consumers, including@discord-player/extractor.npm ciconsistently installsfile-type@21.3.4.Written for commit e9f062b. Summary will update on new commits.
Summary by CodeRabbit