chore(deps): refresh runtimes and adopt ESLint 10 - #11259
diegosouzapw merged 1 commit into
Conversation
…11088 to the release line (#11271) Validated on the combined 8-PR board: ollama-local-capabilities-routing 3/3, managed-model-import 9/9 (including the integration with the carried Gemini-3.5-Flash cleanup from #11259), 88/88 across the board's focused suites, typecheck:core + dashboard-typecheck clean, gates within baseline. This brings #11088 to the release line — it had squash-merged to main by base error (mine) — AND fixes the two defects the port caught: the global filter drop that leaked image/video models into OpenAI chat selections (now scoped to self-hosted providers) and the unregistered hard-lease credential site. Exemplary port discipline: byte-identical carry + the corrections in a separate reviewable commit + the superpowers docs deliberately left out. main still needs the same two-line fix. Thank you @yourspraveen!
|
Status update from the maintainer side: the Gemini 3.5 Flash elimination commit (ddf1bb7) has been carried directly onto release/v3.8.50 (2764812, authorship preserved), integrated with the #11271 port that landed in the same window (the managedModelImport conflict was resolved so the antigravity/agy discoverable-id filters run before the scoped chat filter; managed-model-import suite 9/9). The endpoint-repair commit (6b983ff) was NOT carried because the release tip already repairs that file — 855243a fixed the same broken #11228 hunk but keeps the guided header (with corrected i18n keys), so your revert is fully covered. NOT carried, deliberately, this late in the v3.8.50 cycle: the runtime/toolchain bump commit (80f8f6b — ESLint 10, Bun 1.4.0, Next 16.3.2, vitest, etc.) — a major-toolchain adoption belongs at the start of the next cycle, and Bun is an exact-pin toolchain here (1.3.14, provisioned via the lockfile's @oven/bun-* binaries) so any bump needs the byte-identical gate validation run first; and the quality-contracts commit (63bfd5b), which overlaps the base-red drains already landing from other PRs (#11280 covers the dependency-allowlist + cliCatalog cluster). If you rebase the toolchain + remaining quality work onto the next release branch when it exists (v3.8.51), it will be very welcome there. Thank you @backryun! |
5daea96 to
5b59804
Compare
5b59804 to
91050eb
Compare
91050eb to
9d16357
Compare
|
Thanks — this is a clean, well-scoped ESLint 10 migration. Executed your branch in a probe worktree: npm ci from the updated lockfile installs cleanly and eslint 10.9.0 loads with the new config; a scoped lint run surfaces exactly the 5 known inherited base-red errors (#11449) and nothing new, so no regression is introduced by the config rewrite. Three items before merge: (1) AGENTS.md still documents 'Bun 1.3.14 is pinned as an exact devDependency' (~line 619) — please update it to 1.4.0 in the same PR to avoid introducing docs drift against our docs-accuracy rule; (2) please run one full-repo |
Validated in a combined-batch worktree off release/v3.8.51 tip alongside #11259 and the cherry-picked #11323 successor (#11493): - Focused test: tests/unit/oauth-connection-tokenexpiresat-5326.test.ts — 3/3 pass, exercises the round-trip through createProviderConnection/getProviderConnections - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity gates — all OK - One-string allowlist fix, TDD-proven (fails on base with tokenExpiresAt: null, passes with the change), mutation-checked Thanks for restoring #5326's fix end to end — clean, minimal, well-tested.
|
Held out of this merge batch: `npm run lint` fails on this branch (isolated, off the current `release/v3.8.51` tip) with 275 `@typescript-eslint/no-explicit-any` errors plus a stale-suppressions warning: ``` Reproduced identically (same 275 errors) with only this PR boarded on the pure tip, so it's isolated to this branch's changes to `eslint.config.mjs` (TypeScript-plugin scoping) + `config/quality/eslint-suppressions.json`, not batch drift. The PR body's validation list covers `typecheck:core` and `test:vitest` but doesn't mention `npm run lint`, so this likely wasn't caught before opening. The rest of the validation (`npm ci`, lockfile/deps/node-runtime checks, Bun 1.4.0 pin, typecheck:core) looks solid — this is specifically about the suppressions file needing to be re-synced against what ESLint 10 actually reports after the plugin-scoping change (probably `--prune-suppressions` plus addressing whatever newly-surfaced `no-explicit-any` violations aren't legitimately pre-existing). Happy to take another look once `npm run lint` is green on this branch. |
Confirmed, will fix really soon. |
|
@diegosouzapw Thanks for the detailed follow-up. I confirmed that #11502 covers the inherited release/v3.8.51 base-red repairs, so I will wait for it to merge before rebasing this PR to avoid duplicating those fixes or creating another lockfile conflict. Once #11502 lands, I will rebase #11259 onto the updated release/v3.8.51 tip, update the AGENTS.md Bun pin from 1.3.14 to 1.4.0, run a full no-cache ESLint pass, and rerun check:provider-consistency, check:compression-budget, and check:known-symbols with an isolated DATA_DIR before force-pushing the refreshed branch. |
9d16357 to
40c96fb
Compare
|
Rebased and force-pushed onto the current release/v3.8.51 tip (0023a9e). The refreshed head is 40c96fb. Validation completed on the rebased branch:
All Bun gates used an isolated DATA_DIR and SQLITE_FILE. The current base lazy-loads executors and made getExecutor asynchronous, while check-known-symbols still consumed it synchronously. I kept that base integration repair in a separate commit (40c96fb), with a focused regression test; tests/unit/check-known-symbols.test.ts passes 39/39 and the Bun gate validates all 142 executors. For transparency, the complete Node unit matrix still contains inherited current-base failures. I reproduced the relevant 10 failures independently on a detached clean 0023a9e worktree, so they are not introduced by this PR. The PR-specific lint and requested Bun gates are now green. |
40c96fb to
a8a79ec
Compare
|
Follow-up: the four red jobs from the previous run are now addressed and the branch has been rebased again onto the current release/v3.8.51 tip (d3c395b). New head: a8a79ec. The failures were stale contracts left by recently merged base changes, not ESLint 10 runtime regressions. The repair updates:
Post-commit validation:
The new CI run is now queued. |
a8a79ec to
72bfc45
Compare
|
CI follow-up complete on The remaining Unit Tests 2/4 failures were stale base-contract assertions introduced by the newly rebased release tip:
Validation: focused tests 10/10, changed-file ESLint and Prettier checks pass. The rerun is fully green: all four unit shards, Fast Quality Gates, Vitest, build, docs, ESLint, merge integrity, DAST, and Semgrep. |
|
@diegosouzapw resolved the issue so thoroughly that it can be merged immediately without any problems. |
2cefdfa to
addddff
Compare
f05c7bd to
37a9e6c
Compare
|
@diegosouzapw full overhauled, much more simpler commit. I hope can this accept soon. |
bf3cb94 to
b0c9807
Compare
|
Validated in local merge-train on 192.168.0.113 — train of #12258 #12262 #12166 #12281 #11259 #11950 merged clean onto
|
Summary
This PR modernizes the repository's dependency and lint toolchain without changing provider behavior or application features.
Implementation
fixupConfigRules()from@eslint/compatespreefor JavaScript files and the TypeScript parser for.mts/.cts@typescript-eslintplugin registration under ESLint 10@eslint/compatandespreeto the dependency policy allowlist1.3.14-slimto1.4.0-slim@types/bunto 1.4.0 and refresh the remaining compatible direct dependenciesScope
The branch was rebuilt as a single commit on
release/v3.8.51at63e4afa32. The current diff is limited to:Dockerfile.buneslint.config.mjspackage.jsonpackage-lock.jsonconfig/quality/dependency-allowlist.jsonconfig/quality/eslint-suppressions.jsonProvider catalog changes, application code, and unrelated test-contract repairs are intentionally excluded. The Gemini 3.5 Flash removal from the PR's original history is already present on the release branch and is not part of this diff.
Validation
npm ci --no-audit --no-fund— pass (2,520 packages)npm run lint -- --no-cache— passnpm run check:lockfile— passnpm run check:deps— passnpm run check:node-runtime— pass on Node.js 26.8.1npm run typecheck:core— passnpm run test:vitest— 50 files / 463 tests passnpm run check:provider-consistency— pass on Bun 1.4.0npm run check:compression-budget— pass on Bun 1.4.0 with isolated database pathsnpm run check:known-symbols— pass on Bun 1.4.0 with isolated database pathsgit diff --checkand pre-commit quality gates — passLocal npm 12 policy blocked Bun's postinstall during
npm ci; the package's own installer was run inside the isolated validation worktree before executing the Bun gates.bun --versionreported1.4.0.