Skip to content

chore(deps): refresh runtimes and adopt ESLint 10 - #11259

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
backryun:codex/eliminate-gemini-3-5-flash
Sep 1, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
backryun:codex/eliminate-gemini-3-5-flash

Conversation

@backryun

@backryun backryun commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR modernizes the repository's dependency and lint toolchain without changing provider behavior or application features.

  • adopt ESLint 10.9.0 and make the flat config compatible with its stricter plugin/parser contracts
  • align all remaining Bun toolchain surfaces with the repository's exact Bun 1.4.0 pin
  • refresh compatible runtime, framework, and development dependencies
  • regenerate and validate the npm lockfile

Implementation

  • wrap the Next.js preset with fixupConfigRules() from @eslint/compat
  • use espree for JavaScript files and the TypeScript parser for .mts / .cts
  • avoid duplicate @typescript-eslint plugin registration under ESLint 10
  • add @eslint/compat and espree to the dependency policy allowlist
  • remove 165 suppressions that no longer match live ESLint findings
  • update both Bun Docker stages from 1.3.14-slim to 1.4.0-slim
  • pin @types/bun to 1.4.0 and refresh the remaining compatible direct dependencies

Scope

The branch was rebuilt as a single commit on release/v3.8.51 at 63e4afa32. The current diff is limited to:

  • Dockerfile.bun
  • eslint.config.mjs
  • package.json
  • package-lock.json
  • config/quality/dependency-allowlist.json
  • config/quality/eslint-suppressions.json

Provider catalog changes, application code, and unrelated test-contract repairs are intentionally excluded. The Gemini 3.5 Flash removal from the PR's original history is already present on the release branch and is not part of this diff.

Validation

  • npm ci --no-audit --no-fund — pass (2,520 packages)
  • npm run lint -- --no-cache — pass
  • npm run check:lockfile — pass
  • npm run check:deps — pass
  • npm run check:node-runtime — pass on Node.js 26.8.1
  • npm run typecheck:core — pass
  • npm run test:vitest — 50 files / 463 tests pass
  • unchanged dashboard provider regression — 3/3 pass
  • unchanged Alibaba allowlist regression — 4/4 pass
  • npm run check:provider-consistency — pass on Bun 1.4.0
  • npm run check:compression-budget — pass on Bun 1.4.0 with isolated database paths
  • npm run check:known-symbols — pass on Bun 1.4.0 with isolated database paths
  • git diff --check and pre-commit quality gates — pass

Local npm 12 policy blocked Bun's postinstall during npm ci; the package's own installer was run inside the isolated validation worktree before executing the Bun gates. bun --version reported 1.4.0.

@backryun
backryun requested a review from diegosouzapw as a code owner August 23, 2026 15:35
diegosouzapw pushed a commit that referenced this pull request Aug 23, 2026
…11088 to the release line (#11271)

Validated on the combined 8-PR board: ollama-local-capabilities-routing 3/3, managed-model-import 9/9 (including the integration with the carried Gemini-3.5-Flash cleanup from #11259), 88/88 across the board's focused suites, typecheck:core + dashboard-typecheck clean, gates within baseline. This brings #11088 to the release line — it had squash-merged to main by base error (mine) — AND fixes the two defects the port caught: the global filter drop that leaked image/video models into OpenAI chat selections (now scoped to self-hosted providers) and the unregistered hard-lease credential site. Exemplary port discipline: byte-identical carry + the corrections in a separate reviewable commit + the superpowers docs deliberately left out. main still needs the same two-line fix. Thank you @yourspraveen!
diegosouzapw pushed a commit that referenced this pull request Aug 23, 2026
@diegosouzapw

Copy link
Copy Markdown
Owner

Status update from the maintainer side: the Gemini 3.5 Flash elimination commit (ddf1bb7) has been carried directly onto release/v3.8.50 (2764812, authorship preserved), integrated with the #11271 port that landed in the same window (the managedModelImport conflict was resolved so the antigravity/agy discoverable-id filters run before the scoped chat filter; managed-model-import suite 9/9). The endpoint-repair commit (6b983ff) was NOT carried because the release tip already repairs that file — 855243a fixed the same broken #11228 hunk but keeps the guided header (with corrected i18n keys), so your revert is fully covered. NOT carried, deliberately, this late in the v3.8.50 cycle: the runtime/toolchain bump commit (80f8f6b — ESLint 10, Bun 1.4.0, Next 16.3.2, vitest, etc.) — a major-toolchain adoption belongs at the start of the next cycle, and Bun is an exact-pin toolchain here (1.3.14, provisioned via the lockfile's @oven/bun-* binaries) so any bump needs the byte-identical gate validation run first; and the quality-contracts commit (63bfd5b), which overlaps the base-red drains already landing from other PRs (#11280 covers the dependency-allowlist + cliCatalog cluster). If you rebase the toolchain + remaining quality work onto the next release branch when it exists (v3.8.51), it will be very welcome there. Thank you @backryun!

@diegosouzapw diegosouzapw changed the title fix: refresh provider catalogs, runtimes, and quality contracts fix: refresh provider catalogs, runtimes, and quality contracts [defer to 3.8.51] Aug 23, 2026
@diegosouzapw diegosouzapw changed the title fix: refresh provider catalogs, runtimes, and quality contracts [defer to 3.8.51] fix: refresh provider catalogs, runtimes, and quality contracts Aug 23, 2026
@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch 6 times, most recently from 5daea96 to 5b59804 Compare August 24, 2026 02:01
@diegosouzapw diegosouzapw changed the title fix: refresh provider catalogs, runtimes, and quality contracts fix: refresh provider catalogs, runtimes, and quality contracts [defer to 3.8.51] Aug 24, 2026
@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch from 5b59804 to 91050eb Compare August 24, 2026 05:38
@backryun backryun changed the title fix: refresh provider catalogs, runtimes, and quality contracts [defer to 3.8.51] chore(deps): refresh runtimes and adopt ESLint 10 Aug 24, 2026
@backryun
backryun changed the base branch from release/v3.8.50 to release/v3.8.51 August 24, 2026 05:40
@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch from 91050eb to 9d16357 Compare August 25, 2026 00:43
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks — this is a clean, well-scoped ESLint 10 migration. Executed your branch in a probe worktree: npm ci from the updated lockfile installs cleanly and eslint 10.9.0 loads with the new config; a scoped lint run surfaces exactly the 5 known inherited base-red errors (#11449) and nothing new, so no regression is introduced by the config rewrite. Three items before merge: (1) AGENTS.md still documents 'Bun 1.3.14 is pinned as an exact devDependency' (~line 619) — please update it to 1.4.0 in the same PR to avoid introducing docs drift against our docs-accuracy rule; (2) please run one full-repo npm run lint to completion under ESLint 10 and, if any bulk-suppression entries go stale under v10 rule behavior, do a single --prune-suppressions pass (stale entries hard-exit 2); (3) note that dependabot #11428 bumps the exact same development group (bun 1.4.0, eslint-config-next 16.3.2, vitest, @vitejs/plugin-react, fumadocs-mdx, opencode-ai) — after this merges, that one should be closed as superseded rather than rebased, or the two lockfiles will fight. Also please re-run the three Bun-gated gates (check:provider-consistency, check:compression-budget, check:known-symbols) on 1.4.0 per the byte-identical requirement in AGENTS.md.

diegosouzapw pushed a commit that referenced this pull request Aug 25, 2026
Validated in a combined-batch worktree off release/v3.8.51 tip alongside #11259 and the cherry-picked #11323 successor (#11493):
- Focused test: tests/unit/oauth-connection-tokenexpiresat-5326.test.ts — 3/3 pass, exercises the round-trip through createProviderConnection/getProviderConnections
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity gates — all OK
- One-string allowlist fix, TDD-proven (fails on base with tokenExpiresAt: null, passes with the change), mutation-checked

Thanks for restoring #5326's fix end to end — clean, minimal, well-tested.
@diegosouzapw

Copy link
Copy Markdown
Owner

Held out of this merge batch: `npm run lint` fails on this branch (isolated, off the current `release/v3.8.51` tip) with 275 `@typescript-eslint/no-explicit-any` errors plus a stale-suppressions warning:

```
✖ 275 problems (275 errors, 0 warnings)
There are suppressions left that do not occur anymore. To resolve this, re-run the command with --prune-suppressions to remove unused suppressions.
```

Reproduced identically (same 275 errors) with only this PR boarded on the pure tip, so it's isolated to this branch's changes to `eslint.config.mjs` (TypeScript-plugin scoping) + `config/quality/eslint-suppressions.json`, not batch drift. The PR body's validation list covers `typecheck:core` and `test:vitest` but doesn't mention `npm run lint`, so this likely wasn't caught before opening.

The rest of the validation (`npm ci`, lockfile/deps/node-runtime checks, Bun 1.4.0 pin, typecheck:core) looks solid — this is specifically about the suppressions file needing to be re-synced against what ESLint 10 actually reports after the plugin-scoping change (probably `--prune-suppressions` plus addressing whatever newly-surfaced `no-explicit-any` violations aren't legitimately pre-existing). Happy to take another look once `npm run lint` is green on this branch.

@backryun

Copy link
Copy Markdown
Contributor Author

Held out of this merge batch: npm run lint fails on this branch (isolated, off the current release/v3.8.51 tip) with 275 @typescript-eslint/no-explicit-any errors plus a stale-suppressions warning:

✖ 275 problems (275 errors, 0 warnings) There are suppressions left that do not occur anymore. To resolve this, re-run the command with --prune-suppressions to remove unused suppressions.

Reproduced identically (same 275 errors) with only this PR boarded on the pure tip, so it's isolated to this branch's changes to eslint.config.mjs (TypeScript-plugin scoping) + config/quality/eslint-suppressions.json, not batch drift. The PR body's validation list covers typecheck:core and test:vitest but doesn't mention npm run lint, so this likely wasn't caught before opening.

The rest of the validation (npm ci, lockfile/deps/node-runtime checks, Bun 1.4.0 pin, typecheck:core) looks solid — this is specifically about the suppressions file needing to be re-synced against what ESLint 10 actually reports after the plugin-scoping change (probably --prune-suppressions plus addressing whatever newly-surfaced no-explicit-any violations aren't legitimately pre-existing). Happy to take another look once npm run lint is green on this branch.

Confirmed, will fix really soon.

@backryun

backryun commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor Author

@diegosouzapw Thanks for the detailed follow-up. I confirmed that #11502 covers the inherited release/v3.8.51 base-red repairs, so I will wait for it to merge before rebasing this PR to avoid duplicating those fixes or creating another lockfile conflict.

Once #11502 lands, I will rebase #11259 onto the updated release/v3.8.51 tip, update the AGENTS.md Bun pin from 1.3.14 to 1.4.0, run a full no-cache ESLint pass, and rerun check:provider-consistency, check:compression-budget, and check:known-symbols with an isolated DATA_DIR before force-pushing the refreshed branch.

@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch from 9d16357 to 40c96fb Compare August 25, 2026 22:22
@backryun

Copy link
Copy Markdown
Contributor Author

Rebased and force-pushed onto the current release/v3.8.51 tip (0023a9e). The refreshed head is 40c96fb.

Validation completed on the rebased branch:

  • npm ci: pass; local Bun resolves to 1.4.0
  • full-repo ESLint 10 pass with --no-cache: 0 violations
  • pruned exactly two stale suppression entries (executors/index.ts and autoCombo/routerStrategy.ts)
  • check:provider-consistency: pass
  • check:compression-budget: pass
  • check:known-symbols: pass
  • test:bun:db: 21/21 pass
  • typecheck:core: pass
  • test:vitest: 48 files / 452 tests pass
  • production build: pass
  • check:docs-all, check:deps, and check:lockfile: pass

All Bun gates used an isolated DATA_DIR and SQLITE_FILE.

The current base lazy-loads executors and made getExecutor asynchronous, while check-known-symbols still consumed it synchronously. I kept that base integration repair in a separate commit (40c96fb), with a focused regression test; tests/unit/check-known-symbols.test.ts passes 39/39 and the Bun gate validates all 142 executors.

For transparency, the complete Node unit matrix still contains inherited current-base failures. I reproduced the relevant 10 failures independently on a detached clean 0023a9e worktree, so they are not introduced by this PR. The PR-specific lint and requested Bun gates are now green.

@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch from 40c96fb to a8a79ec Compare August 25, 2026 23:10
@backryun

Copy link
Copy Markdown
Contributor Author

Follow-up: the four red jobs from the previous run are now addressed and the branch has been rebased again onto the current release/v3.8.51 tip (d3c395b). New head: a8a79ec.

The failures were stale contracts left by recently merged base changes, not ESLint 10 runtime regressions. The repair updates:

  • mutation coverage inventory for the tunnel route-guard and universal quota-aware tests
  • route-guard exemption expectation for the reviewed cloudflared GET exemption
  • Claude Web static assertion for the new lazy executor map
  • Command Code tests to await async execute results
  • current Gemini alias spelling and provider-aware Qwen 3.8 lifecycle expectations
  • the required packed CLI closure for volatileEnvPath.mjs plus its policy expectation
  • the five Vietnamese reliability strings that were still marked MISSING

Post-commit validation:

  • focused affected tests: 81/81 pass
  • check:mutation-test-coverage --strict: pass, no drift across 4,562 unit files / 31 mutated modules
  • check:pack-policy: pass
  • changed-file ESLint and Prettier checks: pass

The new CI run is now queued.

@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch from a8a79ec to 72bfc45 Compare August 25, 2026 23:22
@backryun

Copy link
Copy Markdown
Contributor Author

CI follow-up complete on 72bfc4592.

The remaining Unit Tests 2/4 failures were stale base-contract assertions introduced by the newly rebased release tip:

Validation: focused tests 10/10, changed-file ESLint and Prettier checks pass. The rerun is fully green: all four unit shards, Fast Quality Gates, Vitest, build, docs, ESLint, merge integrity, DAST, and Semgrep.

@backryun

Copy link
Copy Markdown
Contributor Author

@diegosouzapw resolved the issue so thoroughly that it can be merged immediately without any problems.

@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch 12 times, most recently from 2cefdfa to addddff Compare August 31, 2026 06:53
@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch 2 times, most recently from f05c7bd to 37a9e6c Compare August 31, 2026 22:22
@backryun

Copy link
Copy Markdown
Contributor Author

@diegosouzapw full overhauled, much more simpler commit. I hope can this accept soon.

@backryun
backryun force-pushed the codex/eliminate-gemini-3-5-flash branch 5 times, most recently from bf3cb94 to b0c9807 Compare September 1, 2026 06:40
@diegosouzapw

Copy link
Copy Markdown
Owner

Validated in local merge-train on 192.168.0.113 — train of #12258 #12262 #12166 #12281 #11259 #11950 merged clean onto origin/release/v3.8.51 (f5e7095):

  • Run 1 (/opt/actions-runner-omniroute-5, train tip 85cd9119): typecheck:core, file-size, complexity ×2, changelog-integrity — all green; the test:unit step was killed by a CI job landing on that runner mid-train (workspace clobbered — infra, documented risk).
  • Run 2 (/srv/omniroute-train/.claude/worktrees/mt-green1, same 6 PRs re-boarded, fresh npm ci): unit 35768/35805 pass (/tmp/mt-unit2.log), vitest 464/465 (/tmp/mt-vitest2.log).
  • Every failure is a latency/timing assert (bounded-time, event-loop lag, cooldown windows) on a box that was never idle (3 active CI runner workers throughout). Discriminated per merge-gates §3: the 3 persistent titles reproduce identically on the pure base tip on the same box (/tmp/mt-base-isolated.log, BASE_ISOLATED_EXIT=1 — same tests, same asserts), 5 more titles reproduce on the pure base on the devbox, and the single vitest failure (provider-family-combos) also fails on main's nightly without any of these PRs. Inherited/infra — not introduced by this train.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deferred-v3.8.52 Grande demais / suspeito para o lote atual; precisa de sessão dedicada no ciclo v3.8.52

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants