Skip to content

deps: realign onnxruntime-node pin to @huggingface/transformers' 1.24.3 lockstep - #11633

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
jonlwheat2-gif:fix/onnx-transformers-lockstep-pin
Aug 26, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
jonlwheat2-gif:fix/onnx-transformers-lockstep-pin

Conversation

@jonlwheat2-gif

@jonlwheat2-gif jonlwheat2-gif commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Fixes the last remaining red from run 32933234257 on release/v3.8.51 (base-red #11449). The other five failing areas in that run were already fixed on base by #11582, #11585, #11588 and #11593; the ONNX drift was not.

Root cause

#11440's production-group dependabot bump moved the root optionalDependencies + overrides pin for onnxruntime-node 1.24.3 → 1.27.0, but @huggingface/transformers@4.2.0 hard-pins onnxruntime-node: "1.24.3" in its own dependencies.

Upstream evidence (researched 2026-08-26)

  • npm dist-tag latest = 4.2.0 (published 2026-04-22); next = stale 4.0.0-next.11. No release since April.
  • Every published 4.x release pins onnxruntime-node 1.24.3 exactly (verified via npm view across all 4.x versions: 4.0.0, 4.0.1, 4.1.0, 4.2.0 → all 1.24.3). There is no released version to lockstep against at 1.27.x today.
  • Upstream support for 1.27 exists only as two open, unmerged PRs against huggingface/transformers.js:
  • Neither is merged or tagged as of this writing, so root cannot legally pin 1.27.x without breaking the single-copy/lockstep contract.

Corroborating detail: the transitive closure my regenerated lockfile restores (global-agent@^3 → roarr, matcher@3, semver-compare, sprintf-js, detect-node, es6-error, json-stringify-safe, boolean) is precisely the subtree upstream PR #1730 describes removing when it moves to 1.27 — independent confirmation that this tree belongs to the 1.24.3 pin.

When upstream merges #1730/#1731 and tags a release pinning 1.27.x, both packages must bump together in one commit — that is the whole point of the lockstep rule pinned by the guard tests below.

Why exact equality matters

onnxruntime-node ships a native library (libonnxruntime.so.1 / .dll). If root says 1.27.0 while transformers pins 1.24.3, npm nests a second copy; two native libs under one SONAME cannot coexist in a process — the loader binds whichever dlopen()s first and the other addon dies with version 'VERS_1.27.0' not found. Dependabot made this same bump on 2026-08-16 and broke the Docker standalone build (documented in the header of tests/unit/onnxruntime-single-copy.test.ts).

The overrides entry masked the nesting by forcing a single hoisted copy at 1.27.0, so the single-copy guard kept passing, but it violated the lockstep contract pinned by:

  • tests/unit/onnxruntime-single-copy.test.ts ("root onnxruntime-node matches the exact version @huggingface/transformers pins")
  • tests/unit/build/optional-transformers-dependency.test.ts (optionalDependency pin == overrides pin == upstream's pin)

Fix

Reverts both root pins to 1.24.3 and regenerates package-lock.json. Lockfile resolves exactly one onnxruntime-node copy at exactly the version transformers.js declares, plus its matching transitive closure.

Diff footprint: package.json (2 lines) + package-lock.json (onnxruntime-node subtree only — every changed lock entry verified to belong to the onnxruntime closure).

Verification

node --import tsx/esm --test tests/unit/build/optional-transformers-dependency.test.ts tests/unit/onnxruntime-single-copy.test.ts
# 5/5 pass (3 previously red)

# lockfile audit
copies of onnxruntime-node: [node_modules/onnxruntime-node]
hoisted version: 1.24.3 == transformers pin 1.24.3

Note: npm run check:lockfile currently fails identically on pristine origin/release/v3.8.51 (pre-existing claude-agent-sdk URL-validation entries) — unrelated to and unchanged by this PR.

⚠️ base-red inherited: #11449

This diff touches only package.json (2 lines) + package-lock.json. Every failing job fails identically on pristine origin/release/v3.8.51 and is inherited, not introduced here:

  • Unit Tests fast-path (1-4/4) — e.g. provider-translate-path-golden.test.ts "GOLDEN provider.ts translate-path is stable across all providers" reproduces on unfixed tip locally; likewise the live-ws/embedWsProxy port-binding tests, APIKEY_PROVIDERS merges ... 233 entries, and the credential-inventory classification checks. None read these manifests.
  • Vitest (fast-path) — tests/unit/autoCombo/models-dev-tier-11508.test.ts: "No test suite found" on both branches (fixed separately by test(autoCombo): port models_dev_tier #11508 guard from node:test to vitest #11635).
  • Docs Gates (fast-path) — same 7 STRICT drifts on both (provider count moved 353 → 354 in code; AGENTS.md, llm.txt, package.json description and hero/diagram SVGs still say "353"). Needs its own docs-sync fix PR.
  • No new ESLint warnings — exits with "There are suppressions left that do not occur anymore" (config/quality/eslint-suppressions.json stale entries); pre-existing on tip, owned by fix(sse): explicit types for openai-responses pureHelpers — clears last failing core typecheck gate #11567.

….3 lockstep

diegosouzapw#11440's production-group bump moved the root optionalDependencies +
overrides pin 1.24.3 -> 1.27.0 while @huggingface/transformers@4.2.0
still hard-pins onnxruntime-node 1.24.3 in its own dependencies (no
4.x release pins anything newer). The overrides entry masked the
nesting by forcing a single hoisted copy at 1.27.0, but broke the
lockstep contract pinned by tests/unit/onnxruntime-single-copy.test.ts
and tests/unit/build/optional-transformers-dependency.test.ts — the
same class of SONAME clash that broke the Docker standalone build on
2026-08-16 when root drifts off upstream's pin.

Reverts both pins to 1.24.3 and regenerates the lockfile: one copy of
onnxruntime-node at exactly the version transformers.js declares, plus
its matching transitive closure (global-agent@^3 tree).

Verified:
- node --import tsx/esm --test tests/unit/build/optional-transformers-dependency.test.ts tests/unit/onnxruntime-single-copy.test.ts  # 5/5 pass
- lockfile resolves exactly one onnxruntime-node @ 1.24.3
@diegosouzapw
diegosouzapw merged commit 1ee4818 into diegosouzapw:release/v3.8.51 Aug 26, 2026
8 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
….3 lockstep (diegosouzapw#11633)

Merged via /merge-batch (2026-08-26, v3.8.51). Validado com `npm install` completo: 0 vulnerabilidades, lockfile consistente após o realinhamento do pin onnxruntime-node. Obrigado pela contribuição.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants