deps: realign onnxruntime-node pin to @huggingface/transformers' 1.24.3 lockstep - #11633
Merged
diegosouzapw merged 1 commit intoAug 26, 2026
Conversation
….3 lockstep diegosouzapw#11440's production-group bump moved the root optionalDependencies + overrides pin 1.24.3 -> 1.27.0 while @huggingface/transformers@4.2.0 still hard-pins onnxruntime-node 1.24.3 in its own dependencies (no 4.x release pins anything newer). The overrides entry masked the nesting by forcing a single hoisted copy at 1.27.0, but broke the lockstep contract pinned by tests/unit/onnxruntime-single-copy.test.ts and tests/unit/build/optional-transformers-dependency.test.ts — the same class of SONAME clash that broke the Docker standalone build on 2026-08-16 when root drifts off upstream's pin. Reverts both pins to 1.24.3 and regenerates the lockfile: one copy of onnxruntime-node at exactly the version transformers.js declares, plus its matching transitive closure (global-agent@^3 tree). Verified: - node --import tsx/esm --test tests/unit/build/optional-transformers-dependency.test.ts tests/unit/onnxruntime-single-copy.test.ts # 5/5 pass - lockfile resolves exactly one onnxruntime-node @ 1.24.3
diegosouzapw
merged commit Aug 26, 2026
1ee4818
into
diegosouzapw:release/v3.8.51
8 of 16 checks passed
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
….3 lockstep (diegosouzapw#11633) Merged via /merge-batch (2026-08-26, v3.8.51). Validado com `npm install` completo: 0 vulnerabilidades, lockfile consistente após o realinhamento do pin onnxruntime-node. Obrigado pela contribuição.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the last remaining red from run 32933234257 on
release/v3.8.51(base-red #11449). The other five failing areas in that run were already fixed on base by #11582, #11585, #11588 and #11593; the ONNX drift was not.Root cause
#11440's production-group dependabot bump moved the root
optionalDependencies+overridespin foronnxruntime-node1.24.3 → 1.27.0, but@huggingface/transformers@4.2.0hard-pinsonnxruntime-node: "1.24.3"in its owndependencies.Upstream evidence (researched 2026-08-26)
latest= 4.2.0 (published 2026-04-22);next= stale4.0.0-next.11. No release since April.onnxruntime-node1.24.3 exactly (verified vianpm viewacross all 4.x versions: 4.0.0, 4.0.1, 4.1.0, 4.2.0 → all1.24.3). There is no released version to lockstep against at 1.27.x today.1.27.0; motivation: 1.24.3 pullsglobal-agent@^3→ deprecatedboolean@3.2.0, while 1.27 moves toglobal-agent@^4)^1.27.0+ sharp^0.35)Corroborating detail: the transitive closure my regenerated lockfile restores (
global-agent@^3→roarr,matcher@3,semver-compare,sprintf-js,detect-node,es6-error,json-stringify-safe,boolean) is precisely the subtree upstream PR #1730 describes removing when it moves to 1.27 — independent confirmation that this tree belongs to the 1.24.3 pin.When upstream merges #1730/#1731 and tags a release pinning 1.27.x, both packages must bump together in one commit — that is the whole point of the lockstep rule pinned by the guard tests below.
Why exact equality matters
onnxruntime-node ships a native library (
libonnxruntime.so.1/.dll). If root says 1.27.0 while transformers pins 1.24.3, npm nests a second copy; two native libs under one SONAME cannot coexist in a process — the loader binds whichever dlopen()s first and the other addon dies withversion 'VERS_1.27.0' not found. Dependabot made this same bump on 2026-08-16 and broke the Docker standalone build (documented in the header oftests/unit/onnxruntime-single-copy.test.ts).The
overridesentry masked the nesting by forcing a single hoisted copy at 1.27.0, so the single-copy guard kept passing, but it violated the lockstep contract pinned by:tests/unit/onnxruntime-single-copy.test.ts("root onnxruntime-node matches the exact version @huggingface/transformers pins")tests/unit/build/optional-transformers-dependency.test.ts(optionalDependency pin == overrides pin == upstream's pin)Fix
Reverts both root pins to
1.24.3and regeneratespackage-lock.json. Lockfile resolves exactly oneonnxruntime-nodecopy at exactly the version transformers.js declares, plus its matching transitive closure.Diff footprint: package.json (2 lines) + package-lock.json (onnxruntime-node subtree only — every changed lock entry verified to belong to the onnxruntime closure).
Verification
Note:
npm run check:lockfilecurrently fails identically on pristineorigin/release/v3.8.51(pre-existingclaude-agent-sdkURL-validation entries) — unrelated to and unchanged by this PR.This diff touches only
package.json(2 lines) +package-lock.json. Every failing job fails identically on pristineorigin/release/v3.8.51and is inherited, not introduced here:provider-translate-path-golden.test.ts"GOLDEN provider.ts translate-path is stable across all providers" reproduces on unfixed tip locally; likewise the live-ws/embedWsProxy port-binding tests,APIKEY_PROVIDERS merges ... 233 entries, and the credential-inventory classification checks. None read these manifests.tests/unit/autoCombo/models-dev-tier-11508.test.ts: "No test suite found" on both branches (fixed separately by test(autoCombo): port models_dev_tier #11508 guard from node:test to vitest #11635).AGENTS.md,llm.txt,package.jsondescription and hero/diagram SVGs still say "353"). Needs its own docs-sync fix PR.config/quality/eslint-suppressions.jsonstale entries); pre-existing on tip, owned by fix(sse): explicit types for openai-responses pureHelpers — clears last failing core typecheck gate #11567.