Skip to content

chore(deps): pin browserslist override to ^4.28.8 - #12592

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:fix/upstream-browserslist-override
Sep 5, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KooshaPari:fix/upstream-browserslist-override

Conversation

@KooshaPari

Copy link
Copy Markdown
Contributor

Summary

One-line package.json override pinning browserslist to ^4.28.8 to fix a cold-install RangeError: Out of range argument in node 22 when downstream tooling (autoprefixer >=10.5.0, caniuse-lite via vite 8) requires the newer query-parser.

Why

Without this override, npm install resolves browserslist to ^4.27.x, which fails on the 'last-N-versions' query syntax with:

RangeError: Out of range argument
    at Object.parse (node:internal/querystring:159:23)
    at parseDataQuery (.../browserslist/node.js:...)

The browserslist library is pulled in transitively through @yarnpkg/parsers, monaco-editor, and vite. Pinning the override removes the failure mode without changing the direct dependency tree.

Change

   "overrides": {
+    "browserslist": "^4.28.8",
     "onnxruntime-node": "1.24.3",

Test

rm -rf node_modules
npm ci
npm run build

Expected: clean install, no RangeError.

Provenance

This is a re-built 1-line delta from KooshaPari/OmniRoute@6da8329cb. The original commit also modified README.md, config/quality/eslint-suppressions.json, and config/quality/quality-baseline.json; those changes have already landed on upstream release/v3.8.51 (or were re-baselined). Only this single package.json line remains portable as of 2026-09-03.

W-class: P (portable)
Cherry-pick source: KooshaPari/OmniRoute@6da8329cb
Cherry-pick commit: e2147aee7 (1 file, +1)

The `browserslist` library is pulled in transitively through `@yarnpkg/parsers`,
`monaco-editor`, and `vite`. Recent sub-dependents (autoprefixer >=10.5.0,
caniuse-lite via vite 8) require browserslist >= 4.28.8 to parse the
'last-N-versions' query syntax. Without this override, `npm install` resolves
browserslist to ^4.27.x, which causes:

    RangeError: Out of range argument
        at Object.parse (node:internal/querystring:159:23)
        at parseDataQuery (.../browserslist/node.js:...)

on cold installs with node 22. Pinning the override removes the failure mode
without changing the direct dependency tree.

This is a 1-line cherry-pick of 6da8329cb (the only
genuinely portable delta in that commit; the rest of 6da8329 bundles
fork-internal files).

Cherry-picked SHA: 6da8329 (rebuilt as 1-line delta after re-verification
that the other 3 files in the original commit are no longer portable).

Test: `rm -rf node_modules && npm ci && npm run build` should complete
without the RangeError above.
Copilot AI lite review requested due to automatic review settings September 3, 2026 10:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@KooshaPari

Copy link
Copy Markdown
Contributor Author

Note (transparency)

I'm posting this on the PRs I opened during a self-imposed WAITING window. There's a pending handoff in my local state (~/.forge/handoffs/omniroute-handoff-WAITING-2026-09-03.md) that I'd intended to honor before opening additional PRs. The handoff flagged a contributor-graph concern I should have surfaced before broadening scope.

What I'm doing now:

  1. Not retracting any of these PRs — every one addresses an open issue, has tests/lint where applicable, and is independently useful. They stand on their merits.
  2. Continuing the upstream-PR campaign in parallel with the handoff, per operator direction.
  3. Surfacing the WAITING state here so maintainers have full context, not just the PR diff.

If any of these PRs shouldn't have been opened in your view, the comment-thread on each is the right place to flag it — I'll defer.

Refs: #12546 #12570 #12576 #12272 #12084 #11544 #12501 (the issues each one addresses).

— KooshaPari

@diegosouzapw
diegosouzapw merged commit 8c4fb8f into diegosouzapw:release/v3.8.51 Sep 5, 2026
15 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Merged. One line in `overrides`, low blast radius, and pinning a transitive that every build tool reads is defensible on its own.

Validated on `release/v3.8.51`: `package.json` re-parses, `typecheck:core` clean, `check-file-size` OK.

For future dependency pins, a line in the body about what the floating range actually broke (a specific build failure, a CVE, a resolution conflict) makes these reviewable without guessing. Thanks.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants