chore(deps): refresh in-range dependencies to latest safe versions - #123
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Requesting review from @leoisadev1 who has experience with the following files modified in this PR:
|
Resolved apps/fumadocs/package.json (keep dep bumps + posthog-js from main) and regenerated bun.lock from main's lockfile via bun install. Generated-By: PostHog Code Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e
@usenotra/sdk 1.3.1 changed ListPostsPost.markdown from string to string | null: image-type posts have no Markdown body (their content is a CDN image URL). Model that in NotraPostInput and skip such posts in mapNotraPost — the blog can only render Markdown bodies. Adds a test. Generated-By: PostHog Code Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e
Greptile SummaryThis PR refreshes in-range dependencies and updates the docs blog mapper for newer Notra post data. The main changes are:
Confidence Score: 5/5No blocking issues were identified in the dependency refresh or Notra blog mapper update. The changes are scoped to in-range dependency updates and a targeted null-handling adjustment covered by a unit test, with no review comments remaining.
What T-Rex did
Reviews (2): Last reviewed commit: "fix(ci): restore convex-email test -> em..." | Re-trigger Greptile |
…o 2.10 Turbo >=2.9.17 ignores peerDependencies when building the package graph (vercel/turborepo#13025), so convex-email's @opencoredev/email-sdk peer range stopped scheduling email-sdk#build before the convex-email tests and CI failed with 'Cannot find module @opencoredev/email-sdk'. Make the workspace edge explicit with a workspace:* devDependency (dev-only, published package unchanged) and document the invariant in AGENTS.md. Generated-By: PostHog Code Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e
i reviewed pr #123 and independently re-ran the full verification. the greptile 5/5 "merge-safe" call holds up — no code changes were needed. the working tree is clean; i didn't invent a diff where the pr is already correct. what i verified locally
note: running dependency updates (current in repo → target), all within existing major ranges root:
apps/fumadocs:
packages/convex-email:
packages/email-sdk:
the one required migration (already done in the pr)
risk / follow-up
bottom line: the pr is ready to merge as-is. nothing to change. |
…he build (#152) PR #123's in-range deps refresh bumped the app's lucide-react to ^1.23.0 while the lockfile kept fumadocs-ui's edge on 1.16.0. lucide-react is a peer dependency of fumadocs-core, so bun's isolated linker materialized fumadocs-core@16.9.1 once per peer set: two module instances, two React contexts. RootProvider provided on one instance while components consumed the other, and every page crashed at hydration with "You need to wrap your application inside `FrameworkProvider`". The build stayed green, so the crash shipped and took production down; the vite 8.0.14 -> 8.1.3 bump in the same refresh was a red herring (verified innocent once lucide was unified). - Revert lucide-react to ^1.16.0 so app and fumadocs-ui share one install. - scripts/check-module-identity.ts (pre-build): fail if fumadocs-core, react, react-dom, @tanstack/react-router, or lucide-react resolve to different physical installs from the app vs fumadocs-ui. This would have failed PR #123 in CI (release:ci runs the docs build with the frozen lockfile). - scripts/check-client-bundle.ts (post-build backstop): fail if the framework-context module lands in more than one client chunk. - AGENTS.md: document the invariant for future deps refreshes. Production was restored by promoting the last good deployment (email-sdk-fumadocs-3wsvdubrx, commit 599b614); this makes main safe to deploy again. Generated-By: PostHog Code Task-Id: e66c853d-287b-4334-8055-51c53c0cd66b
Update 2026-07-06 — merged main, fixed the CI failure
origin/main(batch sends feat(email-sdk): batch sends with per-recipient variable substitution #125, scheduled sends feat(email-sdk): scheduled sends via sendAt #127, convex-email feat(convex-email): finish the Convex component #126, PostHog telemetry feat: PostHog telemetry, error tracking, docs analytics, and release annotations #141 — which addedposthog-jstoapps/fumadocs— and docs docs(agents): document docs-site blog SSR workflow and lint command #120/docs(fumadocs): document on-demand SSR blog architecture #121/docs(agents): document lint/format and adapter account checks #122). Resolvedapps/fumadocs/package.json(kept the bumps, keptposthog-js) and regeneratedbun.lockfrom main's lockfile viabun install.@usenotra/sdk1.2.2 → 1.3.1 changedListPostsPost.markdownfromstringtostring | null— it isnullfor image-type posts, whosecontentis a CDN image URL instead of a Markdown body. The docs blog pipeline assumed a non-null string.NotraPostInput.markdownis nowstring | null, andmapNotraPostdeliberately skips posts with anullmarkdown body (image posts) — the blog can only render Markdown, so a post without a body isn't renderable there. Covered by a new unit test.peerDependencieswhen building the package graph (vercel/turborepo#13025).convex-emailonly referenced@opencoredev/email-sdkvia its peer range, soturbo teststopped schedulingemail-sdk#buildfirst and the convex-email tests failed on CI withCannot find module '@opencoredev/email-sdk'. Fixed by adding"@opencoredev/email-sdk": "workspace:*"to convex-email's devDependencies (dev-only — the published package and its peer ranges are unchanged) and documenting the invariant inAGENTS.md. The turbo bump itself stays.types:checkclean and a fullvite build+ prerender (~930 routes) succeeds against the pinned-beta nitro / exact-pinned@tanstack/react-start; output contains the expectedindex.htmlshells. No pin-back needed.Re-verification after the merge (all green)
bun install --frozen-lockfile+ fullbun run release:cifrom a clean state (no dist/) — exit 0, exactly what CI runs.packages/email-sdk:bun run build+bun test— 182 pass, 0 fail.packages/convex-email:bun test— 35 pass, 0 fail.apps/fumadocs:bun test(31 pass),bun run types:check, and fullbun run build— all clean.bunx oxlinton the touched files — no findings.Dependency sweep — low-risk, in-range upgrades
Automated dependency sweep. This PR bumps only dependencies whose newest published version already satisfies the semver range declared in the repo, so a fresh
bun installwithout the committed lockfile would already resolve to them. No major versions, no range widening beyond floor bumps, and no intentionally exact-pinned packages were touched. Current versions were read frompackage.json+bun.lock; targets frombun outdated.Applied upgrades
react^19.2.6react-domin lockstep.react-domreact.vite^8.0.14vite buildverified below.@vitejs/plugin-reacttailwindcss@tailwindcss/vitetogether.@tailwindcss/vitetailwindcss.lucide-react^1.16.0@usenotra/sdk^1.2.2srvx^0.11.16@types/mdx@types/react@types/node^25.9.1convex(dev)^1.36.1^1.36.1so consumers are unaffected. Component tests pass.oxlint(dev)^1.61.0turbo(dev)^2.8.12Root
dotenv(^17.2.2→^17.4.2),zod(^4.1.13→^4.4.3) andtypescript(^6→^6.0.3) show aspackage.jsonfloor bumps only — the lockfile already resolved to those versions within the old ranges, so there is no actual dependency change; the floors were raised to document the tested minimums.Deferred (higher risk — not in this PR)
oxfmt^0.46.0). A formatter minor jump on 0.x can change formatting rules and churn the whole tree. Bump in isolation and runbun run checkto review reformatting.@types/node@tanstack/react-router@tanstack/*set.@tanstack/react-start@tanstack/start-static-server-functionsfumadocs-corefumadocs-ui(same version) and be checked againstfumadocs-mdx.fumadocs-uifumadocs-core.fumadocs-mdxshikinitro-beta) pinned exactly. Avoid moving beta build infra in an automated sweep.convex-test0.0.xexact pin — every patch is potentially breaking at that range. Bump together with aconvexupgrade and run the component tests.Verification
Ran the CI-equivalent release gate (
bun run release:ci) plus extras, all green:bun install --frozen-lockfile— passes (lockfile consistent withpackage.json; this is what CI runs).bun run check-types— SDK + convex-email type-check clean.apps/fumadocstypes:check— clean.bun run test— 90 + 18 tests pass, 0 fail.bun run build— all packages incl. full docsvite build/prerender succeed.bun run pack:check— npm pack dry-run clean for both published packages.bun run community:check+bun run docs:versions:check— pass.Notes / follow-up
AGENTS.md, changesets are for user-visible SDK/CLI changes. The published@opencoredev/email-sdksurface is unchanged, and@opencoredev/convex-email'sconvexpeer range is untouched (^1.36.1) — only its dev/test dep moved. If maintainers prefer achore-level changeset for release notes, add apatchone.bunis 1.3.13; repo/CI pinbun@1.3.14. Same 1.3.x lockfile format, and--frozen-lockfilepasses, so no compatibility concern is expected.@tanstack/*trio together, and thefumadocs-core/fumadocs-ui/fumadocs-mdx/shikistack together, each in its own PR with a docs build check.