Skip to content

chore(deps): refresh in-range dependencies to latest safe versions - #123

Merged
leoisadev1 merged 4 commits into
mainfrom
tembo/deps-in-range-safe-bumps
Jul 6, 2026
Merged

leoisadev1 merged 4 commits into
mainfrom
tembo/deps-in-range-safe-bumps

Conversation

@tembo

@tembo tembo Bot commented Jul 3, 2026 •

Copy link
Copy Markdown
Contributor

Update 2026-07-06 — merged main, fixed the CI failure

Re-verification after the merge (all green)

  • root bun install --frozen-lockfile + full bun run release:ci from a clean state (no dist/) — exit 0, exactly what CI runs.
  • packages/email-sdk: bun run build + bun test — 182 pass, 0 fail.
  • packages/convex-email: bun test — 35 pass, 0 fail.
  • apps/fumadocs: bun test (31 pass), bun run types:check, and full bun run build — all clean.
  • bunx oxlint on the touched files — no findings.

Dependency sweep — low-risk, in-range upgrades

Automated dependency sweep. This PR bumps only dependencies whose newest published version already satisfies the semver range declared in the repo, so a fresh bun install without the committed lockfile would already resolve to them. No major versions, no range widening beyond floor bumps, and no intentionally exact-pinned packages were touched. Current versions were read from package.json + bun.lock; targets from bun outdated.

Applied upgrades

Package Workspace Current Target Kind Why safe now
react fumadocs 19.2.6 19.2.7 patch, in-range ^19.2.6 React runtime patch; bumped with react-dom in lockstep.
react-dom fumadocs 19.2.6 19.2.7 patch, in-range Kept in lockstep with react.
vite fumadocs 8.0.14 8.1.3 minor, in-range ^8.0.14 Docs-app build tool only; full vite build verified below.
@vitejs/plugin-react fumadocs 6.0.2 6.0.3 patch, in-range Build-plugin patch.
tailwindcss fumadocs 4.3.0 4.3.2 patch, in-range Bumped with @tailwindcss/vite together.
@tailwindcss/vite fumadocs 4.3.0 4.3.2 patch, in-range Kept in lockstep with tailwindcss.
lucide-react fumadocs 1.16.0 1.23.0 minor, in-range ^1.16.0 Icon library, additive minors.
@usenotra/sdk fumadocs 1.2.2 1.3.1 minor, in-range ^1.2.2 Used only by the docs blog fetch script.
srvx fumadocs 0.11.16 0.11.20 patch (0.x), in-range ^0.11.16 Dev server patch.
@types/mdx fumadocs 2.0.13 2.0.14 patch types, in-range Type-only.
@types/react fumadocs 19.2.15 19.2.17 patch types, in-range Type-only.
@types/node fumadocs, email-sdk 25.9.1 25.9.4 patch types, in-range ^25.9.1 Type-only. Held below the v26 major (see deferred).
convex (dev) convex-email 1.39.1 1.42.1 minor, in-range ^1.36.1 Dev/test dependency. Peer range left at ^1.36.1 so consumers are unaffected. Component tests pass.
oxlint (dev) root 1.67.0 1.72.0 minor, in-range ^1.61.0 Lint tooling; not part of the CI release gate.
turbo (dev) root 2.9.15 2.10.2 minor, in-range ^2.8.12 Build orchestrator; used for every check below.

Root dotenv (^17.2.2→^17.4.2), zod (^4.1.13→^4.4.3) and typescript (^6→^6.0.3) show as package.json floor bumps only — the lockfile already resolved to those versions within the old ranges, so there is no actual dependency change; the floors were raised to document the tested minimums.

Deferred (higher risk — not in this PR)

Package Current Latest Why deferred
oxfmt 0.46.0 0.57.0 Out of range (^0.46.0). A formatter minor jump on 0.x can change formatting rules and churn the whole tree. Bump in isolation and run bun run check to review reformatting.
@types/node 25.9.4 26.1.0 Major bump. Needs a deliberate Node typings review; kept at 25.x here.
@tanstack/react-router 1.170.8 1.170.17 Intentionally exact-pinned in the docs app. Patch available but pin signals deliberate control — bump alongside the rest of the @tanstack/* set.
@tanstack/react-start 1.168.13 1.168.27 Exact-pinned; move with the TanStack set.
@tanstack/start-static-server-functions 1.167.9 1.167.18 Exact-pinned; move with the TanStack set.
fumadocs-core 16.9.1 16.10.7 Exact-pinned; minor. Must move with fumadocs-ui (same version) and be checked against fumadocs-mdx.
fumadocs-ui 16.9.1 16.10.7 Exact-pinned; keep in lockstep with fumadocs-core.
fumadocs-mdx 15.0.9 15.0.13 Exact-pinned; patch, but verify with the fumadocs 16.10 pair.
shiki 4.1.0 4.3.0 Exact-pinned; minor. Bump with the fumadocs stack (shared syntax-highlight surface).
nitro 3.0.260522-beta 3.0.260610-beta Pre-release (-beta) pinned exactly. Avoid moving beta build infra in an automated sweep.
convex-test 0.0.53 0.0.54 0.0.x exact pin — every patch is potentially breaking at that range. Bump together with a convex upgrade and run the component tests.

Verification

Ran the CI-equivalent release gate (bun run release:ci) plus extras, all green:

  • bun install --frozen-lockfile — passes (lockfile consistent with package.json; this is what CI runs).
  • bun run check-types — SDK + convex-email type-check clean.
  • apps/fumadocs types:check — clean.
  • bun run test — 90 + 18 tests pass, 0 fail.
  • bun run build — all packages incl. full docs vite build/prerender succeed.
  • bun run pack:check — npm pack dry-run clean for both published packages.
  • bun run community:check + bun run docs:versions:check — pass.

Notes / follow-up

  • No changeset included. Per AGENTS.md, changesets are for user-visible SDK/CLI changes. The published @opencoredev/email-sdk surface is unchanged, and @opencoredev/convex-email's convex peer range is untouched (^1.36.1) — only its dev/test dep moved. If maintainers prefer a chore-level changeset for release notes, add a patch one.
  • Local bun is 1.3.13; repo/CI pin bun@1.3.14. Same 1.3.x lockfile format, and --frozen-lockfile passes, so no compatibility concern is expected.
  • Suggested next sweep: bump the @tanstack/* trio together, and the fumadocs-core/fumadocs-ui/fumadocs-mdx/shiki stack together, each in its own PR with a docs build check.

Want tembo to make any changes? Add a comment with @tembo and i'll get back to work!

View on Tembo View Agent Settings View on automation

@tembo tembo Bot added the tembo Pull request created by Tembo label Jul 3, 2026
@vercel

vercel Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
email-sdk-fumadocs Ready Ready Preview, Comment Jul 6, 2026 6:49pm

Request Review

@tembo

tembo Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor Author

Requesting review from @leoisadev1 who has experience with the following files modified in this PR:

  • bun.lock
  • package.json
  • apps/fumadocs/package.json
  • packages/email-sdk/package.json
  • packages/convex-email/package.json

Resolved apps/fumadocs/package.json (keep dep bumps + posthog-js from main)
and regenerated bun.lock from main's lockfile via bun install.

Generated-By: PostHog Code
Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e
@usenotra/sdk 1.3.1 changed ListPostsPost.markdown from string to
string | null: image-type posts have no Markdown body (their content is
a CDN image URL). Model that in NotraPostInput and skip such posts in
mapNotraPost — the blog can only render Markdown bodies. Adds a test.

Generated-By: PostHog Code
Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e
@leoisadev1
leoisadev1 marked this pull request as ready for review July 6, 2026 18:40
@greptile-apps

greptile-apps Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

Greptile Summary

This PR refreshes in-range dependencies and updates the docs blog mapper for newer Notra post data. The main changes are:

  • Updated dependency ranges and lockfile entries across the root, docs app, SDK, and Convex package.
  • Changed mapNotraPost to accept markdown: string | null and skip image-type posts without Markdown bodies.
  • Added a unit test for skipping Notra posts with markdown: null.
  • Added @opencoredev/email-sdk as a Convex package dev dependency to preserve Turbo build/test ordering.

Confidence Score: 5/5

No blocking issues were identified in the dependency refresh or Notra blog mapper update.

The changes are scoped to in-range dependency updates and a targeted null-handling adjustment covered by a unit test, with no review comments remaining.

T-Rex T-Rex Logs

What T-Rex did

  • Compared the pre-change mapping of a null-markdown image post with the post-change head result for the same payload, confirming the transition from an empty html to null.
  • Validated the dependency sweep by running before/after transcripts, confirming successful frozen installs and tests in the after state and noting the helper scripts used to generate the transcripts.
  • Validated the turbo-convex-edge dependency changes, noting the before state with no devDependency and the after state including a build dependency.

View all artifacts

T-Rex Ran code and verified through T-Rex

Reviews (2): Last reviewed commit: "fix(ci): restore convex-email test -> em..." | Re-trigger Greptile

…o 2.10

Turbo >=2.9.17 ignores peerDependencies when building the package graph
(vercel/turborepo#13025), so convex-email's @opencoredev/email-sdk peer
range stopped scheduling email-sdk#build before the convex-email tests
and CI failed with 'Cannot find module @opencoredev/email-sdk'. Make
the workspace edge explicit with a workspace:* devDependency (dev-only,
published package unchanged) and document the invariant in AGENTS.md.

Generated-By: PostHog Code
Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e
@tembo

tembo Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor Author

Greptile Summary

This PR refreshes dependency versions and updates the docs blog import path for nullable Notra Markdown. The main changes are:

  • In-range dependency bumps across the root workspace, docs app, SDK package, and Convex package.
  • NotraPostInput.markdown now accepts string | null.
  • Notra image-type posts with markdown: null are skipped before Markdown rendering.
  • Unit coverage was added for skipping posts without a Markdown body.

Confidence Score: 5/5

The dependency refresh and nullable Markdown handling appear merge-safe based on the described checks and the absence of code issues.

The changed surfaces are narrow, covered by targeted tests for the Notra null-Markdown case, and the dependency bumps were validated with install, type-check, test, build, pack, and docs checks.

T-Rex T-Rex Logs

What T-Rex did

  • Compared the pre-change and post-change logs for the notra-null-markdown-skip path to validate the contract behavior update.
  • Examined the docs workflow logs to confirm the after-state shows all head commands exited 0, including docs types:check and the 300s-bounded build path, with dependencies resolved for refreshed docs/Vite assets.

View all artifacts

T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "fix(docs): handle nullable markdown from..." | Re-trigger Greptile

i reviewed pr #123 and independently re-ran the full verification. the greptile 5/5 "merge-safe" call holds up — no code changes were needed. the working tree is clean; i didn't invent a diff where the pr is already correct.

what i verified locally

  • bun install — resolves cleanly, bun.lock unchanged (in-range bumps only)
  • type-check — email-sdk, convex-email, and fumadocs (types:check) all pass
  • tests — 182 (email-sdk) + 35 (convex-email) + 31 (fumadocs) = all green
  • build — email-sdk dist + fumadocs vite build & prerender both succeed

note: running bun run test from a cold tree first shows convex-email failing with cannot find module @opencoredev/email-sdk. that's a build-order artifact — email-sdk is a peer dependency so turbo's ^build doesn't build it first. after building email-sdk once, convex-email passes 35/35. not a regression from the bumps.

dependency updates (current in repo → target), all within existing major ranges

root:

  • dotenv ^17.2.2 → ^17.4.2 (patch) — safe
  • zod ^4.1.13 → ^4.4.3 (minor) — safe
  • oxlint ^1.61.0 → ^1.72.0 (dev, minor) — safe
  • turbo ^2.8.12 → ^2.10.2 (dev, minor) — safe
  • typescript ^6 → ^6.0.3 (dev, floor pin) — safe

apps/fumadocs:

  • @usenotra/sdk ^1.2.2 → ^1.3.1 — the one behavioral change (see below)
  • lucide-react ^1.16.0 → ^1.23.0, react/react-dom ^19.2.6 → ^19.2.7, vite ^8.0.14 → ^8.1.3 — safe
  • dev/types: @tailwindcss/vite, tailwindcss ^4.3.0 → ^4.3.2, @types/mdx ^2.0.13 → ^2.0.14, @types/node ^25.9.1 → ^25.9.4, @types/react ^19.2.15 → ^19.2.17, @vitejs/plugin-react ^6.0.2 → ^6.0.3, srvx ^0.11.16 → ^0.11.20 — safe

packages/convex-email:

  • convex ^1.36.1 → ^1.42.1 (dev, minor) — safe; the peer range stays ^1.36.1, which still admits 1.42.x, so consumers aren't tightened

packages/email-sdk:

  • @types/node ^25.9.1 → ^25.9.4 (dev, patch) — safe

the one required migration (already done in the pr)
@usenotra/sdk 1.3.x made listPosts().posts[].markdown nullable — i confirmed against the installed 1.3.1 types (markdown: string | null). image-type posts return markdown: null with a cdn url in content. the pr handles this correctly:

  • NotraPostInput.markdown widened to string | null
  • mapNotraPost returns null (skips) when markdown === null, which also narrows it back to string for the downstream excerptFromMarkdown / estimateReadTime / renderMarkdownToSafeHtml calls
  • covered by a new unit test for the image-post skip case

risk / follow-up

  • no major-version bumps, no api breaks beyond the handled nullable-markdown case — merge-safe.
  • residual watch item: renderMarkdownToSafeHtml(markdown: string) still assumes non-null. it's safe today because mapNotraPost is the only caller and guards first, but if a future caller passes a raw sdk post it could hit null again. optional hardening, not needed for this pr.

bottom line: the pr is ready to merge as-is. nothing to change.

#123

@leoisadev1
leoisadev1 merged commit a30e924 into main Jul 6, 2026
4 checks passed
@leoisadev1
leoisadev1 deleted the tembo/deps-in-range-safe-bumps branch July 6, 2026 19:10
leoisadev1 added a commit that referenced this pull request Jul 7, 2026
…he build (#152)

PR #123's in-range deps refresh bumped the app's lucide-react to ^1.23.0
while the lockfile kept fumadocs-ui's edge on 1.16.0. lucide-react is a
peer dependency of fumadocs-core, so bun's isolated linker materialized
fumadocs-core@16.9.1 once per peer set: two module instances, two React
contexts. RootProvider provided on one instance while components consumed
the other, and every page crashed at hydration with "You need to wrap
your application inside `FrameworkProvider`". The build stayed green, so
the crash shipped and took production down; the vite 8.0.14 -> 8.1.3 bump
in the same refresh was a red herring (verified innocent once lucide was
unified).

- Revert lucide-react to ^1.16.0 so app and fumadocs-ui share one install.
- scripts/check-module-identity.ts (pre-build): fail if fumadocs-core,
  react, react-dom, @tanstack/react-router, or lucide-react resolve to
  different physical installs from the app vs fumadocs-ui. This would
  have failed PR #123 in CI (release:ci runs the docs build with the
  frozen lockfile).
- scripts/check-client-bundle.ts (post-build backstop): fail if the
  framework-context module lands in more than one client chunk.
- AGENTS.md: document the invariant for future deps refreshes.

Production was restored by promoting the last good deployment
(email-sdk-fumadocs-3wsvdubrx, commit 599b614); this makes main safe to
deploy again.

Generated-By: PostHog Code
Task-Id: e66c853d-287b-4334-8055-51c53c0cd66b

This branch was successfully deployed

1 active deployment
Preview — b83e1b8a Deployed Jul 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tembo Pull request created by Tembo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant