Skip to content

Update all dependencies and enforce freshness in CI - #214

Merged
konard merged 9 commits into
mainfrom
issue-204-85de3419e887
Oct 7, 2026
Merged

konard merged 9 commits into
mainfrom
issue-204-85de3419e887

Conversation

@konard

@konard konard commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

The manifests allowed older releases of nix, vt100, which, and many other dependencies, so consumers resolved outdated direct crates alongside current ones. Update every maintained Rust and JavaScript runtime, development, benchmark, and release-script dependency to its latest stable release, refresh both Cargo lockfiles and both JavaScript lockfiles, and update GitHub Actions and pinned CI package tools.

Addresses #204 and the maintainer's request to update all dependencies.

API changes and compatibility

  • nix 0.29 → 0.31.3 and which 7 → 8.0.6: existing process, signal, and executable lookup calls compile unchanged; integration tests pass.
  • vt100 0.15 → 0.16.2: replace the removed Parser::set_size with Parser::screen_mut().set_size. All 12 terminal regression tests pass.
  • ureq 2 → 3.4.2 in release scripts: migrate .set to .header, HTTP status errors to Error::StatusCode, and .into_string to mutable body readers. Preserve the existing release checks and error handling. toml 0.8 → 1.1.6 keeps the manifest version guard passing.
  • Execa 9 → 10.1.0 requires Node.js 22; the CI matrix now covers Node 22, 24, and 26. Retain the public execaCommand and execaCommandSync helpers through wrappers around the upstream parser and execution methods, with ESM/CommonJS exports, option presets, factories, and TypeScript contracts tested. Document Execa 10's .nodeChildProcess, explicit IPC option, and stdin precedence changes in the migration guide.
  • ESLint 10 requires preserving caught errors as cause and removing an unused initial assignment. Add Chalk explicitly for the existing zx fixtures, which previously relied on a transitive install. Use node-pty's latest stable release instead of its prerelease. Its 1.1.0 tarball ships both macOS spawn-helper binaries with mode 0644, whereas the previous beta shipped 0755; this caused posix_spawnp failed in 13 macOS PTY tests. Repair missing owner execute permission for the helper selected by the loaded native binding before PTY startup, preserving existing executable modes. A regression test reproduces EACCES with a mode-0644 helper and verifies successful execution after repair.
  • npm publishing now selects npm 12 and verifies its Node runtime ranges; regression tests cover major selection and engine boundaries.

Freshness policy and reproduction

bun scripts/check-dependencies.mjs compares all 89 maintained package/tool declarations against registry latest stable releases, including embedded Rust-script manifests. Outdated Rust declarations need a same-line GitHub issue blocker; the issue must be open and must be an issue rather than a pull request. Closed blockers, malformed metadata, and lookup failures fail the check. No blockers are needed for the current declarations.

The new workflow runs on every PR, main push, manual dispatch, and weekly. It also runs npm outdated and checks both cargo update --dry-run outputs for pending version updates. Offline policy tests reproduce stale declarations across semver ranges and verify blocker and registry failure handling. Regression tests execute the actual lockfile workflow without ripgrep and with Cargo colors enabled; the gate forces plain output and rejects package upgrades, additions, removals, and downgrades in either manifest.

Before updating dependencies, the registry probe reported 61 stale declarations. Afterward it reports zero. python3 experiments/issue-204/check-consumer.py --rust-root /path/to/old/checkout/rust reproduces the old nix mismatch; running without that argument verifies that the consumer and command-stream share the exact current nix, vt100, and which crate IDs.

Cancellation regression found in CI

Windows run 37546397534 exceeded the 30-minute job limit: log line 1208 reported child_handle_can_stop_the_process running for over 60 seconds. Opt-in traces in the next run showed taskkill completing at 00:08:05 UTC (lines 1188–1191), followed by output collection waiting until 00:08:10 UTC (lines 1193–1198). Cancelled ProcessRunner::run awaited pipe EOF without a deadline, even after the direct child had exited.

The finite experiments/issue-204/pipe-holder.rs fixture reproduces that wait with a descendant retaining stdout and stderr outside the cancelled process group. cargo test --manifest-path rust/Cargo.toml --all-features --test cancelled_output fails its 500-millisecond deadline before the fix. Continue draining during graceful shutdown, then bound remaining collection to the existing 100-millisecond streaming grace after child exit while preserving buffered bytes. Both the inherited-pipe regression and a finite 256-KiB signal-handler output regression pass. Windows native-child tests now run eight bounded attempts for each cancellation path, alternating tracing off and on, with a two-second collection deadline and ten-second outer subprocess deadline.

Validation and release preparation

All nine workflows passed on final commit ce6a2f8bd774b3b1ed9f715c19f92130ad37a71a (committed 2026-10-07 00:18:57 UTC; runs started 00:19:15 UTC): 51 checks succeeded and six release jobs were skipped as expected for a pull request. Rust, JavaScript, dependency freshness, and security are green. The Windows log at lines 1220–1222 confirms that cancelled output collection now returns after its bounded grace; all 16 native-child subprocess probes passed.

  • Full Bun suite after all changes: 2,564 passed, 10 skipped, zero failures across 152 test files. The added Execa benchmark integration case and all 217 freshness/workflow regression tests also pass.
  • Node 22 and Node 24 integration/compatibility suites: 624 passed and two skipped on each runtime.
  • Rust all-feature suite, including doctests: 828 passed; benchmark tests and all six release-script unit suites pass. Non-test builds of the three ureq-migrated scripts also compile.
  • JavaScript lint, repository formatting, duplication threshold, TypeScript declarations, Rust formatting, Clippy with warnings denied, rustdoc with warnings denied, package/file size guards, version/changeset/changelog guards, all 29 executable feature parity checks, generated documentation check, Actionlint, and Zizmor pass locally.
  • Both JavaScript lockfile audits pass using the repository's existing documented advisory exception. npm outdated, cargo outdated --root-deps-only --exit-code 1 in both Cargo packages, and both Cargo dry runs show no pending updates.

Add a JavaScript major changeset for the new Node baseline and a Rust patch changelog fragment. The existing main-branch release workflows will assign versions and publish npm/crates.io packages after merge; this PR does not claim that publication has already occurred.

Remaining upstream limitation: portable-pty 0.9.0 is the latest stable release and still depends on nix 0.28.0. The fresh consumer therefore retains that transitive nix copy alongside the shared nix 0.31.3, although vt100 and which no longer duplicate. Eliminating it requires an upstream portable-pty update or a separate PTY backend replacement. The committed consumer probe reports this explicitly; it does not claim a duplicate-free graph.

Fixes #204

Changes

  • 75 file(s) modified
  • 2742 line(s) added
  • 3436 line(s) removed
  • Files:
    • .github/workflows/benchmarks.yml
    • .github/workflows/bun-shell.yml
    • .github/workflows/dependencies.yml
    • .github/workflows/docs.yml
    • .github/workflows/js.yml
    • .github/workflows/links.yml
    • .github/workflows/parity.yml
    • .github/workflows/quality.yml
    • .github/workflows/rust.yml
    • .github/workflows/security.yml
    • .github/workflows/workflows.yml
    • README.md
    • claude-profiles.mjs
    • docs/README.md
    • docs/features/execa-compat.md
    • docs/site/index.html
    • experiments/issue-204/README.md
    • experiments/issue-204/check-consumer.py
    • experiments/issue-204/pipe-holder.rs
    • js/.changeset/issue-204-dependencies.md
    • js/README.md
    • js/bun.lock
    • js/docs/BUNDLE_SIZE_COMPARISON.md
    • js/docs/EXECA_MIGRATION.md
    • js/examples/features/catalog.mjs
    • js/package-lock.json
    • js/package.json
    • js/scripts/setup-npm.mjs
    • js/src/bun-shell/expansion.mjs
    • js/src/bun-shell/template.mjs
    • js/src/execa/index.cjs
    • js/src/execa/index.mjs
    • js/src/terminal-pty-host-platform.mjs
    • js/src/terminal-pty-host.mjs
    • js/tests/benchmark-suite.test.mjs
    • js/tests/dependency-freshness.test.mjs
    • js/tests/execa/api.test.mjs
    • js/tests/setup-npm.test.mjs
    • js/tests/terminal-pty-helper.test.mjs
    • js/tests/test-cleanup.mjs
    • js/tests/test-helper.mjs
    • js/tests/types/execa-cjs.types.cts
    • js/tests/types/execa.types.ts
    • js/types/api.d.cts
    • js/types/execa-api.d.cts
    • js/types/execa.d.cts
    • js/types/execa.d.ts
    • rust/Cargo.lock
    • rust/Cargo.toml
    • rust/benchmarks/Cargo.lock
    • …and 25 more

Adding .gitkeep for PR creation (default mode).
This file will be removed when the task is complete.

Issue: #204
@konard konard self-assigned this Oct 6, 2026
@konard konard changed the title [WIP] Update dependencies to their latest releases (nix 0.29->0.31, vt100 0.15->0.16, which 7->8) and enforce freshness in CI Update all dependencies and enforce freshness in CI Oct 6, 2026
Comment thread js/tests/dependency-freshness.test.mjs Fixed
Comment thread js/tests/dependency-freshness.test.mjs Fixed
@konard
konard marked this pull request as ready for review October 7, 2026 00:26
@konard

konard commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

Working session summary

PR #214 is updated and ready for review. Dependencies and lockfiles are current, freshness CI is added, and CI regressions are fixed.

Validation: 2,564 JavaScript tests, 828 Rust tests, and 51 CI checks pass. Working tree is clean.

JavaScript now requires Node 22. The remaining portable-pty → nix duplicate is documented. Releases are prepared for publication after merge.


This summary was automatically extracted from the AI working session output.

@konard

konard commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

🤖 Solution Draft Log

This log file contains the complete execution trace of the AI solution draft process.

💰 Cost estimation:

  • Model: GPT-6.1 Sol
  • Provider: OpenAI
  • Public pricing estimate: $9.240264

📊 Context and tokens usage:

  • 674.2K input tokens across requests (cumulative, larger than the 200K context window, so not one request's context), 153.3K / 128K (120%) output tokens

Total: (674.2K + 21.2M cached) input tokens, 153.3K output tokens, $9.240264 cost

🤖 Models used:

  • Tool: OpenAI Codex
  • Requested: gpt-6.1-sol
  • Thinking level: xhigh (~31999 tokens)
  • Model: GPT-6.1 Sol (gpt-6.1-sol)

📎 Log file uploaded as Gist (12559KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard
konard merged commit a171ef3 into main Oct 7, 2026
57 checks passed
@konard

konard commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

🎉 Auto-merged

This pull request has been automatically merged by hive-mind.

  • All CI checks have passed

Auto-merged by hive-mind with --auto-merge flag

@konard

konard commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

📎 Intermediate working-session log (killed session)

This log file contains the complete execution trace of the AI solution draft process.

📎 Log file uploaded as Gist (11433KB)


Now working session is ended, feel free to review and add any feedback on the solution draft.

@konard

konard commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

⚠️ Working session recovered from out of memory

container OOM event — a process in the task cgroup was killed earlier; the session-end memory reading was 9.3 GB of 11.7 GB RAM available (20.1% used) at 2026-10-07T00:30:00.914Z

  • Exit code: 0
  • Detected at: 2026-10-06T22:53:21.833Z
  • Working session: 09b0cbc7-8519-4cc8-9dd8-81bbb18245d4
  • On-kill policy: resume (--on-session-kill=resume)
Kill diagnostics
  • last session memory reading — 9.3 GB of 11.7 GB RAM available (20.1% used) at 2026-10-07T00:30:00.914Z (phase solve_exit)
  • last session V8 heap reading — 45 MB used of 1.6 GB limit (2.8%) at 2026-10-07T00:30:00.914Z (phase solve_exit)
  • last session disk /: 83.9 GB free of 192.7 GB (56.4% used) at 2026-10-07T00:30:00.914Z (phase solve_exit)
  • container reports State.OOMKilled = true (an OOM event hit the container cgroup)
  • host memory now — 9.4 GB of 11.7 GB RAM available (19.4% used)
  • /proc/pressure/memory: some avg10=0.52 avg60=0.54 avg300=0.34 total=4214579610

The work session survived the container OOM event and completed. No replacement session was launched.

📎 The intermediate working-session log was uploaded as a separate comment.

Reported by Hive Mind

konard added a commit that referenced this pull request Oct 7, 2026
The Changesets 3 upgrade (PR #214) passed every pull-request check and
then failed every release on main, because changeset version - the only
command that formats the changelog - ran nowhere before the merge.

Run the release job's versioning script after the fresh-merge
simulation in the lint job, discard its output, and guard the wiring
in workflow-hygiene.test.mjs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update dependencies to their latest releases (nix 0.29->0.31, vt100 0.15->0.16, which 7->8) and enforce freshness in CI

2 participants