Repository navigation
Update all dependencies and enforce freshness in CI - #214
Conversation
Adding .gitkeep for PR creation (default mode). This file will be removed when the task is complete. Issue: #204
Working session summaryPR #214 is updated and ready for review. Dependencies and lockfiles are current, freshness CI is added, and CI regressions are fixed. Validation: 2,564 JavaScript tests, 828 Rust tests, and 51 CI checks pass. Working tree is clean. JavaScript now requires Node 22. The remaining portable-pty → nix duplicate is documented. Releases are prepared for publication after merge. This summary was automatically extracted from the AI working session output. |
🤖 Solution Draft LogThis log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
📊 Context and tokens usage:
Total: (674.2K + 21.2M cached) input tokens, 153.3K output tokens, $9.240264 cost 🤖 Models used:
📎 Log file uploaded as Gist (12559KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🎉 Auto-mergedThis pull request has been automatically merged by hive-mind.
Auto-merged by hive-mind with --auto-merge flag |
📎 Intermediate working-session log (killed session)This log file contains the complete execution trace of the AI solution draft process. 📎 Log file uploaded as Gist (11433KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
|
The Changesets 3 upgrade (PR #214) passed every pull-request check and then failed every release on main, because changeset version - the only command that formats the changelog - ran nowhere before the merge. Run the release job's versioning script after the fresh-merge simulation in the lint job, discard its output, and guard the wiring in workflow-hygiene.test.mjs.
The manifests allowed older releases of nix, vt100, which, and many other dependencies, so consumers resolved outdated direct crates alongside current ones. Update every maintained Rust and JavaScript runtime, development, benchmark, and release-script dependency to its latest stable release, refresh both Cargo lockfiles and both JavaScript lockfiles, and update GitHub Actions and pinned CI package tools.
Addresses #204 and the maintainer's request to update all dependencies.
API changes and compatibility
Parser::set_sizewithParser::screen_mut().set_size. All 12 terminal regression tests pass..setto.header, HTTP status errors toError::StatusCode, and.into_stringto mutable body readers. Preserve the existing release checks and error handling. toml 0.8 → 1.1.6 keeps the manifest version guard passing.execaCommandandexecaCommandSynchelpers through wrappers around the upstream parser and execution methods, with ESM/CommonJS exports, option presets, factories, and TypeScript contracts tested. Document Execa 10's.nodeChildProcess, explicit IPC option, and stdin precedence changes in the migration guide.causeand removing an unused initial assignment. Add Chalk explicitly for the existing zx fixtures, which previously relied on a transitive install. Use node-pty's latest stable release instead of its prerelease. Its 1.1.0 tarball ships both macOSspawn-helperbinaries with mode 0644, whereas the previous beta shipped 0755; this causedposix_spawnp failedin 13 macOS PTY tests. Repair missing owner execute permission for the helper selected by the loaded native binding before PTY startup, preserving existing executable modes. A regression test reproduces EACCES with a mode-0644 helper and verifies successful execution after repair.Freshness policy and reproduction
bun scripts/check-dependencies.mjscompares all 89 maintained package/tool declarations against registry latest stable releases, including embedded Rust-script manifests. Outdated Rust declarations need a same-line GitHub issue blocker; the issue must be open and must be an issue rather than a pull request. Closed blockers, malformed metadata, and lookup failures fail the check. No blockers are needed for the current declarations.The new workflow runs on every PR, main push, manual dispatch, and weekly. It also runs
npm outdatedand checks bothcargo update --dry-runoutputs for pending version updates. Offline policy tests reproduce stale declarations across semver ranges and verify blocker and registry failure handling. Regression tests execute the actual lockfile workflow without ripgrep and with Cargo colors enabled; the gate forces plain output and rejects package upgrades, additions, removals, and downgrades in either manifest.Before updating dependencies, the registry probe reported 61 stale declarations. Afterward it reports zero.
python3 experiments/issue-204/check-consumer.py --rust-root /path/to/old/checkout/rustreproduces the old nix mismatch; running without that argument verifies that the consumer and command-stream share the exact current nix, vt100, and which crate IDs.Cancellation regression found in CI
Windows run 37546397534 exceeded the 30-minute job limit: log line 1208 reported
child_handle_can_stop_the_processrunning for over 60 seconds. Opt-in traces in the next run showed taskkill completing at 00:08:05 UTC (lines 1188–1191), followed by output collection waiting until 00:08:10 UTC (lines 1193–1198). CancelledProcessRunner::runawaited pipe EOF without a deadline, even after the direct child had exited.The finite
experiments/issue-204/pipe-holder.rsfixture reproduces that wait with a descendant retaining stdout and stderr outside the cancelled process group.cargo test --manifest-path rust/Cargo.toml --all-features --test cancelled_outputfails its 500-millisecond deadline before the fix. Continue draining during graceful shutdown, then bound remaining collection to the existing 100-millisecond streaming grace after child exit while preserving buffered bytes. Both the inherited-pipe regression and a finite 256-KiB signal-handler output regression pass. Windows native-child tests now run eight bounded attempts for each cancellation path, alternating tracing off and on, with a two-second collection deadline and ten-second outer subprocess deadline.Validation and release preparation
All nine workflows passed on final commit
ce6a2f8bd774b3b1ed9f715c19f92130ad37a71a(committed 2026-10-07 00:18:57 UTC; runs started 00:19:15 UTC): 51 checks succeeded and six release jobs were skipped as expected for a pull request. Rust, JavaScript, dependency freshness, and security are green. The Windows log at lines 1220–1222 confirms that cancelled output collection now returns after its bounded grace; all 16 native-child subprocess probes passed.npm outdated,cargo outdated --root-deps-only --exit-code 1in both Cargo packages, and both Cargo dry runs show no pending updates.Add a JavaScript major changeset for the new Node baseline and a Rust patch changelog fragment. The existing main-branch release workflows will assign versions and publish npm/crates.io packages after merge; this PR does not claim that publication has already occurred.
Remaining upstream limitation: portable-pty 0.9.0 is the latest stable release and still depends on nix 0.28.0. The fresh consumer therefore retains that transitive nix copy alongside the shared nix 0.31.3, although vt100 and which no longer duplicate. Eliminating it requires an upstream portable-pty update or a separate PTY backend replacement. The committed consumer probe reports this explicitly; it does not claim a duplicate-free graph.
Fixes #204
Changes
.github/workflows/benchmarks.yml.github/workflows/bun-shell.yml.github/workflows/dependencies.yml.github/workflows/docs.yml.github/workflows/js.yml.github/workflows/links.yml.github/workflows/parity.yml.github/workflows/quality.yml.github/workflows/rust.yml.github/workflows/security.yml.github/workflows/workflows.ymlREADME.mdclaude-profiles.mjsdocs/README.mddocs/features/execa-compat.mddocs/site/index.htmlexperiments/issue-204/README.mdexperiments/issue-204/check-consumer.pyexperiments/issue-204/pipe-holder.rsjs/.changeset/issue-204-dependencies.mdjs/README.mdjs/bun.lockjs/docs/BUNDLE_SIZE_COMPARISON.mdjs/docs/EXECA_MIGRATION.mdjs/examples/features/catalog.mjsjs/package-lock.jsonjs/package.jsonjs/scripts/setup-npm.mjsjs/src/bun-shell/expansion.mjsjs/src/bun-shell/template.mjsjs/src/execa/index.cjsjs/src/execa/index.mjsjs/src/terminal-pty-host-platform.mjsjs/src/terminal-pty-host.mjsjs/tests/benchmark-suite.test.mjsjs/tests/dependency-freshness.test.mjsjs/tests/execa/api.test.mjsjs/tests/setup-npm.test.mjsjs/tests/terminal-pty-helper.test.mjsjs/tests/test-cleanup.mjsjs/tests/test-helper.mjsjs/tests/types/execa-cjs.types.ctsjs/tests/types/execa.types.tsjs/types/api.d.ctsjs/types/execa-api.d.ctsjs/types/execa.d.ctsjs/types/execa.d.tsrust/Cargo.lockrust/Cargo.tomlrust/benchmarks/Cargo.lock