Skip to content

chore(deps): update all dependencies to latest - #61

Merged
drewstone merged 1 commit into
mainfrom
chore/deps-latest-20260928
Sep 28, 2026
Merged

drewstone merged 1 commit into
mainfrom
chore/deps-latest-20260928

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Updates every dependency, the build toolchain, and the workflow actions to their latest releases. It releases as tcloud 0.7.0.

Dependency From To
pnpm (packageManager) 9.15.9 12.6.0 (major)
typescript (all packages) ^5.9.3 ^7.0.2 (major)
vitest ^4.1.11 ^5.0.2 (major)
commander (tcloud runtime) ^14.0.3 ^15.0.0 (major)
@types/node ^22 ^26.6.3 (major)
@tangle-network/sandbox (tcloud, tcloud-agent runtime) >=0.54.2 <0.55.0 >=0.55.3 <0.56.0 (0.x minor)
Pi peer (tcloud-agent, optional) @mariozechner/pi-coding-agent ^0.70 + pi-tui ^0.70 @earendil-works/pi-coding-agent ^0.87.1 (renamed; npm deprecates the old name)
tsup ^8.5.1 removed, replaced by tsdown ^0.23.0
typedoc ^0.28.20 removed
viem ^2.56.0 ^2.56.9
hono (relayer) ^4.13.5 ^4.13.9
tsx ^4.23.12 ^4.23.15
pnpm overrides (11 security pins) present removed
actions/checkout, pnpm/action-setup, actions/setup-node v6 / v4 / v6 SHAs v7.0.1 / v6.1.0 / v7.0.0 SHAs
Release Node, npm 22.23.1, 12.0.1 22.23.3, 12.1.0

Fixes

  • TypeScript 7 ships no JS compiler API. tsup's declaration bundler cannot run, so all four packages build with tsdown. Export paths, formats and entry file names are unchanged. Chunk names differ. typedoc supports TypeScript only up to 6.0. Nothing ran its docs script, so the script and typedoc are deleted. The dependency-contract test now parses with oxc-parser, as agent-eval does.
  • TypeScript 7 defaults. baseUrl is gone. types no longer defaults to every @types package, so node is listed explicitly. rootDir is the tsconfig directory, so packages/tcloud resolves tcloud-attestation through the workspace instead of a path into its source. A Buffer is no longer a BlobPart, so transcribe copies it into a Uint8Array. The two tests/agent-runner.test.ts errors that fix(security): remediate dependency alerts #56 recorded on main now await start(). Every tsconfig, including tcloud-agent/tsconfig.check.json, typechecks clean.
  • Pi rename. The extension now type-checks against the real @earendil-works/pi-coding-agent 0.87.1 types, so src/pi-types.d.ts is deleted. fix(security): remediate dependency alerts #56 kept Pi out of the lockfile because Pi 0.70 pulled vulnerable packages. With 0.87.1 installed as a dev dependency, pnpm audit reports none. The extension never imported pi-tui, so that peer is gone.
  • Overrides deleted. With the 11 pnpm.overrides removed and the lockfile regenerated from scratch, pnpm audit reports no known vulnerabilities. The GitHub advisory API returns none for the resolved ws 8.21.0, undici 8.10.2, protobufjs 7.6.6, vite 8.x and esbuild 0.28.2. The same API does flag ws 8.17.0 as a control.
  • pnpm 12. pnpm no longer reads auto-install-peers from .npmrc, so the file is deleted. The default install now brings vitest 5's required vite peer. allowBuilds records the build-script decisions that a CI install requires: esbuild yes, @google/genai and protobufjs no.
  • Node floor. commander 15 requires Node 22.12, so tcloud and tcloud-agent now declare >=22.12.0.
  • Publishing. The NPM_TOKEN secret returned E404 on PUT when @tangle-network/tcloud@0.6.0 published from fix(sdk): cancellable published transport and current Sandbox cohort for Knowledge #60's merge commit (run 36370799261). npm is also restricting token publishes. Release now publishes tokenless through npm trusted publishing, as agent-sdk does. This needs a trusted publisher on npmjs.com for @tangle-network/tcloud → tangle-network/tcloud release.yml.

Verification (drew-gtr-pro, Node 22.23.2, pnpm 12.6.0)

  • CI=true pnpm install --frozen-lockfile with build scripts enabled: passes. Without allowBuilds it fails with ERR_PNPM_IGNORED_BUILDS, as agent-sdk's CI did.
  • pnpm -r build: passes. tsc --noEmit passes for the root, tcloud, tcloud-agent (src and tests) and tcloud-attestation configs.
  • pnpm -r test: tcloud 297 passed and 32 skipped (live/e2e), tcloud-agent 34, tcloud-attestation 16. pnpm test:scripts and node scripts/check-cohort-ranges.mjs pass.
  • node scripts/prove-sdk-transport.mjs passes over real loopback HTTP against the built SDK.
  • Packed tangle-network-tcloud-0.7.0.tgz (42 files, no workspace: specifier). A clean npm consumer passes the release workflow's esbuild bundle, a CJS require, and all four subpath imports. The pnpm 11.24.0 consumer with a 3-day strict release-age policy installs it.
  • Real CLI from the packed tarball with an empty HOME: --version prints 0.7.0. wallet generate writes a wallet. models lists 563 models from the production Router.
  • pnpm -r outdated: empty.

- pnpm 9.15.9 -> 12.6.0, TypeScript 5.9 -> 7.0.2, vitest 4 -> 5, commander 14 -> 15,
  @types/node 22 -> 26, Sandbox 0.54 -> 0.55.3, viem 2.56.9, hono 4.13.9, tsx 4.23.15.
- Replace tsup with tsdown 0.23.0; tsup's declaration bundler needs the TypeScript
  JS API that TypeScript 7 no longer ships. Export paths and entry names are unchanged.
- Delete typedoc and the unused docs script; typedoc supports TypeScript up to 6.0.
- Pi was renamed to @earendil-works/pi-coding-agent. Type-check the extension against
  its real 0.87.1 types and delete the local module shim and the unused pi-tui peer.
- Delete every pnpm override: with them gone, pnpm audit and the GitHub advisory
  database report no vulnerability in the resolved tree.
- pnpm 12 reads no pnpm settings from .npmrc: delete it, and declare build scripts.
- TypeScript 7: drop baseUrl, add node types, resolve tcloud-attestation through the
  workspace, copy the transcribe Buffer into a Uint8Array for Blob, and await
  start() in the agent-runner tests.
- The dependency-contract test parses with oxc-parser instead of the TypeScript API.
- Actions: checkout v7.0.1, pnpm/action-setup v6.1.0, setup-node v7.0.0, Node 22.23.3,
  npm 12.1.0. Publish through npm trusted publishing: NPM_TOKEN returned E404.
- tcloud 0.7.0 requires Node 22.12, as commander 15 does.

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — c6019d2a

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-28T02:50:25Z

@drewstone
drewstone merged commit 06228ac into main Sep 28, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants