chore(deps): update all dependencies to latest - #61
Merged
Merged
Conversation
- pnpm 9.15.9 -> 12.6.0, TypeScript 5.9 -> 7.0.2, vitest 4 -> 5, commander 14 -> 15, @types/node 22 -> 26, Sandbox 0.54 -> 0.55.3, viem 2.56.9, hono 4.13.9, tsx 4.23.15. - Replace tsup with tsdown 0.23.0; tsup's declaration bundler needs the TypeScript JS API that TypeScript 7 no longer ships. Export paths and entry names are unchanged. - Delete typedoc and the unused docs script; typedoc supports TypeScript up to 6.0. - Pi was renamed to @earendil-works/pi-coding-agent. Type-check the extension against its real 0.87.1 types and delete the local module shim and the unused pi-tui peer. - Delete every pnpm override: with them gone, pnpm audit and the GitHub advisory database report no vulnerability in the resolved tree. - pnpm 12 reads no pnpm settings from .npmrc: delete it, and declare build scripts. - TypeScript 7: drop baseUrl, add node types, resolve tcloud-attestation through the workspace, copy the transcribe Buffer into a Uint8Array for Blob, and await start() in the agent-runner tests. - The dependency-contract test parses with oxc-parser instead of the TypeScript API. - Actions: checkout v7.0.1, pnpm/action-setup v6.1.0, setup-node v7.0.0, Node 22.23.3, npm 12.1.0. Publish through npm trusted publishing: NPM_TOKEN returned E404. - tcloud 0.7.0 requires Node 22.12, as commander 15 does.
tangletools
approved these changes
Sep 28, 2026
tangletools
left a comment
Contributor
There was a problem hiding this comment.
✅ Auto-approved PR — c6019d2a
Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.
tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-28T02:50:25Z
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates every dependency, the build toolchain, and the workflow actions to their latest releases. It releases as tcloud 0.7.0.
>=0.54.2 <0.55.0>=0.55.3 <0.56.0(0.x minor)Fixes
docsscript, so the script and typedoc are deleted. The dependency-contract test now parses withoxc-parser, as agent-eval does.baseUrlis gone.typesno longer defaults to every@typespackage, so node is listed explicitly.rootDiris the tsconfig directory, sopackages/tcloudresolves tcloud-attestation through the workspace instead of a path into its source. ABufferis no longer aBlobPart, sotranscribecopies it into aUint8Array. The twotests/agent-runner.test.tserrors that fix(security): remediate dependency alerts #56 recorded on main now awaitstart(). Every tsconfig, includingtcloud-agent/tsconfig.check.json, typechecks clean.@earendil-works/pi-coding-agent0.87.1 types, sosrc/pi-types.d.tsis deleted. fix(security): remediate dependency alerts #56 kept Pi out of the lockfile because Pi 0.70 pulled vulnerable packages. With 0.87.1 installed as a dev dependency,pnpm auditreports none. The extension never importedpi-tui, so that peer is gone.pnpm.overridesremoved and the lockfile regenerated from scratch,pnpm auditreports no known vulnerabilities. The GitHub advisory API returns none for the resolved ws 8.21.0, undici 8.10.2, protobufjs 7.6.6, vite 8.x and esbuild 0.28.2. The same API does flag ws 8.17.0 as a control.auto-install-peersfrom.npmrc, so the file is deleted. The default install now brings vitest 5's requiredvitepeer.allowBuildsrecords the build-script decisions that a CI install requires: esbuild yes, @google/genai and protobufjs no.>=22.12.0.NPM_TOKENsecret returnedE404on PUT when@tangle-network/tcloud@0.6.0published from fix(sdk): cancellable published transport and current Sandbox cohort for Knowledge #60's merge commit (run 36370799261). npm is also restricting token publishes. Release now publishes tokenless through npm trusted publishing, as agent-sdk does. This needs a trusted publisher on npmjs.com for@tangle-network/tcloud→tangle-network/tcloudrelease.yml.Verification (drew-gtr-pro, Node 22.23.2, pnpm 12.6.0)
CI=true pnpm install --frozen-lockfilewith build scripts enabled: passes. WithoutallowBuildsit fails withERR_PNPM_IGNORED_BUILDS, as agent-sdk's CI did.pnpm -r build: passes.tsc --noEmitpasses for the root, tcloud, tcloud-agent (src and tests) and tcloud-attestation configs.pnpm -r test: tcloud 297 passed and 32 skipped (live/e2e), tcloud-agent 34, tcloud-attestation 16.pnpm test:scriptsandnode scripts/check-cohort-ranges.mjspass.node scripts/prove-sdk-transport.mjspasses over real loopback HTTP against the built SDK.tangle-network-tcloud-0.7.0.tgz(42 files, noworkspace:specifier). A clean npm consumer passes the release workflow's esbuild bundle, a CJSrequire, and all four subpath imports. The pnpm 11.24.0 consumer with a 3-day strict release-age policy installs it.HOME:--versionprints 0.7.0.wallet generatewrites a wallet.modelslists 563 models from the production Router.pnpm -r outdated: empty.