Repository navigation
Upgrade dependencies and fix vulnerabilities - #16
Merged
Merged
Conversation
Co-authored-by: Claude Opus 5 via [Pi](https://pi.dev/) <noreply@pi.dev>
Co-authored-by: Claude Opus 5 via [Pi](https://pi.dev/) <noreply@pi.dev>
Co-authored-by: Claude Opus 5 via [Pi](https://pi.dev/) <noreply@pi.dev>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WHY
Routine dependency maintenance. Everything is on latest, the two
tomladvisories are gone, and the repo actually lints again.The lint script was broken on
mainwith 211 errors, so there was no green baseline to upgrade against. First commit fixes that, the other two are the actual maintenance.WHAT
Upgrades
@oclif/core@oclif/plugin-help@oclif/testoclifeslinteslint-config-oclifmochatypescript@types/chai@types/nodesimplelogin-clientMinor and patch bumps
@inquirer/promptsyaml@eslint/compatchaieslint-config-prettiershxts-node@eslint/compat,chaiandshxwere already behind their declared ranges in the lockfile, the install picked them up on the way.Code changes required by the upgrades
tsconfig.json: added"types": ["node"]. TypeScript 7 (and 6 in the same layout) no longer pulls in every@typespackage automatically, sonode:fsand friends stopped resolving. Verified with a scratch project that it's not a pnpm symlink thing.src/commands/alias/delete.ts: droppednode:readline/promisesforconfirmfrom@inquirer/prompts. The newn/no-unsupported-features/node-builtinsrule flags it againstengines.node >=18, and we already use inquirer insl loginanyways.src/commands/alias/alias-list-base.ts: the--allpagination loop became recursion because ofno-await-in-loop, a deadgetFormat()that always returnedplainis gone, and therequire('yaml')inside theyamlbranch is a real import now. Thatrequirewould have thrown in ESM, sosl alias list --format yaml --allwas broken before.src/utils/simplelogin-client.ts:nullreturns becameundefined, the type said one thing and the code did the other after the autofix.src/commands/login.ts,src/utils/config.tsand the rest: mostly??over||,??=, errorcause, import sorting. Bulk of it iseslint --fix.README.mdis regenerated byprepack, thev0.2.0source links in it were stale since the last two releases.Security
toml@<4.2.0to>=4.2.0tomlcomes in viamarkdown-toc > gray-matter, both of which are direct-upgrade dead ends, hence the override.pnpm audit --fixwanted two overlapping entries, I kept the one that subsumes the other.pnpm auditis clean now andprepackstill produces the same TOC.Still open
typescripttypescript-eslint8.70 refuses to load on TS 7 and tracks support for TS >=7.1 in typescript-eslint#10940. Build itself is fine on 7.markdown-toccoffee-script,gulp-headerandlodash.template, all deprecated. Only used inprepack, so I'd say we replace it somewhen rather than in this PR.eslint-plugin-importeslint-import-resolver-typescript, lint works.unrs-resolverbuild scriptVerification
There are no test files in the repo and
pnpm testis commented out in CI, so this is build plus lint plus the release pipeline.pnpm install --frozen-lockfile- passpnpm run build- passpnpm run lint- pass (was 211 errors onmain)pnpm run prepack/postpack- passpnpm run pack:tarballs- pass, 6 targets built with oclif 6pnpm audit- clean./bin/run.js --version,help,alias list --help,config,whoami- pass