Skip to content

chore(deps): upgrade TypeScript and patched toolchain minimums - #125

Merged
mldangelo-oai merged 4 commits into
mainfrom
renovate/typescript-7.x
Oct 3, 2026
Merged

mldangelo-oai merged 4 commits into
mainfrom
renovate/typescript-7.x

Conversation

@renovate

@renovate renovate Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Upgrade TypeScript from 6.0.3 to 7.0.2 in all four plugin packages while retaining Node 20/22/24 support and the current dependency security fixes. Raise the declared minimums to Vite 8.0.16 and Vitest 4.1.11, preserving the useful manifest changes from the superseded dependency PRs.

Add Draw UI type checking to CI, alongside the existing production build and all-plugin build/test matrix.

Validation: clean installs; Draw server build and 10 unit tests, UI type check and production build, and both WebSocket/polling integration tests; Promptfoo build and all 3 Vitest tests; Tax build and all end-to-end, classification, and deterministic parser checks. The final manifest and lockfile pairs pass clean-install validation.

@renovate
renovate Bot force-pushed the renovate/typescript-7.x branch 2 times, most recently from 2c92f74 to 306ed71 Compare September 7, 2026 16:33
@renovate
renovate Bot force-pushed the renovate/typescript-7.x branch from 306ed71 to 7eac509 Compare September 24, 2026 20:40
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T01:04:21.944144Z 2ce3efb New commits
🔒 Security Review ✅ Completed 2026-10-03T01:02:58.118188Z 2ce3efb New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@renovate

renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@mldangelo-oai mldangelo-oai changed the title chore(deps): update dependency typescript to v7 chore(deps): upgrade TypeScript and patched toolchain minimums Oct 3, 2026
@mldangelo-oai
mldangelo-oai merged commit 95cd44e into main Oct 3, 2026
16 checks passed
@mldangelo-oai
mldangelo-oai deleted the renovate/typescript-7.x branch October 3, 2026 01:02
mldangelo-oai added a commit that referenced this pull request Oct 3, 2026
Draw could render without its Excalidraw styles and skip collaboration
setup when the canvas API became ready after the initial effect. Load
the stylesheet, start collaboration when the API is available, and pass
participant cursors to Excalidraw. A two-browser check verified Mermaid
conversion, live drawing/text updates, collaborator cursors, and
restoring the shared scene after reload.

Patch the remaining exact-pinned UI dependencies with scoped Nano ID
overrides, lodash-es 4.18.1, and Sass 1.105.0. The Sass update removes
the vulnerable Chokidar/Braces chain. Keep Node 20 support and an npm
10/11-compatible lockfile. The original Vite minimum update is already
included through #125.

Validation:
- Clean UI installs with npm 10 and npm 11.
- UI TypeScript check and production build.
- All three Draw integration tests: WebSocket, polling, and the new
served-stylesheet regression check.
- Browser QA with two local sessions; no console errors.

The repository CI additionally runs Draw and both other plugins on Node
20, 22, and 24, plus CLI unit tests and ShellCheck.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Michael D'Angelo <mdangelo@openai.com>
mldangelo-oai added a commit that referenced this pull request Oct 3, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.14.1](v0.14.0...v0.14.1)
(2026-10-03)

### Features

- Add `crab version` as an alias for checking the installed version
([#128](#128)).
- Add `crab env encrypt <staging-dir> [output-file]` to retry snapshot
encryption without rerunning the agent. Preserve staging on failure,
reject existing backups and output inside staging, and handle relative
paths and names beginning with a dash
([#68](#68)).

### Bug Fixes

- Restore Draw canvas styling, initialize collaboration after the
Excalidraw API is ready, and display collaborator cursors. Browser
checks cover Mermaid conversion, shared edits, and scene reloads
([#118](#118)).
- Patch Nano ID and lodash-es versions pinned inside Excalidraw
dependencies, and update Sass to remove the vulnerable Chokidar/Braces
chain ([#118](#118)).
- Upgrade Zod to v4
([#50](#50)), Excalidraw to
v0.18.1 ([#104](#104)), and
React to v19 ([#105](#105)).
- Address Draw UI dependency alerts
([#102](#102)) and refresh
plugin locks with patched Engine.IO, Socket.IO parser, Immutable,
DOMPurify, Mermaid, PostCSS, Vite, and Vitest dependencies
([#116](#116),
[#130](#130)).
- Load Node type definitions explicitly so the Tax plugin compiles, and
keep the Draw UI lockfile installable with npm 10 and 11
([#116](#116)).

### Development

- Upgrade all plugin compilers to TypeScript 7.0.2 and require at least
Vite 8.0.16 and Vitest 4.1.11, while retaining Node 20/22/24 support
([#125](#125)).
- Build and test every plugin on Node 20, 22, and 24; add Draw UI type
checking and Promptfoo parser/configuration smoke tests
([#116](#116),
[#125](#125)).
- Update the pinned checkout, setup-node, and CI aggregation actions
([#124](#124),
[#153](#153),
[#154](#154)).

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Michael D'Angelo <mdangelo@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant