Repository navigation
build: isolate benchmark dependency upgrades - #2387
dependabot[bot] wants to merge 7 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c4c03f2be5
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
c4c03f2 to
0684913
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0684913b18
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
0684913 to
21bdeb8
Compare
Bumps [he](https://github.com/mathiasbynens/he) from 1.2.0 to 2.0.0. - [Commits](mathiasbynens/he@v1.2.0...v2.0.0) --- updated-dependencies: - dependency-name: he dependency-version: 2.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
21bdeb8 to
202d43f
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3a0c6aefe7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@coderabbitai review |
|
There was a problem hiding this comment.
🟢 Approval recommended
The dependency isolation, configuration, documentation, and CI changes are consistent and complete.
0 open findings
What changed in this PR
Isolates benchmark-only dependencies in a private package without affecting runtime dependencies.
Changes:
- Adds an independently installed and type-checked benchmark package.
- Updates benchmark imports and upgrades
heto 2.0.0. - Adds CI, Dependabot, and documentation support.
| File | Description |
|---|---|
tsconfig.eslint.json |
Excludes the nested benchmark project. |
scripts/benchmark/tsconfig.json |
Adds benchmark type-checking configuration. |
scripts/benchmark/package.json |
Defines the private benchmark package. |
scripts/benchmark/package-lock.json |
Locks benchmark dependencies separately. |
scripts/benchmark/benchmark.ts |
Updates imports for the new location and he API. |
readme.md |
Documents benchmark setup and historical results. |
package.json |
Delegates benchmark execution and removes benchmark dependencies. |
package-lock.json |
Removes direct benchmark dependencies from the root lockfile. |
eslint.config.mjs |
Excludes the separately configured benchmark project. |
.github/workflows/nodejs-test.yml |
Installs and type-checks benchmark dependencies. |
.github/dependabot.yml |
Adds benchmark dependency updates. |
Files not reviewed (1)
- scripts/benchmark/package-lock.json: Generated file
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b70b531349
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| matrix: | ||
| node: | ||
| - '20.19.0' | ||
| - '20' |
There was a problem hiding this comment.
Keep testing the declared minimum Node release
In the test job, replacing the exact 20.19.0 entry with 20 allows setup-node to select any cached matching Node 20 release, so CI no longer verifies the node >=20.19.0 compatibility promised by package.json. The setup-node v6 documentation confirms that major versions are SemVer specifications distinct from specific versions. If code or a dependency starts relying on behavior added after 20.19.0, all matrix jobs can pass while users on the declared minimum fail; retain 20.19.0 as the lower-bound test.
Useful? React with 👍 / 👎.
Isolates he 2.0.0 and the other benchmark-only libraries (html-entities, parse-entities and tinybench) in a private scripts/benchmark package. Root installs and published runtime dependencies do not depend on the benchmark package. The benchmark requires Node >=22 and uses he named exports. tsx remains at root because trie generators use it.
Adds separate benchmark installation and type checking to CI, documents the benchmark setup and adds its own Dependabot entry.
Validation: root lint, benchmark type checking, library build, 513 tests and the full benchmark run pass locally. One fixture test is skipped because its submodule is not initialized locally. All 50 published source and compiled files are byte-identical to the base build; runtime package fields are unchanged. Fresh GitHub CI runs on the pushed commit.