Skip to content

build: isolate benchmark dependency upgrades - #2387

Open
dependabot[bot] wants to merge 7 commits into
mainfrom
dependabot/npm_and_yarn/he-2.0.0
Open

dependabot[bot] wants to merge 7 commits into
mainfrom
dependabot/npm_and_yarn/he-2.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Isolates he 2.0.0 and the other benchmark-only libraries (html-entities, parse-entities and tinybench) in a private scripts/benchmark package. Root installs and published runtime dependencies do not depend on the benchmark package. The benchmark requires Node >=22 and uses he named exports. tsx remains at root because trie generators use it.

Adds separate benchmark installation and type checking to CI, documents the benchmark setup and adds its own Dependabot entry.

Validation: root lint, benchmark type checking, library build, 513 tests and the full benchmark run pass locally. One fixture test is skipped because its submodule is not initialized locally. All 50 published source and compiled files are byte-identical to the base build; runtime package fields are unchanged. Fresh GitHub CI runs on the pushed commit.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 7, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T07:55:28.159028Z b70b531 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7676aef4-27b6-4cc3-863a-7f64920eebf1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c4c03f2be5

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread package.json Outdated
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/he-2.0.0 branch from c4c03f2 to 0684913 Compare October 8, 2026 20:36

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0684913b18

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread package.json Outdated
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/he-2.0.0 branch from 0684913 to 21bdeb8 Compare October 8, 2026 20:39
Bumps [he](https://github.com/mathiasbynens/he) from 1.2.0 to 2.0.0.
- [Commits](mathiasbynens/he@v1.2.0...v2.0.0)

---
updated-dependencies:
- dependency-name: he
  dependency-version: 2.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/he-2.0.0 branch from 21bdeb8 to 202d43f Compare October 8, 2026 20:44
@fb55 fb55 changed the title build(deps-dev): bump he from 1.2.0 to 2.0.0 build: upgrade he to v2 in an isolated benchmark package Oct 9, 2026
@fb55 fb55 changed the title build: upgrade he to v2 in an isolated benchmark package build: isolate benchmark dependency upgrades Oct 9, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3a0c6aefe7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread readme.md Outdated
@fb55

fb55 commented Oct 9, 2026

Copy link
Copy Markdown
Owner

@coderabbitai review

@fb55
fb55 requested a balanced review from Copilot October 9, 2026 19:00
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The dependency isolation, configuration, documentation, and CI changes are consistent and complete.

0 open findings

What changed in this PR

Isolates benchmark-only dependencies in a private package without affecting runtime dependencies.

Changes:

  • Adds an independently installed and type-checked benchmark package.
  • Updates benchmark imports and upgrades he to 2.0.0.
  • Adds CI, Dependabot, and documentation support.
File Description
tsconfig.eslint.json Excludes the nested benchmark project.
scripts/​benchmark/​tsconfig.json Adds benchmark type-checking configuration.
scripts/​benchmark/​package.json Defines the private benchmark package.
scripts/​benchmark/​package-lock.json Locks benchmark dependencies separately.
scripts/​benchmark/​benchmark.ts Updates imports for the new location and he API.
readme.md Documents benchmark setup and historical results.
package.json Delegates benchmark execution and removes benchmark dependencies.
package-lock.json Removes direct benchmark dependencies from the root lockfile.
eslint.config.mjs Excludes the separately configured benchmark project.
.github/​workflows/​nodejs-test.yml Installs and type-checks benchmark dependencies.
.github/​dependabot.yml Adds benchmark dependency updates.
Files not reviewed (1)
  • scripts/benchmark/package-lock.json: Generated file

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b70b531349

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

matrix:
node:
- '20.19.0'
- '20'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep testing the declared minimum Node release

In the test job, replacing the exact 20.19.0 entry with 20 allows setup-node to select any cached matching Node 20 release, so CI no longer verifies the node >=20.19.0 compatibility promised by package.json. The setup-node v6 documentation confirms that major versions are SemVer specifications distinct from specific versions. If code or a dependency starts relying on behavior added after 20.19.0, all matrix jobs can pass while users on the declared minimum fail; retain 20.19.0 as the lower-bound test.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants