Repository navigation
Conversation
…dates Bumps the development-minor-and-patch group with 3 updates: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest). Updates `@types/node` from 22.20.4 to 22.20.5 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@vitest/coverage-v8` from 5.0.2 to 5.0.3 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8) Updates `vitest` from 5.0.2 to 5.0.3 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 22.20.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-minor-and-patch - dependency-name: "@vitest/coverage-v8" dependency-version: 5.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-minor-and-patch - dependency-name: vitest dependency-version: 5.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 7, 2026, 12:36 AM ET / 04:36 UTC (Revision 6). ClawSweeper reviewWhat this changesUpdates the development lockfile to Node typings 22.20.5 and matching Vitest and V8 coverage packages 5.0.3, including their transitive dependencies. Merge readiness✅ Ready for maintainer review Keep open: these updates remain absent from current main and the latest release. The pinned diff has no actionable correctness or security finding, and no additional merge blocker remains. Priority: P3 Review scores
Verification
How this fits togetherClawpatch’s development tooling uses Node typings to check TypeScript and Vitest to run tests and measure coverage. The lockfile selects the package versions installed by contributors and CI. flowchart LR
A[Development dependency ranges] --> B[Locked package versions]
B --> C[Development and CI install]
C --> D[Type checking]
C --> E[Tests and coverage]
D --> F[Validation results]
E --> F
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Retain the existing development-tooling contract while adopting these coordinated patch releases through the normal dependency-update path. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates development dependencies rather than reporting a reproducible application bug. Is this the best way to solve the issue? Yes: the lockfile-only update preserves declared ranges and the Node 22 typing floor while keeping Vitest and coverage versions synchronized. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against b8565de5bb68. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (5 earlier review cycles)
|
Complete the dependency refresh from PR #233 and record the combined update in the changelog. Keep the Node 22 floor and 48-hour release-age policy.
What Problem This Solves
Refreshes development dependencies within the repository's 48-hour release-age policy: Node 22 typings 22.20.5, Vitest and V8 coverage 5.0.3, Vite 8.3.2, and pnpm 11.28.4.
User Impact
Development and CI use the eligible patch releases while the published CLI keeps its Node 22 floor. No CLI behavior or package-version change.
Why This Change Was Made
Keeps the Vitest and coverage versions aligned, includes Vitest's upstream fix for pnpm trust-downgrade installation failures, and keeps the Crabbox hydration pnpm pin aligned with the package manager. Newer Oxfmt, Oxlint, and Vite releases remain deferred by the cooldown. Thanks @dependabot[bot] for the original dependency update.
Evidence
On an isolated AWS Linux runner with Node 24.19.0 and pnpm 11.28.4, the full gate passed: frozen install, typecheck, lint, formatting, V8 coverage (50 files; 964 tests passed, 2 platform skips), build, and packaged CLI smoke (13 mapped features, including 3 CUDA features).
Independent Codex autoreview completed with no actionable P0–P2 findings. GitHub Actions provides the final Node 22/24/26 and Windows checks on the updated PR head.