Skip to content

fix(deps): bump @sasjs/utils to 3.6.3 - #1476

Merged
allanbowe merged 5 commits into
mainfrom
chore/drop-prepare-and-bump-utils
Oct 4, 2026
Merged

allanbowe merged 5 commits into
mainfrom
chore/drop-prepare-and-bump-utils

Conversation

@sasjs-dev

@sasjs-dev sasjs-dev Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

All four @sasjs/* dependencies now track their released versions.

@sasjs/adapter  4.19.1 -> 4.19.2
@sasjs/core     5.2.10 -> 5.3.0
@sasjs/lint     4.1.1  -> 4.1.2
@sasjs/utils    3.6.2  -> 3.6.4

adapter 4.19.2 is the release that carried the adapter cleanup which had been sitting on master unreleased - the prepare script removal, the redundant https removal and the Dependabot removal - because those PRs merged with merge commits and semantic-release reads only the first-parent chain. lint 4.1.2 carries the same engines fix as this PR.

This package's own manifest

prepare            removed   ran `git config core.hooksPath ./.git-hooks` on install
find               removed   no call site in src
engines            >=14 -> ^14.18.0 || >=16.10.0
@types/prompts     added     devDependency - see below

engines matches what the tree supports: this package resolves consola@3.4.2 through @sasjs/utils, and consola declares ^14.18.0 || >=16.10.0, so >=14 admitted 14.0-14.17 and all of 15.x. checkNodeVersion enforces the same range.

@types/prompts is a devDependency because this package's own source imports prompts (src/commands/auth/login.ts and its spec). It previously resolved only by accident - @types/prompts is a dependency of @sasjs/utils, and npm hoisted it to the root on some installs and nested it under utils on others. TypeScript only auto-resolves @types from the root, so when it nested the build failed:

src/commands/auth/login.ts(1,21): error TS7016: Could not find a declaration file for module 'prompts'.

Depending on where another package's transitive types happen to land is not a contract.

Verified

  • resolved in the lockfile: adapter 4.19.2, core 5.3.0, lint 4.1.2, utils 3.6.4, @types/prompts 2.4.9
  • npm run build: exit 0, 0 TS errors (checked without a pipe, so the exit code is the build's)
  • mocked suite: 86 suites, 667 tests passed - the one failure is printVersion, which needs a globally installed @sasjs/cli and fails identically on main
  • npm audit --omit=dev: 0 vulnerabilities
  • lockfile regenerated with npx npm@10 install, matching what CI runs

Merge with squash or rebase

A merge commit's Merge pull request #NNN subject is invisible to semantic-release, which walks only the first-parent chain.

Picks up the Logger.warn fix - falsy arguments were passed straight to consola
while every other log method dropped them - and drops the install-time script
and the redundant dependencies that 3.6.2 carried.

Also removes this package's own `prepare` script, which ran
`git config core.hooksPath ./.git-hooks` on every install, and the `find`
dependency, which has no call site in src.
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Coverage report

Total coverage

Status Category Percentage Covered / Total
🟡 Statements 75.74% 3574/4719
🟡 Branches 63.39% 1463/2308
🟡 Functions 75.55% 717/949
🟢 Lines 84.29% 9094/10789

Status of coverage: 🟢 - ok, 🟡 - slightly more than threshold, 🔴 - under the threshold

Show files with reduced coverage 🔻

Reduced coverage

Status Filename Statements Branches Functions Lines
🟢 src/commands/compile/compileSingleFile.ts 95.83% (-2.08% 🔻) 84% (-4% 🔻) 100% 100%

Status of coverage: 🟢 - ok, 🟡 - slightly more than threshold, 🔴 - under the threshold

Report generated by 🧪jest coverage report action from 013d361

@sasjs-dev sasjs-dev Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the base...head diff (package.json plus package-lock.json: @sasjs/utils 3.6.2 -> 3.6.3, the unused direct find dependency dropped, the dead prepare script removed).

  • package.json:4-5 - "node": ">=14" no longer matches the tree the lockfile pins: the bump resolves consola 3.4.2 (package-lock.json:4923), which declares node: ^14.18.0 || >=16.10.0, so Node 14.0-14.17 and all of 15.x fall outside a shipped transitive's requirement (jsdom 26.0.0, a pre-existing runtime dependency, already requires >=18). npm only warns today, but the declared floor should describe what installs: raise engines.node to >=18, or at least to ^14.18.0 || >=16.10.0, and align the >=12 floor enforced by checkNodeVersion() (src/utils/utils.ts:497-504) with it.

1 finding above for review.

sasjs added 4 commits October 4, 2026 12:14
3.6.4 restores @types/prompts as a dependency, and 3.6.3 dropped the
install-time script and the redundant dependencies that 3.6.2 carried.

Also removes this package's own `prepare` script, which ran
`git config core.hooksPath ./.git-hooks` on every install, and the `find`
dependency, which has no call site in src.
engines.node said >=14, but this package resolves consola 3.4.2 through
@sasjs/utils, and consola declares ^14.18.0 || >=16.10.0. A major-only floor
admits versions whose own dependencies reject them: 14.0-14.17 and every 15.x.

engines.node now states ^14.18.0 || >=16.10.0, and the checkNodeVersion script
enforces the same range rather than a bare `parseInt(node) < 14`, so the two
cannot drift apart.
The three @sasjs runtime dependencies now track the released versions:

    @sasjs/adapter  4.19.1 -> 4.19.2   install script and redundant `https` removed
    @sasjs/core     5.2.10 -> 5.3.0
    @sasjs/utils    3.6.2  -> 3.6.4    (already in this branch)

4.19.2 is the release that carried the adapter cleanup that had been sitting on
master unreleased, because those merges used merge commits and semantic-release
only reads the first-parent chain.

@sasjs/lint stays at 4.1.1 until sasjs/lint#250 releases.
@sasjs/lint 4.1.2 carries the engines fix (^14.18.0 || >=16.10.0) and the
prepare-script removal, so all four @sasjs dependencies now track the released
versions: adapter 4.19.2, core 5.3.0, lint 4.1.2, utils 3.6.4.

@types/prompts is added as a devDependency because this package's own source
imports 'prompts' (src/commands/auth/login.ts and its spec). It previously
resolved only by accident: @types/prompts is a dependency of @sasjs/utils, and
npm hoisted it to the root on some installs and nested it under utils on others.
TypeScript only auto-resolves @types from the root, so when it nested, the build
failed:

  src/commands/auth/login.ts(1,21): error TS7016: Could not find a declaration
  file for module 'prompts'.

Depending on where another package's transitive types land is not a contract;
this package imports prompts, so it declares the types.
@allanbowe
allanbowe merged commit 1a6c483 into main Oct 4, 2026
2 checks passed
@allanbowe
allanbowe deleted the chore/drop-prepare-and-bump-utils branch October 4, 2026 13:16

@sasjs-dev sasjs-dev Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review at the head the PR reached before it was squash-merged to main (merge commit 1a6c483, subject from the PR title - see the title finding below). Three commits landed since the last review, including the final 013d361 (lint 4.1.2 + @types/prompts); the prior finding is addressed: engines.node is now "^14.18.0 || >=16.10.0" and the checkNodeVersion npm script enforces the same range. Manifest and lockfile moved together; the audit step is strict and the pipeline was green at the final head.

  • PR title - the repo squashes on merge (squash_merge_commit_title = COMMIT_OR_PR_TITLE) and semantic-release reads the squashed subject, but the title stayed "fix(deps): bump @sasjs/utils to 3.6.3" while the PR ultimately shipped utils 3.6.4, adapter 4.19.2, core 5.3.0, lint 4.1.2, the engines rewrite and the prepare-script removal - the merge commit now carries the stale subject, so the release note will describe one sub-bump and none of the rest. For the next bump round, update the title before merging, or merge with a corrected subject.

  • src/utils/utils.ts:7 and src/commands/run/run.ts:25 - import axios from 'axios' is not declared in package.json dependencies; it resolves only through @sasjs/adapter's transitive pin (axios 1.20.0 in the lockfile). An adapter release that drops or re-versions axios breaks the CLI build with no signal. Declare axios in dependencies at the version the tree resolves.

  • package.json:4-5 - the new engines range still does not describe the tree it ships: jsdom 26.0.0 is a direct runtime dependency (imported at src/commands/web/internal/updateSasjsTag.ts:2) and declares engines: node >=18 (package-lock.json), so installing on any Node 14/15/16 release the range admits now pulls a direct dependency that does not support it, and the commit subject "require the Node range the tree actually supports" is contradicted by it. CI only exercises Node 22, so the 14/16 leg is untested. Either raise the floor to >=18 or downgrade jsdom.

  • src/utils/utils.ts:497-506 - checkNodeVersion() is dead code with a stale floor: it is exported and exercised only by its own spec (src/utils/spec/utils.spec.ts:233-259), never called from the CLI entry, and still enforces the pre-PR >=12 floor while the package.json "checkNodeVersion" script enforces the new range - two gates with different truths. Remove the function and its spec block, or make it the single runtime gate by calling it from src/cli.ts with the range updated.

  • package.json leftovers: @types/find 0.2.4 (line 101) and @types/lodash.groupby 4.6.9 (line 104) remain in devDependencies though neither find nor lodash.groupby is imported anywhere in src, and jwt-decode 3.1.2 (line 82) and lodash.groupby 4.6.0 (line 83) are declared in dependencies but unreferenced in src (the codebase imports lodash.uniqby, not groupby). tslib 2.8.1 (line 122) is referenced nowhere either (no importHelpers in tsconfig.json, no direct import). All five are candidates for a follow-up cleanup PR.

5 findings above for review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant