Repository navigation
fix(deps): bump @sasjs/utils to 3.6.3 - #1476
Conversation
Picks up the Logger.warn fix - falsy arguments were passed straight to consola while every other log method dropped them - and drops the install-time script and the redundant dependencies that 3.6.2 carried. Also removes this package's own `prepare` script, which ran `git config core.hooksPath ./.git-hooks` on every install, and the `find` dependency, which has no call site in src.
Coverage reportTotal coverage
Show files with reduced coverage 🔻Reduced coverage
Report generated by 🧪jest coverage report action from 013d361 |
There was a problem hiding this comment.
Reviewed the base...head diff (package.json plus package-lock.json: @sasjs/utils 3.6.2 -> 3.6.3, the unused direct find dependency dropped, the dead prepare script removed).
- package.json:4-5 -
"node": ">=14"no longer matches the tree the lockfile pins: the bump resolves consola 3.4.2 (package-lock.json:4923), which declaresnode: ^14.18.0 || >=16.10.0, so Node 14.0-14.17 and all of 15.x fall outside a shipped transitive's requirement (jsdom 26.0.0, a pre-existing runtime dependency, already requires >=18). npm only warns today, but the declared floor should describe what installs: raise engines.node to >=18, or at least to ^14.18.0 || >=16.10.0, and align the >=12 floor enforced by checkNodeVersion() (src/utils/utils.ts:497-504) with it.
1 finding above for review.
3.6.4 restores @types/prompts as a dependency, and 3.6.3 dropped the install-time script and the redundant dependencies that 3.6.2 carried. Also removes this package's own `prepare` script, which ran `git config core.hooksPath ./.git-hooks` on every install, and the `find` dependency, which has no call site in src.
engines.node said >=14, but this package resolves consola 3.4.2 through @sasjs/utils, and consola declares ^14.18.0 || >=16.10.0. A major-only floor admits versions whose own dependencies reject them: 14.0-14.17 and every 15.x. engines.node now states ^14.18.0 || >=16.10.0, and the checkNodeVersion script enforces the same range rather than a bare `parseInt(node) < 14`, so the two cannot drift apart.
The three @sasjs runtime dependencies now track the released versions: @sasjs/adapter 4.19.1 -> 4.19.2 install script and redundant `https` removed @sasjs/core 5.2.10 -> 5.3.0 @sasjs/utils 3.6.2 -> 3.6.4 (already in this branch) 4.19.2 is the release that carried the adapter cleanup that had been sitting on master unreleased, because those merges used merge commits and semantic-release only reads the first-parent chain. @sasjs/lint stays at 4.1.1 until sasjs/lint#250 releases.
@sasjs/lint 4.1.2 carries the engines fix (^14.18.0 || >=16.10.0) and the prepare-script removal, so all four @sasjs dependencies now track the released versions: adapter 4.19.2, core 5.3.0, lint 4.1.2, utils 3.6.4. @types/prompts is added as a devDependency because this package's own source imports 'prompts' (src/commands/auth/login.ts and its spec). It previously resolved only by accident: @types/prompts is a dependency of @sasjs/utils, and npm hoisted it to the root on some installs and nested it under utils on others. TypeScript only auto-resolves @types from the root, so when it nested, the build failed: src/commands/auth/login.ts(1,21): error TS7016: Could not find a declaration file for module 'prompts'. Depending on where another package's transitive types land is not a contract; this package imports prompts, so it declares the types.
There was a problem hiding this comment.
Re-review at the head the PR reached before it was squash-merged to main (merge commit 1a6c483, subject from the PR title - see the title finding below). Three commits landed since the last review, including the final 013d361 (lint 4.1.2 + @types/prompts); the prior finding is addressed: engines.node is now "^14.18.0 || >=16.10.0" and the checkNodeVersion npm script enforces the same range. Manifest and lockfile moved together; the audit step is strict and the pipeline was green at the final head.
-
PR title - the repo squashes on merge (squash_merge_commit_title = COMMIT_OR_PR_TITLE) and semantic-release reads the squashed subject, but the title stayed "fix(deps): bump @sasjs/utils to 3.6.3" while the PR ultimately shipped utils 3.6.4, adapter 4.19.2, core 5.3.0, lint 4.1.2, the engines rewrite and the prepare-script removal - the merge commit now carries the stale subject, so the release note will describe one sub-bump and none of the rest. For the next bump round, update the title before merging, or merge with a corrected subject.
-
src/utils/utils.ts:7 and src/commands/run/run.ts:25 -
import axios from 'axios'is not declared in package.json dependencies; it resolves only through @sasjs/adapter's transitive pin (axios 1.20.0 in the lockfile). An adapter release that drops or re-versions axios breaks the CLI build with no signal. Declare axios in dependencies at the version the tree resolves. -
package.json:4-5 - the new engines range still does not describe the tree it ships: jsdom 26.0.0 is a direct runtime dependency (imported at src/commands/web/internal/updateSasjsTag.ts:2) and declares
engines: node >=18(package-lock.json), so installing on any Node 14/15/16 release the range admits now pulls a direct dependency that does not support it, and the commit subject "require the Node range the tree actually supports" is contradicted by it. CI only exercises Node 22, so the 14/16 leg is untested. Either raise the floor to >=18 or downgrade jsdom. -
src/utils/utils.ts:497-506 - checkNodeVersion() is dead code with a stale floor: it is exported and exercised only by its own spec (src/utils/spec/utils.spec.ts:233-259), never called from the CLI entry, and still enforces the pre-PR >=12 floor while the package.json "checkNodeVersion" script enforces the new range - two gates with different truths. Remove the function and its spec block, or make it the single runtime gate by calling it from src/cli.ts with the range updated.
-
package.json leftovers: @types/find 0.2.4 (line 101) and @types/lodash.groupby 4.6.9 (line 104) remain in devDependencies though neither
findnorlodash.groupbyis imported anywhere in src, and jwt-decode 3.1.2 (line 82) and lodash.groupby 4.6.0 (line 83) are declared in dependencies but unreferenced in src (the codebase imports lodash.uniqby, not groupby). tslib 2.8.1 (line 122) is referenced nowhere either (no importHelpers in tsconfig.json, no direct import). All five are candidates for a follow-up cleanup PR.
5 findings above for review.
All four
@sasjs/*dependencies now track their released versions.adapter 4.19.2is the release that carried the adapter cleanup which had been sitting on master unreleased - thepreparescript removal, the redundanthttpsremoval and the Dependabot removal - because those PRs merged with merge commits and semantic-release reads only the first-parent chain.lint 4.1.2carries the sameenginesfix as this PR.This package's own manifest
enginesmatches what the tree supports: this package resolvesconsola@3.4.2through@sasjs/utils, and consola declares^14.18.0 || >=16.10.0, so>=14admitted 14.0-14.17 and all of 15.x.checkNodeVersionenforces the same range.@types/promptsis a devDependency because this package's own source importsprompts(src/commands/auth/login.tsand its spec). It previously resolved only by accident -@types/promptsis a dependency of@sasjs/utils, and npm hoisted it to the root on some installs and nested it under utils on others. TypeScript only auto-resolves@typesfrom the root, so when it nested the build failed:Depending on where another package's transitive types happen to land is not a contract.
Verified
npm run build: exit 0, 0 TS errors (checked without a pipe, so the exit code is the build's)printVersion, which needs a globally installed@sasjs/cliand fails identically onmainnpm audit --omit=dev: 0 vulnerabilitiesnpx npm@10 install, matching what CI runsMerge with squash or rebase
A merge commit's
Merge pull request #NNNsubject is invisible to semantic-release, which walks only the first-parent chain.