Skip to content

fix(deps): bump @sasjs/utils to 3.6.3 - #250

Merged
allanbowe merged 3 commits into
mainfrom
chore/drop-prepare-and-bump-utils
Oct 4, 2026
Merged

allanbowe merged 3 commits into
mainfrom
chore/drop-prepare-and-bump-utils

Conversation

@sasjs-dev

@sasjs-dev sasjs-dev Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @sasjs/utils to 3.6.4 and removes this package's prepare script.

Why 3.6.4 and not 3.6.3

3.6.3 broke this package's Build Package step:

node_modules/@sasjs/utils/input/readAndValidateInput.d.ts(1,21): error TS7016:
Could not find a declaration file for module 'prompts'.

3.6.3 had moved @types/prompts to devDependencies, but that declaration file is published and imports from prompts, so any consumer typechecking with skipLibCheck disabled fails. Fixed in sasjs/utils#270 and released as 3.6.4 - which also carries 3.6.3's removal of the install-time script and the redundant dependencies.

This package pins @sasjs/utils directly, so it installs its own nested copy that the CLI's bump cannot reach. It has to be fixed here.

Verified

  • npm run build: clean (this was the failing step)
  • npm test: 45 suites, 399 tests passed
  • npm audit --omit=dev: 0 vulnerabilities

Picks up the Logger.warn fix, and drops the install-time script and redundant
dependencies that 3.6.2 carried. Also removes this package's own `prepare`
script, which ran `git config core.hooksPath ./.git-hooks` on every install.
@sasjs-dev
sasjs-dev Bot force-pushed the chore/drop-prepare-and-bump-utils branch from f001e42 to e510a66 Compare October 4, 2026 11:31

@sasjs-dev sasjs-dev Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the full base...head diff at the current head e510a66 (the PR was rebased from f001e42, so this covers the rebased head rather than the queued sha): the @sasjs/utils 3.6.2 -> 3.6.3 bump in package.json:73 with its lockfile changes, plus the prepare script removal.

  • CI is red at this head: the Build Package step fails in both check runs with node_modules/@sasjs/utils/input/readAndValidateInput.d.ts(1,21): error TS7016: Could not find a declaration file for module 'prompts' (tsc exit code 2). The cause is the bump itself: @sasjs/utils 3.6.3 dropped @types/prompts from its dependencies (package-lock.json:1710 - the utils dependency list no longer carries "@types/prompts": "2.0.13", and the node_modules/@types/prompts entry is deleted), while its shipped readAndValidateInput.d.ts still imports 'prompts', so tsc cannot type-check the d.ts chain. Hold at 3.6.2 until @sasjs/utils re-ships the types, or add an exactly-pinned @types/prompts devDependency so the build resolves.

  • package.json:4-5 - "node": ">=14" no longer matches the tree the lockfile pins: the bump resolves consola 3.4.2 (package-lock.json:2669), which declares node: ^14.18.0 || >=16.10.0, so Node 14.0-14.17 and all of 15.x fall outside a shipped transitive's requirement. Raise engines.node to at least ^14.18.0 || >=16.10.0 and align the >=14 floor enforced by checkNodeVersion.js with it.

2 findings above for review.

sasjs added 2 commits October 4, 2026 12:11
3.6.3 moved @types/prompts to devDependencies, and input/readAndValidateInput.d.ts
is published and imports from 'prompts', so typechecking against it failed with
TS7016 - which is what broke this package's Build Package step. 3.6.4 declares
@types/prompts as a dependency again.

Also removes this package's own `prepare` script, which ran
`git config core.hooksPath ./.git-hooks` on every install.
engines.node said >=14, but this package resolves consola 3.4.2 through
@sasjs/utils, and consola declares ^14.18.0 || >=16.10.0. A major-only floor
therefore admits versions whose own dependencies reject them: 14.0-14.17 and
every 15.x.

engines.node now states ^14.18.0 || >=16.10.0, and checkNodeVersion.js enforces
the same range rather than a bare `parseInt(node) < 14`, so the runtime check and
the published manifest cannot drift apart.
@sasjs-dev

sasjs-dev Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Both addressed - the first was already fixed before your review landed, the second was a real find.

Finding 1 - TS7016 on the 3.6.3 bump

Correct, and it was the bump itself. Your review is against e510a66; the head has since moved to 043de3e and now pins 3.6.4, which restores @types/prompts as a dependency of @sasjs/utils (sasjs/utils#270, released 12:06Z).

I did not take the devDependency workaround you suggested, because it fixes this package and leaves every other consumer broken. The published input/readAndValidateInput.d.ts imports from prompts, so the types belong in @sasjs/utils's dependencies - which is the rule @types/fs-extra already follows in that package.

npm run build    exit=0      (was: TS7016, tsc exit 2)
npm test         45 suites, 399 tests passed

Finding 2 - engines.node vs the tree

A genuine find, and it is wider than this repo. consola@3.4.2 declares ^14.18.0 || >=16.10.0, and this package resolves it through @sasjs/utils, so >=14 admitted 14.0-14.17 and all of 15.x - versions whose own dependencies reject them.

043de3e raises engines.node to ^14.18.0 || >=16.10.0 and makes checkNodeVersion.js enforce that range rather than a bare parseInt(node) < 14, so the manifest and the runtime check cannot drift. Verified across the boundaries:

14.0.0 false   14.17.9 false   14.18.0 true   14.21.3 true
15.0.0 false   15.14.0 false
16.0.0 false   16.9.9  false   16.10.0 true   16.20.2 true
17.0.0 true    18.19.0 true    20.11.0 true   22.11.0 true

@sasjs/cli declares the same >=14 and resolves the same consola, so it gets the same fix in its own PR.

@allanbowe
allanbowe merged commit 609695b into main Oct 4, 2026
2 checks passed
@allanbowe
allanbowe deleted the chore/drop-prepare-and-bump-utils branch October 4, 2026 12:25
@sasjs-gha

sasjs-gha Bot commented Oct 4, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 4.1.2 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

@sasjs-gha sasjs-gha Bot added the released label Oct 4, 2026
sasjs-dev Bot pushed a commit to sasjs/cli that referenced this pull request Oct 4, 2026
The three @sasjs runtime dependencies now track the released versions:

    @sasjs/adapter  4.19.1 -> 4.19.2   install script and redundant `https` removed
    @sasjs/core     5.2.10 -> 5.3.0
    @sasjs/utils    3.6.2  -> 3.6.4    (already in this branch)

4.19.2 is the release that carried the adapter cleanup that had been sitting on
master unreleased, because those merges used merge commits and semantic-release
only reads the first-parent chain.

@sasjs/lint stays at 4.1.1 until sasjs/lint#250 releases.
allanbowe pushed a commit to sasjs/cli that referenced this pull request Oct 4, 2026
* fix(deps): bump @sasjs/utils to 3.6.3

Picks up the Logger.warn fix - falsy arguments were passed straight to consola
while every other log method dropped them - and drops the install-time script
and the redundant dependencies that 3.6.2 carried.

Also removes this package's own `prepare` script, which ran
`git config core.hooksPath ./.git-hooks` on every install, and the `find`
dependency, which has no call site in src.

* fix(deps): bump @sasjs/utils to 3.6.4

3.6.4 restores @types/prompts as a dependency, and 3.6.3 dropped the
install-time script and the redundant dependencies that 3.6.2 carried.

Also removes this package's own `prepare` script, which ran
`git config core.hooksPath ./.git-hooks` on every install, and the `find`
dependency, which has no call site in src.

* fix(engines): require the Node range the tree actually supports

engines.node said >=14, but this package resolves consola 3.4.2 through
@sasjs/utils, and consola declares ^14.18.0 || >=16.10.0. A major-only floor
admits versions whose own dependencies reject them: 14.0-14.17 and every 15.x.

engines.node now states ^14.18.0 || >=16.10.0, and the checkNodeVersion script
enforces the same range rather than a bare `parseInt(node) < 14`, so the two
cannot drift apart.

* fix(deps): bump @sasjs/adapter and @sasjs/core to their latest

The three @sasjs runtime dependencies now track the released versions:

    @sasjs/adapter  4.19.1 -> 4.19.2   install script and redundant `https` removed
    @sasjs/core     5.2.10 -> 5.3.0
    @sasjs/utils    3.6.2  -> 3.6.4    (already in this branch)

4.19.2 is the release that carried the adapter cleanup that had been sitting on
master unreleased, because those merges used merge commits and semantic-release
only reads the first-parent chain.

@sasjs/lint stays at 4.1.1 until sasjs/lint#250 releases.

* fix(deps): bump @sasjs/lint to 4.1.2, and declare @types/prompts

@sasjs/lint 4.1.2 carries the engines fix (^14.18.0 || >=16.10.0) and the
prepare-script removal, so all four @sasjs dependencies now track the released
versions: adapter 4.19.2, core 5.3.0, lint 4.1.2, utils 3.6.4.

@types/prompts is added as a devDependency because this package's own source
imports 'prompts' (src/commands/auth/login.ts and its spec). It previously
resolved only by accident: @types/prompts is a dependency of @sasjs/utils, and
npm hoisted it to the root on some installs and nested it under utils on others.
TypeScript only auto-resolves @types from the root, so when it nested, the build
failed:

  src/commands/auth/login.ts(1,21): error TS7016: Could not find a declaration
  file for module 'prompts'.

Depending on where another package's transitive types land is not a contract;
this package imports prompts, so it declares the types.

---------

Co-authored-by: sasjs <sasjs@4gl.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant