chore(deps): bump npm dependencies across the workspace

Consolidates dependabot #2, #3, #5 and #6 into one changeset so the
workspace resolves against a single lockfile instead of four that each
assume they land first.

Majors:
  typescript           5.9.3  -> 6.0.3
  vite                 7.3.6  -> 8.2.1
  @vitejs/plugin-react 5.2.0  -> 6.0.5

Minor/patch (the npm-minor-patch group): @anthropic-ai/claude-agent-sdk,
@openai/codex-sdk, @opencode-ai/sdk, @tanstack/react-router,
@tanstack/react-start, @tanstack/router-cli, @biomejs/biome,
@commitlint/{cli,config-conventional}, turbo, ultracite, bippy, ws,
happy-dom and @fontsource{,-variable}.

TypeScript 6 turned the deprecated `baseUrl` into a hard error, which
breaks every tsup `--dts` build in the workspace. No tsconfig here sets
that option — tsup injects `baseUrl: compilerOptions.baseUrl || "."`
into its dts compiler options unconditionally, so the option we are
being warned about is one we never asked for. tsconfig.base.json now
sets `ignoreDeprecations: "6.0"`, TypeScript's own sanctioned escape
hatch and valid through 6.x, and it should come back out once tsup
stops injecting the option.

Rebasing onto the merged @types/node 26 bump surfaced a second problem.
esbuild 0.28.2 and its ~25 per-platform binary packages were published
minutes apart on 2026-08-08, so all of them sit inside pnpm's default
minimumReleaseAge window. Re-resolving the lockfile kept the parent and
dropped every platform package, because optional dependencies that fail
resolution are silently skipped rather than raising. That leaves an
esbuild with no binary behind it, and its postinstall then picks a
different version off the hoist path and fails:

    Error: Expected "0.28.2" but got "0.27.7"

main does not hit this only because dependabot resolves lockfiles with
its own resolver, which the gate does not apply to. pnpm-workspace.yaml
now excludes esbuild and its platform packages, matching how the SDKs,
turbo and ultracite are already handled there.
This commit is contained in:
Nayan
2026-08-11 05:35:44 +05:30
parent 24215ecbf9
commit 26b270c5a4
12 changed files with 802 additions and 1212 deletions
+5 -5
View File
@@ -36,17 +36,17 @@
"typecheck": "tsc --noEmit"
},
"dependencies": {
"@anthropic-ai/claude-agent-sdk": "^0.3.196",
"@anthropic-ai/claude-agent-sdk": "^0.3.224",
"@clack/prompts": "^1.7.0",
"@jridgewell/trace-mapping": "^0.3.31",
"@openai/codex-sdk": "^0.146.0",
"@opencode-ai/sdk": "^1.18.13",
"bippy": "^0.5.32",
"@openai/codex-sdk": "^0.147.0",
"@opencode-ai/sdk": "^1.18.15",
"bippy": "^0.6.1",
"citty": "^0.2.2",
"diff": "^9.0.0",
"element-source": "^0.0.5",
"picocolors": "^1.1.1",
"ws": "^8.21.0",
"ws": "^8.21.3",
"zod": "^4.0.0"
},
"devDependencies": {
+6 -6
View File
@@ -16,21 +16,21 @@
},
"dependencies": {
"@airship/site-tokens": "workspace:*",
"@tanstack/react-router": "^1.170.0",
"@tanstack/react-start": "^1.168.0",
"@tanstack/react-router": "^1.170.23",
"@tanstack/react-start": "^1.168.40",
"react": "19.2.8",
"react-dom": "19.2.8"
},
"devDependencies": {
"@tailwindcss/vite": "^4.3.0",
"@tanstack/router-cli": "^1.167.0",
"@tanstack/router-cli": "^1.167.25",
"@types/react": "^19.2.0",
"@types/react-dom": "^19.2.0",
"@vitejs/plugin-react": "^5.2.0",
"@vitejs/plugin-react": "^6.0.5",
"playwright": "^1.62.1",
"tailwindcss": "^4.3.0",
"typescript": "^5.7.0",
"vite": "^7.3.0",
"typescript": "^6.0.3",
"vite": "^8.2.1",
"wrangler": "^4.42.0"
}
}
+6 -6
View File
@@ -21,16 +21,16 @@
"typecheck": "turbo run typecheck"
},
"devDependencies": {
"@biomejs/biome": "^2.5.6",
"@commitlint/cli": "^21.1.0",
"@commitlint/config-conventional": "^21.1.0",
"@biomejs/biome": "^2.5.7",
"@commitlint/cli": "^21.2.1",
"@commitlint/config-conventional": "^21.2.0",
"@types/node": "^26.2.0",
"czg": "^1.13.1",
"husky": "^9.1.7",
"tsup": "^8.5.0",
"turbo": "^2.10.1",
"typescript": "^5.7.0",
"ultracite": "^7.10.0",
"turbo": "^2.10.9",
"typescript": "^6.0.3",
"ultracite": "^7.10.1",
"vitest": "^4.1.10"
},
"packageManager": "pnpm@11.9.0",
+3 -3
View File
@@ -21,9 +21,9 @@
"dependencies": {
"@airship/git": "workspace:*",
"@airship/protocol": "workspace:*",
"@anthropic-ai/claude-agent-sdk": "^0.3.196",
"@openai/codex-sdk": "^0.146.0",
"@opencode-ai/sdk": "^1.18.13",
"@anthropic-ai/claude-agent-sdk": "^0.3.224",
"@openai/codex-sdk": "^0.147.0",
"@opencode-ai/sdk": "^1.18.15",
"diff": "^9.0.0",
"zod": "^4.0.0"
},
+2 -2
View File
@@ -25,8 +25,8 @@
"typecheck": "tsc --noEmit"
},
"devDependencies": {
"@fontsource-variable/inter": "^5.1.1",
"@fontsource/jetbrains-mono": "^5.1.1",
"@fontsource-variable/inter": "^5.3.0",
"@fontsource/jetbrains-mono": "^5.3.0",
"yaml": "^2.6.1"
}
}
+3 -3
View File
@@ -26,7 +26,7 @@
"@dnd-kit/abstract": "0.5.0",
"@dnd-kit/dom": "0.5.0",
"@dnd-kit/geometry": "0.5.0",
"bippy": "^0.5.32"
"bippy": "^0.6.1"
},
"devDependencies": {
"@storybook/addon-a11y": "10.5.7",
@@ -34,10 +34,10 @@
"@storybook/html-vite": "10.5.7",
"@vitest/browser": "^4.1.10",
"@vitest/browser-playwright": "^4.1.10",
"happy-dom": "^20.11.1",
"happy-dom": "^20.11.2",
"playwright": "^1.62.1",
"storybook": "10.5.7",
"vite": "^7.3.6",
"vite": "^8.2.1",
"vitest": "^4.1.10"
}
}
+1 -1
View File
@@ -25,7 +25,7 @@
"@airship/overlay": "workspace:*",
"@airship/protocol": "workspace:*",
"@airship/source": "workspace:*",
"ws": "^8.21.0"
"ws": "^8.21.3"
},
"devDependencies": {
"@types/node": "^26.2.0",
+2 -2
View File
@@ -28,8 +28,8 @@
"@airship/editor-tokens": "workspace:*"
},
"devDependencies": {
"@fontsource-variable/inter": "^5.1.1",
"@fontsource/jetbrains-mono": "^5.1.1",
"@fontsource-variable/inter": "^5.3.0",
"@fontsource/jetbrains-mono": "^5.3.0",
"yaml": "^2.6.1"
}
}
+1 -1
View File
@@ -27,7 +27,7 @@
"dependencies": {
"@airship/protocol": "workspace:*",
"@jridgewell/trace-mapping": "^0.3.31",
"bippy": "^0.5.32",
"bippy": "^0.6.1",
"element-source": "^0.0.5"
},
"devDependencies": {
+753 -1183
View File
File diff suppressed because it is too large Load Diff
+14
View File
@@ -12,6 +12,20 @@ allowBuilds:
# `make web:preview` and the deploy lane need it to have run its install step.
workerd: true
minimumReleaseAgeExclude:
# esbuild ships its binary as ~25 per-platform packages listed as OPTIONAL
# dependencies, published minutes apart from the parent. When the parent is
# old enough to pass the release-age gate but the platform packages are not,
# pnpm drops them silently — optional deps that fail resolution are not an
# error — and installs an esbuild with no binary behind it. The postinstall
# then finds a different version's binary on the hoist path and fails with
# `Expected "0.28.2" but got "0.27.7"`.
#
# The parent is pinned; the platform packages cannot be, because pnpm rejects
# a name pattern carrying a version union and enumerating all 25 for every
# bump is not maintainable. They only ever publish in lockstep with the
# version above, so the unpinned glob follows whatever it is pinned to.
- 'esbuild@0.28.2'
- '@esbuild/*'
- '@anthropic-ai/claude-agent-sdk-darwin-arm64@0.3.196'
- '@anthropic-ai/claude-agent-sdk-darwin-x64@0.3.196'
- '@anthropic-ai/claude-agent-sdk-linux-arm64-musl@0.3.196'
+6
View File
@@ -12,6 +12,12 @@
"esModuleInterop": true,
"resolveJsonModule": true,
"skipLibCheck": true,
// tsup's .d.ts build injects `baseUrl: "."` unconditionally (see
// tsup/dist/rollup.js — `baseUrl: compilerOptions.baseUrl || "."`), and
// TypeScript 6 made the deprecated option a hard error. Nothing here sets
// baseUrl, so this only silences tsup's own injection. Drop it once tsup
// ships a build that stops setting it — it stops working in TypeScript 7.
"ignoreDeprecations": "6.0",
"declaration": true,
"declarationMap": true,
"sourceMap": true,