Consolidates dependabot #2, #3, #5 and #6 into one changeset so the workspace resolves against a single lockfile instead of four that each assume they land first. Majors: typescript 5.9.3 -> 6.0.3 vite 7.3.6 -> 8.2.1 @vitejs/plugin-react 5.2.0 -> 6.0.5 Minor/patch (the npm-minor-patch group): @anthropic-ai/claude-agent-sdk, @openai/codex-sdk, @opencode-ai/sdk, @tanstack/react-router, @tanstack/react-start, @tanstack/router-cli, @biomejs/biome, @commitlint/{cli,config-conventional}, turbo, ultracite, bippy, ws, happy-dom and @fontsource{,-variable}. TypeScript 6 turned the deprecated `baseUrl` into a hard error, which breaks every tsup `--dts` build in the workspace. No tsconfig here sets that option — tsup injects `baseUrl: compilerOptions.baseUrl || "."` into its dts compiler options unconditionally, so the option we are being warned about is one we never asked for. tsconfig.base.json now sets `ignoreDeprecations: "6.0"`, TypeScript's own sanctioned escape hatch and valid through 6.x, and it should come back out once tsup stops injecting the option. Rebasing onto the merged @types/node 26 bump surfaced a second problem. esbuild 0.28.2 and its ~25 per-platform binary packages were published minutes apart on 2026-08-08, so all of them sit inside pnpm's default minimumReleaseAge window. Re-resolving the lockfile kept the parent and dropped every platform package, because optional dependencies that fail resolution are silently skipped rather than raising. That leaves an esbuild with no binary behind it, and its postinstall then picks a different version off the hoist path and fails: Error: Expected "0.28.2" but got "0.27.7" main does not hit this only because dependabot resolves lockfiles with its own resolver, which the gate does not apply to. pnpm-workspace.yaml now excludes esbuild and its platform packages, matching how the SDKs, turbo and ultracite are already handled there.
52 lines
2.6 KiB
YAML
52 lines
2.6 KiB
YAML
packages:
|
|
- "packages/*"
|
|
- "apps/*"
|
|
# apps/web is both airship's home page and the app `make run` points the CLI at.
|
|
# It lives inside this workspace — unlike the standalone home/ and examples/
|
|
# trees it replaces, each of which carried its own lockfile and node_modules.
|
|
# One lockfile, one install, one lint pass; the cost is that React, Vite and
|
|
# Tailwind are now root dependencies. See README.md § The site.
|
|
allowBuilds:
|
|
esbuild: true
|
|
# wrangler's runtime. apps/web deploys to Cloudflare Workers, and both
|
|
# `make web:preview` and the deploy lane need it to have run its install step.
|
|
workerd: true
|
|
minimumReleaseAgeExclude:
|
|
# esbuild ships its binary as ~25 per-platform packages listed as OPTIONAL
|
|
# dependencies, published minutes apart from the parent. When the parent is
|
|
# old enough to pass the release-age gate but the platform packages are not,
|
|
# pnpm drops them silently — optional deps that fail resolution are not an
|
|
# error — and installs an esbuild with no binary behind it. The postinstall
|
|
# then finds a different version's binary on the hoist path and fails with
|
|
# `Expected "0.28.2" but got "0.27.7"`.
|
|
#
|
|
# The parent is pinned; the platform packages cannot be, because pnpm rejects
|
|
# a name pattern carrying a version union and enumerating all 25 for every
|
|
# bump is not maintainable. They only ever publish in lockstep with the
|
|
# version above, so the unpinned glob follows whatever it is pinned to.
|
|
- 'esbuild@0.28.2'
|
|
- '@esbuild/*'
|
|
- '@anthropic-ai/claude-agent-sdk-darwin-arm64@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk-darwin-x64@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk-linux-arm64-musl@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk-linux-arm64@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk-linux-x64-musl@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk-linux-x64@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk-win32-arm64@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk-win32-x64@0.3.196'
|
|
- '@anthropic-ai/claude-agent-sdk@0.3.196'
|
|
- '@openai/codex-sdk@0.146.0'
|
|
# Unlike the other two SDKs this bundles no binary — the `opencode` CLI is a
|
|
# separate install, detected on PATH at runtime. See providers/opencode.ts.
|
|
- '@opencode-ai/sdk@1.18.13'
|
|
- '@openai/codex@0.146.0-darwin-arm64 || 0.146.0-darwin-x64 || 0.146.0-linux-arm64 || 0.146.0-linux-x64 || 0.146.0-win32-arm64 || 0.146.0-win32-x64 || 0.146.0'
|
|
- '@turbo/darwin-64@2.10.1'
|
|
- '@turbo/darwin-arm64@2.10.1'
|
|
- '@turbo/linux-64@2.10.1'
|
|
- '@turbo/linux-arm64@2.10.1'
|
|
- '@turbo/windows-64@2.10.1'
|
|
- '@turbo/windows-arm64@2.10.1'
|
|
- turbo@2.10.1
|
|
- ultracite@7.10.0
|
|
- '@opencode-ai/sdk@1.18.13'
|