Skip to content

chore(deps): update dependencies - #40

Merged
ejscribner merged 2 commits into
mainfrom
chore/dependency-update-20260929-t_9818fb19
Sep 30, 2026
Merged

ejscribner merged 2 commits into
mainfrom
chore/dependency-update-20260929-t_9818fb19

Conversation

@dex-the-ai

@dex-the-ai dex-the-ai commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR updates the direct npm dependencies. It started as a within-major sweep (commit 2bcbb7a). After review it also takes every major upgrade that can be adopted safely today, with the code and config migrations those upgrades need (commit f68b34d). One major is still held back (TypeScript 7), for the reason given below.

Hermes tasks: t_9818fb19 (initial sweep) and t_ecedb34a (major follow-up, requested in this comment). Board: couchbase-examples.

Updated dependencies

Ecosystem Dependency Previous Updated Type Notes
npm couchbase 4.7.0 4.7.1 dependency Patch release, still pinned to an exact version
npm express ^4.22.2 ^5.2.1 dependency Major, see the migration notes
npm yaml ^2.9.0 ^2.9.1 dependency Patch release
npm @types/express ^4.17.25 ^5.0.6 devDependency Major, matches Express 5
npm jest ^29.7.0 ^30.5.2 devDependency Major
npm @jest/globals ^29.7.0 ^30.5.2 devDependency Major, matches Jest 30
npm @types/jest ^29.5.14 ^30.0.0 devDependency Major, matches Jest 30
npm typescript ^5.9.3 ^6.0.3 devDependency Major, see the migration notes
npm env-cmd ^10.1.0 ^11.0.0 devDependency Major. The -f flag is unchanged, so npm start and npm test work as before
npm @types/supertest ^6.0.3 ^7.2.1 devDependency Major, types only
npm prettier ^3.8.4 ^3.9.9 devDependency Minor release, same target as #37
npm supertest ^7.2.2 ^7.3.0 devDependency Minor release
npm ts-jest ^29.4.11 ^29.4.14 devDependency Patch release. 29.4.x already supports Jest 30
npm @babel/cli, @babel/core, @babel/node, @babel/plugin-transform-runtime, @babel/preset-env ^7.x removed devDependency Unused, see below

Migrations

  • Express 5 (path-to-regexp 8). A bare * route is no longer valid, so the 404 catch-all in src/app.ts becomes app.get('/{*splat}', ...), which keeps it GET-only. @types/express 5 types req.params values as string | string[], so the :id handlers in the three controllers are now typed Request<{ id: string }>. Nothing else was needed: the handlers don't reassign req.query, express.urlencoded already passes extended: true explicitly, and responses go through res.json/res.status.
  • TypeScript 6. moduleResolution: "node" (node10) is deprecated and is an error in TS 6, so tsconfig.json now uses module/moduleResolution "node16". The emitted code is still CommonJS, because package.json has no "type": "module". With node16, ts-jest requires isolatedModules: true. That in turn needs an explicit rootDir: "./" (TS 6 no longer infers it when outDir is set) and export type { ... } for the three model type re-exports.
  • Babel removed. No script, config or test ever ran the Babel packages or .babelrc: npm start uses ts-node, and Jest uses ts-jest. They were left over from the initial commit. Babel 8 also can't be installed cleanly next to Jest 30, whose internals still use Babel 7 syntax plugins with @babel/core ^7 peers. Hoisting Babel 8 produced invalid peer entries in npm ls, so removing the unused toolchain is the clean option. If you'd rather keep Babel for anything outside this repo, say so and I'll restore it on 7.x.

Still held back

Dependency Current Latest Reason
typescript 6.0.3 7.0.2 TypeScript 7 is the native (Go) compiler. The package only exposes unstable/* API entry points, with no typescript compiler API, and ts-jest 29.4.14 declares typescript >=4.3 <7. ts-node and ts-jest can't run on it yet. TS 6 is the latest line the toolchain supports.

Overlapping Dependabot PRs

Validation

  • npm install on Node v24.21.0 / npm 11.19.0 (the CI Node version) and on Node v22.23.1: npm ls --all shows no invalid or unmet non-optional peers.
  • npx tsc --noEmit -p . passed on TypeScript 6.0.3.
  • npm test (env-cmd 11 with config/test.env, Jest 30 against Capella travel-sample): 16/16 suites, 16/16 tests passed. It was run 7 times across Node 22 and 24. One early Node 22 run had a single failure that I couldn't reproduce in 6 later full runs. I didn't capture which test it was, and it looked like transient network latency to Capella.
  • npm run testGA (the CI command, env exported) on Node 24: 16/16 passed.
  • GitHub Actions Type Script Tests on f68b34d: passed, 16/16.
  • npm start (env-cmd 11 + ts-node on TS 6) started the API. Checks against Express 5 (the last two exercise the new catch-all):
    • / → 200
    • /swagger-ui → 301 to /swagger-ui/, which returns 200
    • GET /api/v1/airline/list?country=France&limit=2 → 200
    • GET /api/v1/airline/airline_10 → 200
    • a missing document id → 404 {"message":"document not found"}
    • /nope/deep/path → 404 Not Found
    • POST /nope → 404
  • Playwright walkthrough: Swagger "Try it out" on GET /api/v1/airline/list returned 200 with live data.
npm uninstall @babel/cli @babel/core @babel/node @babel/plugin-transform-runtime @babel/preset-env
git rm .babelrc
npm install express@^5.2.1
npm install -D @types/express@^5.0.6 jest@^30.5.2 @jest/globals@^30.5.2 @types/jest@^30.0.0 typescript@^6.0.3 env-cmd@^11.0.0 @types/supertest@^7.2.1
npx tsc --noEmit -p .
npm test
npm run testGA          # Node 24, CI env exported
npm start               # then curl checks + Playwright walkthrough of /swagger-ui/

The local config/test.env and config/dev.env files were created from machine credentials for this run only. Both are gitignored and not committed.

Evidence

Surface Status Artifact
Swagger UI /swagger-ui/ on Express 5 Captured screenshot
GET /api/v1/airline/list?country=France&limit=5&offset=0 via Swagger "Try it out" 200 with live Capella data screenshot
Walkthrough recording Captured video
CI Type Script Tests Passed, 16/16 run 36648969062

Swagger UI

Swagger overview

Swagger "Try it out" response

Swagger walkthrough

Walkthrough video

Open the Swagger walkthrough

Risk notes

  • Express 5 is the only runtime major. The tutorial's route surface is small: fixed paths plus :id, and the catch-all was the only incompatible pattern. The full CRUD integration suite and the live curl/Swagger checks all passed on it.
  • The other majors (Jest, TypeScript, env-cmd, type packages) only affect dev tooling.
  • The tsconfig.json change from commonjs/node to node16/node16 still emits CommonJS for this package. If the tutorial later adds "type": "module", relative imports will need file extensions.
  • npm audit went from 7 transitive advisories to 4: tar (critical, via couchbase > cmake-js), browserslist (high), qs and baseline-browser-mapping (moderate). None comes from a direct dependency version in this PR, and npm audit fix --force was not used.

Rollback

Revert f68b34d to return to the within-major update only, or revert the whole PR to restore the previous package.json, package-lock.json, tsconfig.json and .babelrc.

🤖 Generated with Claude Code

Bump direct dependencies to latest stable versions within their current
major lines: couchbase 4.7.1, express 4.22.3, yaml 2.9.1, Babel 7.29.7,
prettier 3.9.9, supertest 7.3.0, ts-jest 29.4.14.

Hermes task: t_9818fb19

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dex-the-ai

Copy link
Copy Markdown
Contributor Author

CI note: every check that runs on this PR passed (CodeQL, plus Analyze for javascript-typescript and for actions). The repo's Type Script Tests workflow (tests.yaml) did not run because GitHub has it in the disabled_inactivity state; its last run was the 2026-08-29 schedule on main. I ran the same steps locally on Node v24.21.0: npm install passed and npm run testGA passed 16/16 against Capella travel-sample. A maintainer can re-enable the workflow under Actions → Type Script Tests → Enable workflow if CI-side confirmation is wanted before merge.

@ejscribner

Copy link
Copy Markdown
Contributor

@dex-the-ai I enabled the workflow. Can you take another pass at the major deps you left out though. I'd like to knock out as many of those as possible if we can do so safely. Feel free to include any changes and migrations needed to enable us to use those newer versions.

Move to the current majors that can be adopted safely: express 5.2.1
(@types/express 5.0.6), jest 30.5.2 (@jest/globals, @types/jest 30),
typescript 6.0.3, env-cmd 11.0.0 and @types/supertest 7.2.1.

Migrations:
- Express 5 / path-to-regexp 8: the bare '*' catch-all becomes
  '/{*splat}'. The :id handlers are typed as Request<{ id: string }>
  because Express 5 types params as string | string[].
- TypeScript 6: moduleResolution "node" (node10) is deprecated, so the
  project uses module/moduleResolution "node16". ts-jest requires
  isolatedModules with node16, which in turn needs an explicit rootDir
  and `export type` for the model type re-exports.
- Remove the unused Babel toolchain (@babel/* and .babelrc). Nothing
  invokes it (ts-node and ts-jest compile the TypeScript), and Babel 8
  can't be hoisted next to Jest 30's Babel 7 internals without invalid
  peer dependencies.

TypeScript 7 is left out because it ships no compiler API yet, and
ts-jest 29.4.14 declares typescript >=4.3 <7.

Hermes task: t_ecedb34a

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dex-the-ai

Copy link
Copy Markdown
Contributor Author

@ejscribner Thanks for enabling the workflow. I went back through the majors and pushed f68b34d, which takes every one I could adopt safely. The one still held back is TypeScript 7.

Now included

  • express 5.2.1 / @types/express 5.0.6. Migration: the bare app.get('*') 404 catch-all isn't valid in path-to-regexp 8, so it's now app.get('/{*splat}'). The :id controller handlers are typed Request<{ id: string }>, because Express 5 types params as string | string[].
  • jest / @jest/globals / @types/jest 30. ts-jest 29.4.14 already supports Jest 30, so no ts-jest major was needed.
  • typescript 6.0.3. Migration: moduleResolution: "node" is now an error, so tsconfig.json uses node16/node16, which still emits CommonJS. ts-jest needs isolatedModules for that, and that in turn needs an explicit rootDir and export type on the three model re-exports.
  • env-cmd 11. -f still works, so no script changes.
  • @types/supertest 7.
  • Babel: removed instead of bumped. Nothing in the repo ran it (ts-node and ts-jest do all the compiling), and it was left over from the initial commit. Babel 8 also can't be installed cleanly next to Jest 30, whose internals still peer on @babel/core ^7, so a forced bump would have left invalid peers. If you want Babel kept for some other reason, tell me and I'll restore it on 7.x.

Still held back: TypeScript 7.0.2. It's the native Go compiler and doesn't ship the JS compiler API yet (only unstable/* entry points). ts-jest declares typescript >=4.3 <7, and ts-node needs the same API, so the test and start scripts can't run on it yet.

Verification

  • CI Type Script Tests (now enabled) passed 16/16 on f68b34d: https://github.com/couchbase-examples/typescript-quickstart/actions/runs/36648969062
  • Locally on Node 24.21.0: npx tsc --noEmit is clean, npm run testGA passed 16/16 and npm test passed 16/16.
  • Across 7 local runs on Node 22 and 24, one early run had a single failure that didn't come back in 6 later full runs. I didn't capture which test it was, and it looked like transient latency to Capella.
  • npm start on Express 5: Swagger, list, get-by-id and missing-doc 404 all behave as before, and unknown GET/POST paths still return 404 through the new catch-all. Screenshots and a walkthrough video are in the updated PR description.
  • npm audit went from 7 transitive advisories to 4 as a side effect.

This PR now also supersedes Dependabot #28 (express 5) and #36 (@babel/cli 8), as well as #37. I haven't closed any of them, so you can close them when you merge.

@ejscribner
ejscribner merged commit 2d44193 into main Sep 30, 2026
4 checks passed
@ejscribner
ejscribner deleted the chore/dependency-update-20260929-t_9818fb19 branch September 30, 2026 15:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants