chore(deps): update dependencies - #40
Conversation
Bump direct dependencies to latest stable versions within their current major lines: couchbase 4.7.1, express 4.22.3, yaml 2.9.1, Babel 7.29.7, prettier 3.9.9, supertest 7.3.0, ts-jest 29.4.14. Hermes task: t_9818fb19 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
CI note: every check that runs on this PR passed (CodeQL, plus Analyze for javascript-typescript and for actions). The repo's |
|
@dex-the-ai I enabled the workflow. Can you take another pass at the major deps you left out though. I'd like to knock out as many of those as possible if we can do so safely. Feel free to include any changes and migrations needed to enable us to use those newer versions. |
Move to the current majors that can be adopted safely: express 5.2.1
(@types/express 5.0.6), jest 30.5.2 (@jest/globals, @types/jest 30),
typescript 6.0.3, env-cmd 11.0.0 and @types/supertest 7.2.1.
Migrations:
- Express 5 / path-to-regexp 8: the bare '*' catch-all becomes
'/{*splat}'. The :id handlers are typed as Request<{ id: string }>
because Express 5 types params as string | string[].
- TypeScript 6: moduleResolution "node" (node10) is deprecated, so the
project uses module/moduleResolution "node16". ts-jest requires
isolatedModules with node16, which in turn needs an explicit rootDir
and `export type` for the model type re-exports.
- Remove the unused Babel toolchain (@babel/* and .babelrc). Nothing
invokes it (ts-node and ts-jest compile the TypeScript), and Babel 8
can't be hoisted next to Jest 30's Babel 7 internals without invalid
peer dependencies.
TypeScript 7 is left out because it ships no compiler API yet, and
ts-jest 29.4.14 declares typescript >=4.3 <7.
Hermes task: t_ecedb34a
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@ejscribner Thanks for enabling the workflow. I went back through the majors and pushed Now included
Still held back: TypeScript 7.0.2. It's the native Go compiler and doesn't ship the JS compiler API yet (only Verification
This PR now also supersedes Dependabot #28 (express 5) and #36 (@babel/cli 8), as well as #37. I haven't closed any of them, so you can close them when you merge. |
Summary
This PR updates the direct npm dependencies. It started as a within-major sweep (commit
2bcbb7a). After review it also takes every major upgrade that can be adopted safely today, with the code and config migrations those upgrades need (commitf68b34d). One major is still held back (TypeScript 7), for the reason given below.Hermes tasks:
t_9818fb19(initial sweep) andt_ecedb34a(major follow-up, requested in this comment). Board:couchbase-examples.Updated dependencies
-fflag is unchanged, sonpm startandnpm testwork as beforeMigrations
*route is no longer valid, so the 404 catch-all insrc/app.tsbecomesapp.get('/{*splat}', ...), which keeps it GET-only.@types/express5 typesreq.paramsvalues asstring | string[], so the:idhandlers in the three controllers are now typedRequest<{ id: string }>. Nothing else was needed: the handlers don't reassignreq.query,express.urlencodedalready passesextended: trueexplicitly, and responses go throughres.json/res.status.moduleResolution: "node"(node10) is deprecated and is an error in TS 6, sotsconfig.jsonnow usesmodule/moduleResolution"node16". The emitted code is still CommonJS, becausepackage.jsonhas no"type": "module". With node16, ts-jest requiresisolatedModules: true. That in turn needs an explicitrootDir: "./"(TS 6 no longer infers it whenoutDiris set) andexport type { ... }for the three model type re-exports..babelrc:npm startuses ts-node, and Jest uses ts-jest. They were left over from the initial commit. Babel 8 also can't be installed cleanly next to Jest 30, whose internals still use Babel 7 syntax plugins with@babel/core ^7peers. Hoisting Babel 8 producedinvalidpeer entries innpm ls, so removing the unused toolchain is the clean option. If you'd rather keep Babel for anything outside this repo, say so and I'll restore it on 7.x.Still held back
unstable/*API entry points, with notypescriptcompiler API, and ts-jest 29.4.14 declarestypescript >=4.3 <7. ts-node and ts-jest can't run on it yet. TS 6 is the latest line the toolchain supports.Overlapping Dependabot PRs
Validation
npm installon Node v24.21.0 / npm 11.19.0 (the CI Node version) and on Node v22.23.1:npm ls --allshows no invalid or unmet non-optional peers.npx tsc --noEmit -p .passed on TypeScript 6.0.3.npm test(env-cmd 11 withconfig/test.env, Jest 30 against Capellatravel-sample): 16/16 suites, 16/16 tests passed. It was run 7 times across Node 22 and 24. One early Node 22 run had a single failure that I couldn't reproduce in 6 later full runs. I didn't capture which test it was, and it looked like transient network latency to Capella.npm run testGA(the CI command, env exported) on Node 24: 16/16 passed.Type Script Testsonf68b34d: passed, 16/16.npm start(env-cmd 11 + ts-node on TS 6) started the API. Checks against Express 5 (the last two exercise the new catch-all):/→ 200/swagger-ui→ 301 to/swagger-ui/, which returns 200GET /api/v1/airline/list?country=France&limit=2→ 200GET /api/v1/airline/airline_10→ 200{"message":"document not found"}/nope/deep/path→ 404Not FoundPOST /nope→ 404GET /api/v1/airline/listreturned 200 with live data.The local
config/test.envandconfig/dev.envfiles were created from machine credentials for this run only. Both are gitignored and not committed.Evidence
/swagger-ui/on Express 5GET /api/v1/airline/list?country=France&limit=5&offset=0via Swagger "Try it out"Type Script TestsSwagger UI
Swagger "Try it out" response
Walkthrough video
Open the Swagger walkthrough
Risk notes
:id, and the catch-all was the only incompatible pattern. The full CRUD integration suite and the live curl/Swagger checks all passed on it.tsconfig.jsonchange fromcommonjs/nodetonode16/node16still emits CommonJS for this package. If the tutorial later adds"type": "module", relative imports will need file extensions.npm auditwent from 7 transitive advisories to 4:tar(critical, via couchbase > cmake-js),browserslist(high),qsandbaseline-browser-mapping(moderate). None comes from a direct dependency version in this PR, andnpm audit fix --forcewas not used.Rollback
Revert
f68b34dto return to the within-major update only, or revert the whole PR to restore the previouspackage.json,package-lock.json,tsconfig.jsonand.babelrc.🤖 Generated with Claude Code