Repository navigation
build(deps): refresh rendering, desktop, and build dependencies - #279
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 29, 2026, 9:36 PM ET / September 30, 2026, 01:36 UTC (Revision 2). ClawSweeper reviewWhat this changesUpdates web rendering, Electron desktop, packaging, and build-tool dependencies; aligns pnpm pins across manifests, Dockerfiles, workflows, and docs; and regenerates the web assets embedded in the Go server. Merge readiness✅ Ready for maintainer review Current main and v0.6.0 still use the older dependencies, so this PR remains useful. The follow-up Docker change resolves the prior review’s image-build blocker, and the current head has a successful Docker Image check. No discrete patch defect or unresolved merge risk was found. Priority: P3 Review scores
Verification
How this fits togetherClickClack renders chat and artifact content in a Svelte web app bundled into its Go server. Electron packages the desktop app, while pnpm, Docker, and CI prepare and validate those outputs. flowchart LR
Content[Chat and artifact content] --> Web[Svelte web app]
Web --> Sanitizer[HTML sanitization]
Sanitizer --> Bundle[Web build]
Bundle --> Server[Go server assets]
Tooling[pnpm and CI] --> Bundle
Tooling --> Desktop[Electron desktop]
Desktop --> Installers[Desktop installers]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Retain frozen-lockfile validation and repeatable embedded-asset builds across the coordinated dependency update. Do we have a high-confidence way to reproduce the issue? Not applicable: this is a dependency refresh rather than a bug report. The earlier Docker failure was addressed, and the exact current head has a successful Docker Image check. Is this the best way to solve the issue? Yes. Updating the manifests, lockfile, build pins, and embedded assets together follows the repository’s existing build path. AGENTS.md: found, but no applicable review policy affected this item. Codex review notes: model internal, reasoning high; reviewed against 615ab2ef40cb. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
What Problem This Solves
ClickClack's rendering, desktop runtime, packaging, and build dependencies have newer patch/minor releases eligible under the existing 48-hour cooldown.
User Impact
Updates DOMPurify and the Electron 43 runtime with upstream fixes, refreshes build tooling, and regenerates the embedded web app. Node.js 24, macOS 12, and Go 1.26.6 minimums remain unchanged.
Why This Change Was Made
Update DOMPurify to 3.4.16, Vite to 8.3.1, its Svelte plugin to 7.3.1, Electron to 43.7.5, electron-builder to 26.17.0, Wrangler to 4.142.0, Node.js types to 26.6.3, and pnpm to 12.7.0. Keep the pnpm pin consistent across source docs, Docker builds, and workflows. pnpm 12.7 validates the complete workspace manifest set, so both Dockerfiles now stage the desktop and bot-example manifests before the frozen-lockfile install. Registry publication timestamps were checked before selecting versions; newer releases still inside the cooldown stay deferred.
Evidence
pnpm checkpassed, including 94 web utility tests, the Go suite, 31 FakeCo tests, 63 desktop contract tests, root/workspace typechecks, lint, and formatting.pnpm docs:siteand repeatedpnpm buildpassed. Updated embedded assets were copied directly from the build.ERR_PNPM_OUTDATED_LOCKFILEfor the missing bot-example manifest. With both missing manifests included, standard and Cloudflare Docker builds passed on a fresh AWS Crabbox lease. Frozen-lockfile enforcement stays enabled.