Skip to content

build(deps): refresh rendering, desktop, and build dependencies - #279

Merged
steipete merged 2 commits into
mainfrom
oss-s6-clickclack-deps
Sep 30, 2026
Merged

steipete merged 2 commits into
mainfrom
oss-s6-clickclack-deps

Conversation

@steipete

@steipete steipete commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

What Problem This Solves

ClickClack's rendering, desktop runtime, packaging, and build dependencies have newer patch/minor releases eligible under the existing 48-hour cooldown.

User Impact

Updates DOMPurify and the Electron 43 runtime with upstream fixes, refreshes build tooling, and regenerates the embedded web app. Node.js 24, macOS 12, and Go 1.26.6 minimums remain unchanged.

Why This Change Was Made

Update DOMPurify to 3.4.16, Vite to 8.3.1, its Svelte plugin to 7.3.1, Electron to 43.7.5, electron-builder to 26.17.0, Wrangler to 4.142.0, Node.js types to 26.6.3, and pnpm to 12.7.0. Keep the pnpm pin consistent across source docs, Docker builds, and workflows. pnpm 12.7 validates the complete workspace manifest set, so both Dockerfiles now stage the desktop and bot-example manifests before the frozen-lockfile install. Registry publication timestamps were checked before selecting versions; newer releases still inside the cooldown stay deferred.

Evidence

  • AWS Crabbox: frozen-lockfile install and full pnpm check passed, including 94 web utility tests, the Go suite, 31 FakeCo tests, 63 desktop contract tests, root/workspace typechecks, lint, and formatting.
  • pnpm docs:site and repeated pnpm build passed. Updated embedded assets were copied directly from the build.
  • Independent Codex P2 review passed across the full dependency diff and the Docker follow-up with no actionable findings.
  • The initial Docker CI job reproduced ERR_PNPM_OUTDATED_LOCKFILE for the missing bot-example manifest. With both missing manifests included, standard and Cloudflare Docker builds passed on a fresh AWS Crabbox lease. Frozen-lockfile enforcement stays enabled.
  • GitHub Actions covers PostgreSQL/coverage, Playwright E2E, Docker, Node 24 compatibility, embedded-build repeatability, and packaging on macOS, Windows, and Linux before merge.

@steipete
steipete requested a review from a team as a code owner September 30, 2026 01:24
@clawsweeper

clawsweeper Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 30, 2026
@clawsweeper

clawsweeper Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed September 29, 2026, 9:36 PM ET / September 30, 2026, 01:36 UTC (Revision 2).

ClawSweeper review

What this changes

Updates web rendering, Electron desktop, packaging, and build-tool dependencies; aligns pnpm pins across manifests, Dockerfiles, workflows, and docs; and regenerates the web assets embedded in the Go server.

Merge readiness

✅ Ready for maintainer review

Current main and v0.6.0 still use the older dependencies, so this PR remains useful. The follow-up Docker change resolves the prior review’s image-build blocker, and the current head has a successful Docker Image check. No discrete patch defect or unresolved merge risk was found.

Priority: P3
Reviewed head: 24edb88d1096216f32ae8f5ff9f2884d9f58ee18

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) The coordinated update has a clean review and the current-head image build now passes, supporting normal merge readiness.
Proof confidence 🐚 platinum hermit (4/6) Not applicable: The supplied Repository State classifies the author as MEMBER, so the external-contributor proof gate does not apply. The changed web, desktop, and Docker build paths have reported Crabbox validation and an exact-head successful Docker Image check; no stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The supplied Repository State classifies the author as MEMBER, so the external-contributor proof gate does not apply. The changed web, desktop, and Docker build paths have reported Crabbox validation and an exact-head successful Docker Image check; no stored-data contract changes.
Evidence reviewed 7 items Current main still uses older web dependencies: Pinned main specifies DOMPurify 3.4.15, Vite 8.3.0, and the older Svelte plugin.
Latest release also uses older dependencies: The v0.6.0 tag specifies the older web dependency versions; this refresh has not shipped there.
Changed rendering dependencies: The PR head updates the sanitizer and web build dependencies. Chat Markdown passes through DOMPurify before rendering.
Findings None None.
Security None None.

How this fits together

ClickClack renders chat and artifact content in a Svelte web app bundled into its Go server. Electron packages the desktop app, while pnpm, Docker, and CI prepare and validate those outputs.

flowchart LR
Content[Chat and artifact content] --> Web[Svelte web app]
Web --> Sanitizer[HTML sanitization]
Sanitizer --> Bundle[Web build]
Bundle --> Server[Go server assets]
Tooling[pnpm and CI] --> Bundle
Tooling --> Desktop[Electron desktop]
Desktop --> Installers[Desktop installers]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Direct version updates 8 packages The refresh spans rendering, desktop runtime, packaging, and build tooling.

Technical review

Best possible solution:

Retain frozen-lockfile validation and repeatable embedded-asset builds across the coordinated dependency update.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this is a dependency refresh rather than a bug report. The earlier Docker failure was addressed, and the exact current head has a successful Docker Image check.

Is this the best way to solve the issue?

Yes. Updating the manifests, lockfile, build pins, and embedded assets together follows the repository’s existing build path.

AGENTS.md: found, but no applicable review policy affected this item.

Codex review notes: model internal, reasoning high; reviewed against 615ab2ef40cb.

Labels

Label changes:

  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • remove merge-risk: 🚨 automation: Current PR review selected no merge-risk labels.
  • remove rating: 🦐 gold shrimp: Current PR rating is rating: 🐚 platinum hermit, so this older rating label is no longer current.

Label justifications:

  • P3: This is routine dependency maintenance with no verified user-facing regression.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The supplied Repository State classifies the author as MEMBER, so the external-contributor proof gate does not apply. The changed web, desktop, and Docker build paths have reported Crabbox validation and an exact-head successful Docker Image check; no stored-data contract changes.

Evidence

What I checked:

  • Current main still uses older web dependencies: Pinned main specifies DOMPurify 3.4.15, Vite 8.3.0, and the older Svelte plugin. (apps/web/package.json:19, 615ab2ef40cb)
  • Latest release also uses older dependencies: The v0.6.0 tag specifies the older web dependency versions; this refresh has not shipped there. (apps/web/package.json:19, 31d299eee271)
  • Changed rendering dependencies: The PR head updates the sanitizer and web build dependencies. Chat Markdown passes through DOMPurify before rendering. (apps/web/package.json:19, 24edb88d1096)
  • Rendering consumer: The web app sanitizes parsed chat Markdown, identifying the user-facing path affected by the DOMPurify update. (apps/web/src/lib/format.ts:5, 24edb88d1096)
  • Docker follow-up: Both Dockerfiles now stage the desktop and bot-example manifests before the frozen-lockfile install, matching the workspace package globs. (Dockerfile:7, 24edb88d1096)
  • Current-head image validation: GitHub reports Docker Image success for the exact current PR head. The earlier ClawSweeper review at d56b716 had requested a passing image build. (24edb88d1096)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-09-30T01:28:35.482Z sha d56b716 :: blocked before merge. :: none

@clawsweeper clawsweeper Bot added rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. and removed merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. labels Sep 30, 2026
@steipete
steipete merged commit d5f6004 into main Sep 30, 2026
12 of 13 checks passed
@steipete
steipete deleted the oss-s6-clickclack-deps branch September 30, 2026 01:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant