Skip to content

chore(deps): move Composer to Prisma ORM 8.0.0-rc.17 and CLI engine 0.7.0 - #345

Merged
kristof-siket merged 4 commits into
mainfrom
chore/cli-engine-0.7.0
Oct 8, 2026
Merged

kristof-siket merged 4 commits into
mainfrom
chore/cli-engine-0.7.0

Conversation

@kristof-siket

@kristof-siket kristof-siket commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Moves Composer to Prisma ORM 8.0.0-rc.17 and CLI engine 0.7.0 together. ORM rc.17 is the first ORM release that peers engine 0.7.0, the engine the Prisma CLI ships since prisma/prisma-cli#337. With both on 0.7.0, the CLI can drop the two temporary exceptions in its release check (prisma/prisma-cli#338).

Changes

  1. Engine: @prisma/cli-engine 0.6.3 → 0.7.0 in its five pins (the root override, @internal/cli, the prisma-cloud target, and @prisma/composer-cli's peer and dev dependencies). Engine 0.7.0 adds API and error codes and removes nothing.
  2. ORM: @prisma/orm-postgres and @prisma/orm-toolchain 8.0.0-rc.16 → 8.0.0-rc.17 in all seven manifests.
  3. The rc.16 to rc.17 upgrade guides, applied where their detection matches Composer:
    • foreign-keys-name-their-backing-index (and its extension twin): every contract is re-emitted with the rc.17 toolchain. Only the auth pack's contract changes. Its two foreign keys now name their backing indexes (account_userId_idx, session_userId_idx), so its storage hash moves.
    • orm-collections-lock-rows, contract-artifacts-restamp: covered by the same re-emit. No other emitted file changes.
    • enum-codecs-refused and with-is-a-collection-member match by pattern only: a timestamptz-string codec on a plain column, and an import attribute with: { type: 'json' }.
  4. Auth pack migration: 0001_init is re-authored with migration plan, as the pack's prisma.config.ts describes. Its operations are the same; the rc.17 renderer writes timestamptz without quotes. examples/auth re-materialises the auth space from the pack: 0001_init, refs/head.json, and the snapshot directory move to the new hash.

Storage hashes (old → new):

  • auth pack head, and the auth space in examples/auth: 310f206d → 0df0ef09

No other storage, execution or profile hash changes.

For the release notes

An auth database deployed with an earlier Composer has its marker at 310f206d. Its next deploy stops with MIGRATION_PATH_NOT_FOUND until someone runs prisma db sign against it. The rc.17 extension guide prescribes the same re-sign for bundled contracts.

Checks run locally

  • pnpm typecheck, lint, lint:casts, lint:deps (including the ORM-pin and contract-snapshot lints), test:scripts, check:skill-packaging, check:cli-engine-pin, check:publish-deps, check:orm-pins, check:npm-effect-resolution, check:family-static-graph, check:floor-imports and lint:retired-binary-name pass.
  • turbo run test --continue: 64 of 66 tasks pass. The two failures come from this machine's shared local Postgres daemon, not from this change:
    • local-target: its beforeAll hook timed out after 5 s while it started the daemon.
    • integration-tests: the daemon reported database or disk is full and a held lock file after the disk filled up mid-run, and it still held an orders database from an older run.

The Prisma CLI ships @prisma/cli-engine 0.7.0 since prisma/prisma-cli#337.
Engine 0.7.0 is a minor release that adds API and error codes and removes
nothing, so only the pins move.

Signed-off-by: Kristof Siket <siket@prisma.io>
@prisma-gizmo

prisma-gizmo Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

✅ Gizmo reviewed 25a43de — posted 0 inline comment(s) this pass.

Open findings: none

Change walkthrough

This PR is a coordinated dependency bump: Composer moves to Prisma ORM 8.0.0-rc.17 across all seven manifests and to CLI engine 0.7.0 across all five pins, and the auth pack's emitted artifacts are regenerated with the rc.17 toolchain so the pack and the examples/auth space stay in lockstep with the new ORM.

Version pins. The @prisma/orm-postgres / @prisma/orm-toolchain bumps span the three example packages, the auth shared module, the prisma-cloud extension target, and composer-prisma-cloud (dependency, peer, and devDependency). The @prisma/cli-engine bump covers the root pnpm override, @internal/cli, the extension target's devDependency, and composer-cli's peer + devDependency. All pins remain exact versions, which is what check:cli-engine-pin demands, and every ORM pin agrees on one version, which is what check:orm-pins and lint:orm-pins enforce. The lockfile was regenerated to match (it's among the skipped generated files).

Auth contract re-emit. The rc.17 upgrade guide foreign-keys-name-their-backing-index is visible in contract.json: the account and session foreign keys — the only two FKs in the contract — now carry explicit index.name blocks (account_userId_idx, session_userId_idx) that match the index entries already present on those tables. This moves the storage hash from 310f206d to 0df0ef09.

Auth migration re-authoring. The pack's 0001_init migration and its examples/auth mirror were re-materialised: migration.json gets the new to/migrationHash/createdAt, and ops.json's DDL is re-rendered with timestamptz unquoted — the only ops delta, and semantically identical SQL. The pack and example copies are byte-identical, and refs/head.json matches the new storage hash, as does the generated StorageHash type in contract.d.ts. The profile hash is untouched, consistent with the PR's claim that no other storage, execution, or profile hash moved.

No stale references to the old hash, rc.16, or engine 0.6.3 remain anywhere in the tree, so the PR's stated motivation — letting the CLI drop its engine-version exceptions — is fully realised on the Composer side.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Essentials
  • Run ID: 6b2281b2-02ef-466a-b82f-3c8d65619a28
📥 Commits

Reviewing files that changed from the base of the PR and between 1f695dc and 25a43de.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (20)
  • examples/auth/migrations/auth/0001_init/migration.json
  • examples/auth/migrations/auth/0001_init/ops.json
  • examples/auth/migrations/auth/refs/head.json
  • examples/auth/migrations/snapshots/0df0ef0989ec3dd95124dde6303fbe0572bbab08bebf00abff6a7955cadd786e/contract.d.ts
  • examples/auth/migrations/snapshots/0df0ef0989ec3dd95124dde6303fbe0572bbab08bebf00abff6a7955cadd786e/contract.json
  • examples/auth/migrations/snapshots/310f206db185446ac06c56b425d961c2ae7c9d3f4fd409a92c4832592b2d8839/contract.json
  • examples/auth/package.json
  • examples/orm-demo/package.json
  • examples/store/modules/catalog/package.json
  • examples/store/modules/orders/package.json
  • package.json
  • packages/0-framework/3-tooling/cli/package.json
  • packages/1-prisma-cloud/1-extensions/target/package.json
  • packages/1-prisma-cloud/2-shared-modules/auth/package.json
  • packages/1-prisma-cloud/2-shared-modules/auth/src/pack/contract.d.ts
  • packages/1-prisma-cloud/2-shared-modules/auth/src/pack/contract.json
  • packages/1-prisma-cloud/2-shared-modules/auth/src/pack/migrations/0001_init/migration.json
  • packages/1-prisma-cloud/2-shared-modules/auth/src/pack/migrations/0001_init/ops.json
  • packages/9-public/composer-cli/package.json
  • packages/9-public/composer-prisma-cloud/package.json
💤 Files with no reviewable changes (1)
  • examples/auth/migrations/snapshots/310f206db185446ac06c56b425d961c2ae7c9d3f4fd409a92c4832592b2d8839/contract.json

Included review availability: This review used your included allowance. 3 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour.


Summary by CodeRabbit

  • Improvements
    • Updated the authentication schema contract with model and relation metadata, plus expanded PostgreSQL support for row locking and conflict-handling inserts.
    • Refreshed authentication migration metadata and schema definitions, including PostgreSQL timestamp type declarations.
    • Updated the PostgreSQL and CLI tooling used by the examples and packages.

Walkthrough

The PR updates Prisma ORM, toolchain, and CLI engine versions across examples and packages. It refreshes the generated PostgreSQL auth contract with model types, field and relation mappings, capabilities, indexes, and storage hashes. Auth migration SQL changes timestamp types to unquoted timestamptz, and migration metadata and snapshot references are updated.

Estimated code review effort

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 25a43

The upgrade can proceed with the documented database re-sign step for existing auth deployments.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the primary changes: upgrading Composer to Prisma ORM 8.0.0-rc.17 and CLI engine 0.7.0.
Description check ✅ Passed The description directly explains the dependency upgrades, generated contract and migration changes, storage hash update, release impact, and test results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@prisma/composer@345
npm i https://pkg.pr.new/@prisma/composer-cli@345
npm i https://pkg.pr.new/@prisma/composer-prisma-cloud@345

commit: 25a43de

Pins @prisma/orm-postgres and @prisma/orm-toolchain at 8.0.0-rc.17 in all seven manifests. ORM rc.17 peers @prisma/cli-engine 0.7.0, the engine this branch already pins.

Following the rc.16 to rc.17 guides, the entries whose detection matches Composer:
- foreign-keys-name-their-backing-index and its extension twin: one re-emit of every contract with the rc.17 toolchain. Only the auth pack has foreign keys whose backing index the contract now names (account_userId_idx, session_userId_idx), so only its storage hash changes.
- orm-collections-lock-rows and contract-artifacts-restamp: covered by the same re-emit; no other emitted file changes.
- enum-codecs-refused and with-is-a-collection-member: false matches. The first is a timestamptz-string codec on a plain column, the second an import attribute.

The auth pack's 0001_init is re-authored with migration plan, as the pack's prisma.config.ts describes. Its operations are the same; the rc.17 renderer writes timestamptz unquoted. examples/auth re-materialises the auth space from the pack: 0001_init, refs/head.json, and the snapshot directory move to the new hash.

Storage hashes (old -> new):
- auth pack head, and the auth space in examples/auth: 310f206d -> 0df0ef09

An auth database deployed with an earlier Composer has its marker at 310f206d. Run prisma db sign against it before its next deploy.

Signed-off-by: Kristof Siket <siket@prisma.io>
@kristof-siket kristof-siket changed the title chore(deps): align Composer with CLI engine 0.7.0 chore(deps): move Composer to Prisma ORM 8.0.0-rc.17 and CLI engine 0.7.0 Oct 8, 2026
@kristof-siket
kristof-siket marked this pull request as ready for review October 8, 2026 15:12

@prisma-gizmo prisma-gizmo Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New findings: none · trace

@prisma-gizmo prisma-gizmo Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No critical or major Gizmo finding is open and the head commit has been reviewed. Approving.

@kristof-siket
kristof-siket merged commit 745a784 into main Oct 8, 2026
25 checks passed
@kristof-siket
kristof-siket deleted the chore/cli-engine-0.7.0 branch October 8, 2026 15:31
kristof-siket added a commit that referenced this pull request Oct 8, 2026
Re-runs pnpm bump-minor on top of main to resolve the version conflicts with #345.

Signed-off-by: Kristof Siket <siket@prisma.io>
wmadden pushed a commit that referenced this pull request Oct 8, 2026
…rc.15; release v0.29.1 (#349)

* fix(deps): go back to alchemy 2.0.0-beta.78 so npm stops nesting prisma@8.0.0-rc.15

alchemy 2.0.0-beta.80 and later declare optional peers on exactly prisma@8.0.0-rc.15 and @prisma/orm-postgres@8.0.0-rc.11. Any other prisma version fails the peer, so npm installs a full nested prisma@8.0.0-rc.15 (with @prisma/cli-engine 0.4.0) under @prisma/composer and @prisma/composer-cli. The prisma CLI's conformance check then fails on that nested engine.

This reverts the dependency part of #348 and restores the pins it removed: alchemy 2.0.0-beta.78, effect 4.0.0-rc.115 and the exact @effect/* pins. beta.79 also lacks the peers, but its alchemy/Prisma entry fails to load without @alchemy.run/frontend-frameworks, and Composer imports alchemy/Prisma. beta.78 and beta.79 only work on effect rc.115, which still needs the @effect/vitest pin to keep npm on one effect copy.

ORM 8.0.0-rc.17 and cli-engine 0.7.0 from #345 stay.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>

* chore(release): v0.29.1

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>

* docs(deps): one effect override placeholder, and name both pin sites in the dedupe check's timeout message

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>

---------

Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants