chore(deps): upgrade vite to 8.3.1 and pin bundled dev rolldown to 1.2.9 - #2034
Conversation
…o 1.2.9 Vite 8.3.1 inlines rolldown 1.2.9's browser dev runtime into bundledDevClient.mjs, while its rolldown range (~1.2.9) resolves 1.2.10+. rolldown 1.2.10 dropped the kind argument from registerFactory (rolldown#10915), so with a newer rolldown every lazy import() and HMR update in bundled dev mode (`unstable_bundledDev` in dev/test-studio) fails with 'factory.fn is not a function'. Pin rolldown under vite@8.3.1 to 1.2.9, the version Vite 8.3.1 was built against. The next Vite release serves the runtime from the installed rolldown (vite#23568), so the scoped override stops applying once Vite is bumped past 8.3.1. Vite is only a transitive dependency here, so it was bumped with `pnpm update vite -r`. The Studio `next` dist-tag overrides stay on their locked 6.13.3-next.7 versions. Co-authored-by: Cody Olsen <stipsan@users.noreply.github.com>
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
✅ E2E Tests🟢 43 passed • 🟡 1 flaky • view full report • view run Studio: https://plugins-e2e-test-studio-eu8jbi00j.sanity.dev Datasets: |
Coverage Report
File CoverageNo changed files found. |
The sanity@next bump brings in vite@8.3.1, whose bundled-dev client inlines rolldown 1.2.9's runtime while its `rolldown: ~1.2.9` range resolves 1.2.11. rolldown 1.2.10 dropped the `kind` argument from registerFactory (rolldown/rolldown#10915), so every lazy import in the test studio's `sanity dev` failed with `factory.fn is not a function`. Same override as #2034.
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The override is correctly scoped and matches the documented upstream incompatibility.
Review effort: Balanced
Findings: None
What changed in this PR
Pins Rolldown 1.2.9 under Vite 8.3.1 to preserve bundled-development lazy imports and HMR compatibility.
Changes:
- Adds a version-scoped pnpm override.
- Documents the incompatibility and removal condition.
| File | Description |
|---|---|
pnpm-workspace.yaml |
Adds the scoped Rolldown compatibility override. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Resolves the pnpm-lock.yaml conflict with #2034 by keeping this branch's lockfile: it already has vite@8.3.1 with the identical `vite@8.3.1>rolldown` pin that #2034 added, on top of the sanity@next bump, and passes `pnpm install --frozen-lockfile` and `pnpm dedupe --check` against the merged manifests.
<!-- CURSOR_AGENT_PR_BODY_BEGIN --> ### Description Turns on the new `beta.reactActivityMode` flag from [sanity-io/sanity#14901](sanity-io/sanity#14901) for every workspace in `dev/test-studio`, so the plugins in this monorepo get dogfooded with recently used tools kept mounted behind React's `<Activity>` (effects torn down while hidden, re-created on reveal) instead of being unmounted on tool switch. The flag's typings ship in `sanity@6.17.0-next.106`, published by [Release @next run 36426787139](https://github.com/sanity-io/sanity/actions/runs/36426787139) from the PR's merge commit (`f5821c33bf`). The lockfile was still on `6.13.3-next.7`, where the config fails type-checking with `TS2353: 'reactActivityMode' does not exist in type 'BetaFeatures'`, so this also re-resolves the `next` overrides. ### Changes - `dev/test-studio/sanity.config.ts`: a shared `beta` constant applied by `createWorkspace` (placed before `...config`, so a workspace that defines its own `beta` still opts out) and on the standalone `cross-dataset-duplicator-target` workspace, which also registers a tool. - `pnpm-lock.yaml`: `sanity`, `@sanity/vision`, `@sanity/types`, `@sanity/util`, `@sanity/schema`, `@sanity/mutator` and `groq` move in lockstep from `6.13.3-next.7` to `6.17.0-next.106` (one copy of each). Regenerated with `pnpm dedupe`, the same command the "Dedupe lockfile" workflow runs, repeated until `pnpm dedupe --check` passes, so no follow-up bot PR is needed. That also collapses duplicates the bump would otherwise leave behind, which is why a few direct deps shift to in-range versions already in the graph: `@codemirror/state` 6.7.6 / `@codemirror/view` 6.43.13 / `@uiw/react-codemirror` 4.25.12 (code-input), `xstate` 5.33.2 (dashboard-widget-vercel), `@mux/mux-player(-react)` 3.13.4 (mux-input), `@tanstack/react-virtual` 3.14.13 (workflow), `uuid` 14.0.2 (graph-view), `axios` 1.20.0 (shopify-assets). Catalogs and `package.json` specifiers are unchanged. - `pnpm-workspace.yaml`: `sanity@6.17.0-next.106` needs `@sanity/sdk` and `@sanity/sdk-react` `^3.5.0`, which `sanity-svc.npm` published from `sanity-io/sdk` without provenance (since 3.4.0), tripping `trustPolicy: no-downgrade`. `3.5.0` of both is added to `trustPolicyExclude` next to the existing `@sanity/sdk@2.1.2 || 3.0.0-rc.1` entry. Without this, `pnpm dedupe` on `main` (and so the Dedupe lockfile workflow) currently fails with `ERR_PNPM_TRUST_DOWNGRADE`. The bump also pulls in `vite@8.3.1`, whose bundled-dev client needs the `vite@8.3.1>rolldown: 1.2.9` pin; without it every lazy chunk in `pnpm dev` fails with `factory.fn is not a function`. That pin landed on `main` in #2034 (this branch had added the identical override before it merged), and the merge keeps this branch's deduped lockfile, which already resolves `vite@8.3.1` → `rolldown@1.2.9`. No changeset: only the private test studio and workspace tooling change; published package ranges are untouched. ### Testing - `pnpm format`, `pnpm lint` (type-aware), `pnpm knip`, `pnpm build` (52 tasks) and `pnpm test run` (224 files, 1391 tests) all pass locally. - `pnpm oxlint dev/test-studio/sanity.config.ts` fails with `TS2353` on `6.13.3-next.7` and passes on `6.17.0-next.106`. - After merging `main`: `pnpm install --frozen-lockfile` and `pnpm dedupe --check` both pass. - Manual test of tool switching in the test studio: in progress; this description will be updated with the recording. <!-- CURSOR_AGENT_PR_BODY_END --> <div><a href="https://cursor.com/agents/bc-e9a7834b-ed40-45c0-8168-0afdb8a313c7?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a> <a href="https://cursor.com/background-agent?bcId=bc-e9a7834b-ed40-45c0-8168-0afdb8a313c7&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a> </div> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…overrides (#2038) <!-- CURSOR_AGENT_PR_BODY_BEGIN --> ### Description Follow-up to [#2034](#2034). #2034 was merged before this AGENTS.md commit was pushed, so it lands separately. While `pnpm-workspace.yaml` overrides `sanity`, `@sanity/mutator`, `@sanity/schema`, `@sanity/types`, `@sanity/util`, `@sanity/vision`, and `groq` to the `next` dist-tag, any full re-resolution moves them to the newest `next` prerelease. That includes editing `overrides`, `pnpm update <pkg>`, and `pnpm dedupe`. pnpm cannot reuse a locked version for a dist-tag, so a targeted dependency change silently becomes a Studio upgrade. The new prerelease can also trip `trustPolicy: no-downgrade`, which is what happened with `@sanity/sdk@3.5.0` until [#2037](#2037) allowlisted it. The note covers the two options: call the Studio bump out in the PR, or keep it out by resolving through a local registry proxy that serves the locked versions as `next`. #2034's lockfile was produced the second way. The note also warns against temporarily pinning the overrides to an exact version. I tried that first: pnpm applies semver overrides to `peerDependencies` ranges too, and the rewritten ranges (for example `sanity: 6.13.3-next.7` in `@sanity/cli-build`'s peers) stay in the lockfile. ### What to review - `AGENTS.md`: one new paragraph under "Code Style → Dependencies", after the Studio upgrade steps. ### Testing Docs only. `oxfmt --check AGENTS.md` passes. ### Notes for release N/A. Docs only, no changeset. <!-- CURSOR_AGENT_PR_BODY_END --> <div><a href="https://cursor.com/agents/bc-8a49abed-56bd-47f4-9e16-fbcde27d80eb?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a> <a href="https://cursor.com/background-agent?bcId=bc-8a49abed-56bd-47f4-9e16-fbcde27d80eb&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a> </div> Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Description
Ports sanity-io/sanity#15055.
dev/test-studiorunssanity devwithunstable_bundledDev: true, so it has the same exposure.Vite 8.3.1 inlines rolldown 1.2.9's browser dev runtime into
bundledDevClient.mjs, but declaresrolldown: ~1.2.9. rolldown 1.2.10 dropped thekindargument fromregisterFactory(rolldown#10915). With rolldown 1.2.10 or 1.2.11 under Vite 8.3.1, every lazyimport()and HMR update in bundled dev fails withTypeError: factory.fn is not a function.This PR moves Vite from 8.2.2 to 8.3.1 and adds
'vite@8.3.1>rolldown': '1.2.9', with the same removal condition as upstream: the next Vite release serves the runtime from the installed rolldown (vite#23568), so delete the entry when bumping past 8.3.1.Differences from the Sanity PR:
@sanity/cli,@sanity/cli-build,vitestand the Vite plugins), so there is no catalog entry to bump. It was moved withpnpm update vite -r.vite>rolldown: 1.2.8/tsdown>rolldownpins from sanity#14835, so there is nothing to remove. It stayed safe only because Vite was still on 8.2.2. That wouldn't last:@sanity/cli@8.13.0, which the currentsanity@nextuses, requiresvite ^8.3.0, and the clean regeneration in #2018 already resolves Vite 8.3.0 with rolldown 1.2.9, which is therequestLazycrash combination.@sanity/tsdown-configkeeps 1.2.6, so plugin builds are unaffected. All 296dist/files are byte-identical to a freshmainbuild.What to review
pnpm-workspace.yaml: the scoped override and its removal condition.pnpm-lock.yaml:@oxc-project/types@0.150.0, andpostcss@8.5.28(required by Vite 8.3.1). Peer suffixes follow:(vite@8.2.2)becomes(vite@8.3.1), and the rolldown peers of@rolldown/plugin-babeland the Studio CLI packages go from(rolldown@1.2.6)to(rolldown@1.2.9).overridesedit makes pnpm fully re-resolve, which also applies normalization unrelated to Vite, the same thing a Renovate or dedupe run would do. No versions are added or removed by this part:@codemirror/state6.7.2 /@codemirror/view6.43.10 to the locked 6.7.4 / 6.43.11. Vision itself already used those, so its tree now mixes fewer copies.@oxlint/binding-linux-arm64-gnu@1.83.0is added.catalogs.peer.reactentry is dropped.@vitejs/devtoolspeer is kept only in thesanitysnapshot thatdev/test-studiouses, since it is the only importer that depends on@vitejs/devtools.nextoverrides stay on their locked 6.13.3-next.7. At the time, a full re-resolution would have moved them to 6.17.0-next.106, which pulls@sanity/sdk@3.5.0and failedtrustPolicy: no-downgrade. To keep that upgrade out, I resolved through a throwaway local registry proxy that reported the locked versions asnext. pnpm wrote the whole lockfile itself, with no hand edits, and it has nolocalhostortarball:entries. Both a clean-cloneCI=true pnpm install --frozen-lockfileand a plainpnpm installagainst npm accept it as-is.The AGENTS.md note about that
next-override gotcha was pushed after this PR merged, so it's in #2038.Resolved after merge: the
ERR_PNPM_TRUST_DOWNGRADEfor@sanity/sdk@3.5.0also brokepnpm dedupeonmain.@sanity/sdk3.4.0 and 3.5.0 were published bysanity-svc.npmwithout provenance. #2037 fixed it by allowlisting@sanity/sdk@3.5.0and@sanity/sdk-react@3.5.0while it bumped the Studio.Vite 8.3.x also raised its optional
@vitejs/devtoolspeer range to^0.7.1, while the test studio uses 0.4.12, so pnpm now reports a peer warning. The DevTools workflow still works, because it goes through theDevTools()plugin rather than Vite's top-leveldevtoolsoption. Bumping@vitejs/devtools*to 0.7 is left for a separate PR.Testing
First I confirmed the root cause in the published tarballs (Linux x64 binding strings):
registerFactoryshapebundledDevClient.mjsregisterFactory(id, kind, fn)(8.3.1 also hasrequestLazy)registerFactory(id, kind, fn)registerFactory(id, fn)Then I ran
dev/test-studioin bundled dev, authenticated, and drove it headlessly with Playwright. Each run loaded Workspace Home, edited the heading insanity-plugin-workspace-home/src/components/WorkspaceHome.tsx, reverted the edit, and then opened the Structure tool:/@vite/lazychunks, all 200.[vite] hot updatedfor the edit and the revert, applied in place with no reload. Structure renders. 0 page or console errors.~1.2.9match)TypeError: factory.fn is not a functionatViteDevRuntime.initModule, the Studio crash screen, and nothing renders.ENABLE_VITE_DEVTOOLS=true/__devtools/returns 200. The only error is devframe's "rpc to be trusted" timeout, because no one approved the one-time auth prompt.mainafter #2037 (sanity@6.17.0-next.106)Removing the override alone and running
pnpm update rolldown -rkept Vite's locked 1.2.9. A fresh resolution, like the regeneration in #2018, picks the newest~1.2.9match instead, which is why the negative control sets 1.2.11 explicitly.bundled_dev_vite_8_3_1_rolldown_1_2_9_lazy_load_and_hmr.mp4
Pinned rolldown 1.2.9: heading hot updated in place
rolldown 1.2.11 under Vite 8.3.1: factory.fn is not a function
Other checks that passed locally:
pnpm format(no changes)pnpm lint: 1,505 files, 0 diagnosticspnpm knippnpm build: 52/52 tasks uncached, including thesanity buildoftest-studioande2e-studioon Vite 8.3.1, plus anENABLE_VITE_DEVTOOLS=truestudio build that records a Rolldown sessionpnpm test run: 224 files, 1,391 testsCI=true pnpm install --frozen-lockfiledist/comparison againstmainNotes for release
N/A. This is dev tooling only: no published package changes, so no changeset.
To show artifacts inline, enable in settings.