Skip to content

chore(deps): bump effect+platform-node to ^4.0.2, pin @types/node to 24 LTS - #134

Merged
kiro-systemf[bot] merged 2 commits into
masterfrom
chore/deps-sota-bump
Oct 8, 2026
Merged

kiro-systemf[bot] merged 2 commits into
masterfrom
chore/deps-sota-bump

Conversation

@systemfsoftware-maker

@systemfsoftware-maker systemfsoftware-maker commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

The npm launcher now bundles stable Effect 4.0.2 instead of 4.0.0-rc.118. Every @types/node in the lockfile is on the Node 24 LTS line, and CI fails if one leaves it. This replaces #124, #125, #126 and #127, which only reach 4.0.0/4.0.1 and float @types/node to 26.x.

  • Pin: a pnpm-workspace.yaml override (@types/node: ^24.19.1) also covers the @types/ws edge that used to pull 26.6.4. pnpm 11 no longer reads package.json#pnpm, so the override lives next to allowBuilds.
  • Guard: deno task check-dep-pins runs in the JS gate's deno step. It fails if any @types/node in pnpm-lock.yaml is off 24.x, if none is found at all, or if the launcher's Dependabot entry stops ignoring typescript or @types/node semver-major updates.
  • One Effect line: scripts/deno.jsonc moves to Effect 4.0.2 as well.
  • Ride-along: regenerating the lockfile with pnpm 11 re-resolves latest, which moved root @effect/tsgo from 0.48.1 to 0.51.1 (accepted).

Checked locally: frozen install, build, typecheck, lint, the cargo gate, deno check/lint, nix flake check, and the workspace-tarballs rehearsal. The guard exits 1 on the master lockfile and on this PR's first lockfile (both carry @types/node@26.6.4), and exits 0 on this tree.

…24 LTS

- effect, @effect/platform-node: 4.0.0-rc.118 -> ^4.0.2 (stable v4).
- @types/node: latest -> ^24.19.1, tracking the Node 24 LTS line.
- dependabot: ignore @types/node semver-major in the npm wrapper entry
  and exclude it from major-updates, mirroring the typescript handling,
  so the 24 pin is not re-bumped to 26.x.
- pnpm-lock.yaml regenerated with pnpm@11.27.0.

Supersedes #124, #125, #126, #127.
Review round on #134 (conductor ruling):
- pnpm-workspace.yaml: overrides @types/node ^24.19.1, so @types/ws no
  longer resolves @types/node@26.6.4. pnpm 11 ignores package.json#pnpm
  ("The pnpm field in package.json is no longer read"), so the override
  lives next to allowBuilds.
- scripts/tools/check-dep-pins.ts (deno task check-dep-pins), run in the
  js-gate.yml deno step: fails when any pnpm-lock.yaml resolution of
  @types/node is off the 24 line or none is resolved, and when the
  launcher dependabot entry stops ignoring typescript or @types/node
  semver-major.
- scripts/deno.jsonc: effect and @effect/platform-deno 4.0.2, so the
  repo runs one Effect line.
- dependabot.yml comment and AGENTS.md: Effect v4 RC -> Effect v4.

@kiro-systemf kiro-systemf Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consolidated SOTA bump verified: effect+@effect/platform-node ^4.0.2, @types/node ^24.19.1 (Node 24 LTS) with a pnpm-workspace override collapsing the transitive 26.x copy, dependabot semver-major ignore for @types/node, and a new js-gate guard (check-dep-pins.ts) that reds CI if any @types/node leaves the 24 line (proven red on 26.x fixtures). deno.jsonc effect bump + AGENTS.md/dependabot.yml truth fixes. CI green (gate/nix/npm/packaging/tools); hunt-grep clean; base master. accept_eval=pass. Supersedes #124-127.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant