Skip to content

Refresh workspace and GitHub Actions dependencies - #170

Merged
niemyjski merged 10 commits into
mainfrom
feature/dependency-refresh-2026-07
Oct 6, 2026
Merged

niemyjski merged 10 commits into
mainfrom
feature/dependency-refresh-2026-07

Conversation

@niemyjski

@niemyjski niemyjski commented Jul 12, 2026 •

Copy link
Copy Markdown
Member

Refresh compatible SDK/sample dependencies, including Expo SDK 57 and Vitest 5. SDK source and APIs are unchanged. build.yml has only five Action-version edits; the added scripts and ESLint changes are removed. Removed the unused browser-example Vitest project after its test was deleted, and reduced overrides from six to two without changing the lockfile.

Validation: clean install, builds, lint, 346 tests, sample dogfooding, Expo exports, and SDK runtime audit passed. Updated-head Linux/macOS/Windows CI and CodeQL are green.

Merge gates: unpatched high-severity braces/node-forge advisories in Expo tooling require risk acceptance or fixes. Expo Doctor remains 20/21 due to cooling-held patches. Backend delivery/native crash reporting are unverified. Human review is required.

Verification and implementation details
  • Rebased onto current main. ConsoleLog.ts, all other SDK source, and eslint.config.mjs match main. Removed the added publication/versioning scripts and their tests. GitHub Actions changes are only checkout v7, setup-node v7 (two uses), cache v6, and setup-dotnet v6.
  • Exact cleanup-head (70d57c63) hosted proof: PR build, push build, and CodeQL passed. The workflow retains main's publication behavior; green job status is not a separate proof of registry delivery because main's CI publish step permits publication failures.
  • Distribution comparison used independently clean-installed/built main and PR trees. Of 314 SDK dist files, 296 are byte-identical, including all TypeScript-generated JavaScript and declarations; core and React Native match completely. The other 18 are CDN bundles and maps. Every unminified bundle matches after normalizing only esbuild's documented CommonJS module-evaluation error fix. CDN bundles are not claimed to be byte-identical.
  • The browser logger uses textarea values for literal text and initializes after DOMContentLoaded. These flows were previously tested and dogfooded; the additional browser logger test has since been removed at the author's request. No browser-example Vitest project remains. Root tests now total 346 in 26 files.
  • Removed redundant overrides for brace-expansion, nanoid, and both xmldom release lines. The lockfile still selects their patched versions, which satisfy every installed parent's declared range. Clean installation preserves that graph. Retained only SvelteKit → cookie 0.7.2 (upstream requests ^0.6.0) and xcode → uuid 11.1.1 (upstream requests ^7.0.3), to avoid reintroducing the cookie validation advisory and uuid bounds-check advisory. Both overrides are scoped to their consumers; newer ESM-only uuid majors are not forced into CommonJS xcode.
  • Browser log/error queueing, React boundary fallback, Vue error control, Svelte message/caught-error controls, Next.js route log (HTTP 200) and boundary retry, and Expo logs/errors/feature usage/identity/reference IDs were exercised. Express normal routes returned 200, caught/uncaught errors returned expected 500 responses, and unknown routes returned 404. Production builds passed for every buildable workspace. Expo web export: 366 modules / 646 KB; iOS Hermes export: 700 modules / 1.7 MB.
  • Compatible security fixes: brace-expansion 5.0.12, devalue 5.9.4, proxy-addr 2.0.8, source-map-js 1.2.2. Full npm audit reports 15 high dependency entries propagated from two underlying advisories; OSV confirms braces and node-forge. Neither has a published patch. These are reached through Expo/Metro tooling, not published SDK runtime dependencies. No unsafe major downgrade or audit suppression is applied.
  • All seven published SDK runtime workspaces audit clean. Registry verification passed for 829 package signatures and 264 attestations. All 910 remote lockfile entries have npm-registry URLs and integrity hashes. Release ages were checked for 421 changed entries; only source-map-js 1.2.2 is younger than seven days and has a narrow security-fix cooling exception.
  • Expo Doctor expects expo 57.0.26 and expo-constants 57.0.20; cooled versions remain 57.0.25 and 57.0.19. TypeScript 7 is held for lint/Svelte compatibility, React/native versions remain Expo-aligned, and AsyncStorage remains 2.2.0 because 3.x removes the SDK's required multiRemove API. typescript-eslint is pinned to 8.64.0, the newest tested release that passes without modifying ConsoleLog or lint policy; 8.65+ flags its existing unbound method. Prettier stays at 3.8.3 to avoid unrelated SDK formatting changes.
  • Reproduce local gates with npm ci, npm run build, npm run lint, npm test, npm run check --workspace=example/svelte-kit, npm audit, npm audit signatures, and osv-scanner scan --lockfile=package-lock.json. Run expo install --check / expo-doctor from example/expo to see the unsuppressed cooling-window mismatch.

Copilot AI review requested due to automatic review settings July 12, 2026 18:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Refreshes dependency versions across the Exceptionless.JavaScript monorepo (core SDK packages plus example apps) to align on current compatible tooling, reduce known vulnerabilities via overrides, and keep the build/test toolchain consistent across workspaces.

Changes:

  • Bumps esbuild across all SDK packages and updates root allowScripts accordingly.
  • Updates framework/example dependencies (React, Vue, Vite, SvelteKit, Next.js, Expo/RN) and adds the missing @testing-library/dom dependency for the React example.
  • Adds root overrides to pin @react-native-async-storage/async-storage and patch vulnerable transitive dependencies (cookie, postcss, uuid).

Reviewed changes

Copilot reviewed 14 out of 15 changed files in this pull request and generated no comments.

Show a summary per file
File Description
package.json Updates shared dev deps (React/Vitest), updates allowScripts, and adds dependency overrides for security/compatibility pins.
packages/core/package.json Bumps esbuild used for bundling core package outputs.
packages/browser/package.json Bumps esbuild used for bundling browser package outputs.
packages/angularjs/package.json Bumps esbuild used for bundling AngularJS wrapper outputs.
packages/node/package.json Bumps esbuild and updates @types/node for Node package development/build.
packages/react/package.json Updates React type dependencies and bumps esbuild for the React wrapper bundle.
packages/react-native/package.json Pins AsyncStorage dev dependency for Expo/RN compatibility and updates React types.
packages/vue/package.json Bumps esbuild used for bundling Vue wrapper outputs.
example/browser/package.json Updates Vite for the browser sample app.
example/react/package.json Updates React/Vite tooling and adds @testing-library/dom to satisfy testing-library peer requirements.
example/vue/package.json Updates Vue/compiler and Vite for the Vue sample app.
example/svelte-kit/package.json Updates SvelteKit/Svelte/Vite/Vitest versions for the SvelteKit sample app.
example/nextjs/package.json Updates Next.js and aligns React versions for the Next.js sample app.
example/expo/package.json Upgrades Expo SDK and React Native version while keeping Expo-pinned React and AsyncStorage versions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 19e8d457aa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json Outdated
@niemyjski

Copy link
Copy Markdown
Member Author

Dependency/security recheck (2026-07-31)

  • Updated official actions to their current releases: actions/checkout@v7, actions/setup-node@v7, actions/cache@v6, and actions/setup-dotnet@v6.
  • Refreshed the remaining compatible workspace updates, including Vite 8.2.0, Expo 57.0.9 / React Native 0.86.2, SvelteKit 2.70.2, and current React/Node type packages.
  • npm audit: 0 vulnerabilities across 908 dependencies.
  • OSV Scanner: no issues across 868 lockfile packages (14 local workspace entries are unscannable by design).
  • npm registry verification: 800 package signatures verified; 221 packages also have verified attestations.
  • Reconciled the 33 open Dependabot alerts shown for the default branch against this PR lockfile. Every vulnerable package resolves at or above its patched version here, including shell-quote@1.10.0, next@16.2.12, sharp@0.35.3, undici@7.29.0, postcss@8.5.23, and brace-expansion@5.0.8.

Validation passed:

  • clean npm 11 install
  • full monorepo build
  • 347 tests
  • ESLint + Prettier
  • Svelte diagnostics (0 errors / 0 warnings)
  • Expo Doctor (20/20)
  • Expo iOS and web production exports
  • Sharp native smoke test
  • live sample exercises for Browser, React, Vue, SvelteKit, Next.js, Expo web, and Express

The samples successfully rendered and queued their log/error events. Submission failures were expected because the local Exceptionless backend at ports 7110/7111 was not running.

@niemyjski niemyjski changed the title Refresh workspace dependencies Refresh workspace and GitHub Actions dependencies Aug 13, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 92e79b4c52

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/build.yml Outdated
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T03:22:07.221930Z 70d57c6 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@niemyjski niemyjski self-assigned this Oct 6, 2026
@niemyjski niemyjski added the dependencies Pull requests that update a dependency file label Oct 6, 2026
@niemyjski
niemyjski force-pushed the feature/dependency-refresh-2026-07 branch from bcd340e to 060ee6e Compare October 6, 2026 02:40
@niemyjski
niemyjski merged commit 31bed60 into main Oct 6, 2026
10 checks passed
@niemyjski
niemyjski deleted the feature/dependency-refresh-2026-07 branch October 6, 2026 03:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants