Repository navigation
chore(deps): move every dependency to its latest release - #244
Conversation
agent-interface 2.13.1, agent-profile-materialize 0.20.3, hono 4.13.9, zod 4.6.5, vitest 5.0.2, @types/node 26.6.3 and tsx 4.23.15. The runtime-consumer regression now pins agent-eval 0.200.1, agent-runtime 0.283.0 and sandbox 0.55.3. Transitive packages are refreshed within their ranges. agent-trace-contract moves to ^1.3.0, not 2.0.0: contract-build.ts refuses a lockfile with two contract builds, and agent-runtime 0.283.0 and agent-eval 0.200.1 still require 1.x. pnpm 12.6.0 is pinned through packageManager, so CI drops its version input and the pnpm 9/10 onlyBuiltDependencies list. Actions move to checkout v7, setup-node v7 and pnpm/action-setup v6.1.0. Both images move to node:24-slim, and the app image installs with pnpm 12.6.0 after copying pnpm-workspace.yaml, so allowBuilds builds better-sqlite3.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
tangletools
left a comment
There was a problem hiding this comment.
✅ Auto-approved PR — 8cc46c37
Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.
tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-28T05:42:40Z
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8cc46c3772
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| '@pnpm/exe.win32-arm64': 12.6.0 | ||
| '@pnpm/exe.win32-x64': 12.6.0 | ||
|
|
||
| --- |
There was a problem hiding this comment.
Remove the extra YAML document from the lockfile
The committed lockfile contains two YAML documents: a standalone pnpm bootstrap lock occupies lines 1–157, while the actual workspace lock starts here. Consequently, every CI, Docker, or developer install that reads this file fails before dependency resolution with ERR_PNPM_BROKEN_LOCKFILE: expected a single document in the stream, but found more, including the workflow's pnpm install --frozen-lockfile.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Checked this, and it does not reproduce. pnpm 12 writes the leading document on purpose: it locks the package manager itself through packageManagerDependencies. The file parses for every pnpm that installs this repo.
- CI run 36383060685 on this head passed with pnpm 12.6.0, which
pnpm/action-setup@v6.1.0installed frompackageManager. Itspnpm install --frozen-lockfilestep passed, and so did the test job. docker build -f docker/Dockerfileran with corepack pnpm 12.6.0. The frozen install passed, andtsc --noEmitpassed inside the image.- pnpm 10.34.5 with
--config.manage-package-manager-versions=falsealso completedpnpm install --frozen-lockfileagainst this lockfile. It printed "Done in 5.3s using pnpm v10.34.5" and noERR_PNPM_BROKEN_LOCKFILE. - agent-sdk
mainalready carries the same two-document lockfile under pnpm 12.
I found one related limit, and it is outside this lockfile. A non-corepack pnpm 10 cannot switch itself to 12.6.0, because pnpm 12's package has no bin/ directory. Corepack shims, which the Mac and gtr use, switch correctly.
Every dependency the inventory found out of date now moves to its latest release, with one exception:
agent-trace-contractgoes to the newest 1.x release. The change also moves pnpm to 12.6.0, the GitHub Actions to their current majors, and both images to Node 24.What moves
tests/runtime-consumerpinspnpm update -r --depth 20)packageManager: pnpm@12.6.0. CI no longer passesversion: 11, and the pnpm 9/10onlyBuiltDependencieslist is removed because pnpm 12 refuses settings it does not recognisedocker/Dockerfileanddocker/Dockerfile.cli-runtimemove fromnode:22-slimtonode:24-slim. The app image installs with pnpm 12.6.0 and copiespnpm-workspace.yamlbefore the install, soallowBuildsbuilds better-sqlite3 during the install.minimumReleaseAgeExcludenow lists only the four first-party versions that published within the last day. The old exact-version entries are gone because those versions are older than the release-age window.Why trace-contract stays on 1.x
src/trace/contract-build.tsrefuses a lockfile that pins more than oneagent-trace-contractbuild. agent-runtime 0.283.0 and agent-eval 0.200.1 still declare trace-contract^1.2.0and^1.3.0. With the root on 2.0.0, the runtime-consumer workspace locked both builds, andtests/trace-emitter.test.tsfailed. trace-contract 2.0.0 only removes the unusedATTR.sideEffect, so the root can move once Runtime and Eval accept 2.x.Verification (drew-gtr-pro, Node 22.23.2, pnpm 12.6.0, no machine pnpm config)
pnpm install --frozen-lockfilepassed. better-sqlite3 built throughallowBuilds.pnpm build(tsc --noEmit) passed with 0 errors.pnpm testpassed: vitest ran 72 files with 1207 tests passing and 19 skipped, and the runtime-consumer regression passed 1 of 1 against agent-runtime 0.283.0 and agent-eval 0.200.1.docker build -f docker/Dockerfile.cli-runtime --build-arg CLI_BRIDGE_HARNESSES=codexpassed. The image reports Node v24.21.0, codex-cli 0.158.0 and iptables 1.8.9.docker build -f docker/Dockerfilepassed with the final lockfile. pnpm v12.6.0 ran the install, andtsc --noEmitpassed inside the image. The image runs Node v24.21.0, and better-sqlite3 opened an in-memory database.No running bridge was restarted. The Mac and gtr services keep their current checkouts until someone redeploys them.
Rollback: revert the squash commit.