Skip to content

chore(deps): move every dependency to its latest release - #244

Merged
drewstone merged 1 commit into
mainfrom
chore/deps-latest-20260928
Sep 28, 2026
Merged

drewstone merged 1 commit into
mainfrom
chore/deps-latest-20260928

Conversation

@drewstone

Copy link
Copy Markdown
Owner

Every dependency the inventory found out of date now moves to its latest release, with one exception: agent-trace-contract goes to the newest 1.x release. The change also moves pnpm to 12.6.0, the GitHub Actions to their current majors, and both images to Node 24.

What moves

Group Change
Runtime dependencies agent-interface 2.12.0 -> 2.13.1, agent-profile-materialize 0.19.2 -> 0.20.3, agent-trace-contract ^1.0.2 -> ^1.3.0, hono ^4.13.9, zod ^4.6.5
Dev dependencies vitest 4.1.11 -> 5.0.2, @types/node ^26.6.3, tsx ^4.23.15
tests/runtime-consumer pins agent-eval 0.182.0 -> 0.200.1, agent-runtime 0.231.1 -> 0.283.0, sandbox 0.37.1 -> 0.55.3, agent-interface 2.13.1, agent-profile-materialize 0.20.3
Transitive packages refreshed within their declared ranges (pnpm update -r --depth 20)
pnpm packageManager: pnpm@12.6.0. CI no longer passes version: 11, and the pnpm 9/10 onlyBuiltDependencies list is removed because pnpm 12 refuses settings it does not recognise
Actions checkout v7, setup-node v7, pnpm/action-setup v6.1.0 (the floating v6 tag does not include pnpm 12 support)
Images docker/Dockerfile and docker/Dockerfile.cli-runtime move from node:22-slim to node:24-slim. The app image installs with pnpm 12.6.0 and copies pnpm-workspace.yaml before the install, so allowBuilds builds better-sqlite3 during the install.

minimumReleaseAgeExclude now lists only the four first-party versions that published within the last day. The old exact-version entries are gone because those versions are older than the release-age window.

Why trace-contract stays on 1.x

src/trace/contract-build.ts refuses a lockfile that pins more than one agent-trace-contract build. agent-runtime 0.283.0 and agent-eval 0.200.1 still declare trace-contract ^1.2.0 and ^1.3.0. With the root on 2.0.0, the runtime-consumer workspace locked both builds, and tests/trace-emitter.test.ts failed. trace-contract 2.0.0 only removes the unused ATTR.sideEffect, so the root can move once Runtime and Eval accept 2.x.

Verification (drew-gtr-pro, Node 22.23.2, pnpm 12.6.0, no machine pnpm config)

  • pnpm install --frozen-lockfile passed. better-sqlite3 built through allowBuilds.
  • pnpm build (tsc --noEmit) passed with 0 errors.
  • pnpm test passed: vitest ran 72 files with 1207 tests passing and 19 skipped, and the runtime-consumer regression passed 1 of 1 against agent-runtime 0.283.0 and agent-eval 0.200.1.
  • docker build -f docker/Dockerfile.cli-runtime --build-arg CLI_BRIDGE_HARNESSES=codex passed. The image reports Node v24.21.0, codex-cli 0.158.0 and iptables 1.8.9.
  • docker build -f docker/Dockerfile passed with the final lockfile. pnpm v12.6.0 ran the install, and tsc --noEmit passed inside the image. The image runs Node v24.21.0, and better-sqlite3 opened an in-memory database.

No running bridge was restarted. The Mac and gtr services keep their current checkouts until someone redeploys them.

Rollback: revert the squash commit.

agent-interface 2.13.1, agent-profile-materialize 0.20.3, hono 4.13.9,
zod 4.6.5, vitest 5.0.2, @types/node 26.6.3 and tsx 4.23.15. The
runtime-consumer regression now pins agent-eval 0.200.1, agent-runtime
0.283.0 and sandbox 0.55.3. Transitive packages are refreshed within
their ranges.

agent-trace-contract moves to ^1.3.0, not 2.0.0: contract-build.ts
refuses a lockfile with two contract builds, and agent-runtime 0.283.0
and agent-eval 0.200.1 still require 1.x.

pnpm 12.6.0 is pinned through packageManager, so CI drops its version
input and the pnpm 9/10 onlyBuiltDependencies list. Actions move to
checkout v7, setup-node v7 and pnpm/action-setup v6.1.0. Both images
move to node:24-slim, and the app image installs with pnpm 12.6.0 after
copying pnpm-workspace.yaml, so allowBuilds builds better-sqlite3.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T05:44:59.261398Z 8cc46c3 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 8cc46c37

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-28T05:42:40Z

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8cc46c3772

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pnpm-lock.yaml
'@pnpm/exe.win32-arm64': 12.6.0
'@pnpm/exe.win32-x64': 12.6.0

---

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove the extra YAML document from the lockfile

The committed lockfile contains two YAML documents: a standalone pnpm bootstrap lock occupies lines 1–157, while the actual workspace lock starts here. Consequently, every CI, Docker, or developer install that reads this file fails before dependency resolution with ERR_PNPM_BROKEN_LOCKFILE: expected a single document in the stream, but found more, including the workflow's pnpm install --frozen-lockfile.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked this, and it does not reproduce. pnpm 12 writes the leading document on purpose: it locks the package manager itself through packageManagerDependencies. The file parses for every pnpm that installs this repo.

  • CI run 36383060685 on this head passed with pnpm 12.6.0, which pnpm/action-setup@v6.1.0 installed from packageManager. Its pnpm install --frozen-lockfile step passed, and so did the test job.
  • docker build -f docker/Dockerfile ran with corepack pnpm 12.6.0. The frozen install passed, and tsc --noEmit passed inside the image.
  • pnpm 10.34.5 with --config.manage-package-manager-versions=false also completed pnpm install --frozen-lockfile against this lockfile. It printed "Done in 5.3s using pnpm v10.34.5" and no ERR_PNPM_BROKEN_LOCKFILE.
  • agent-sdk main already carries the same two-document lockfile under pnpm 12.

I found one related limit, and it is outside this lockfile. A non-corepack pnpm 10 cannot switch itself to 12.6.0, because pnpm 12's package has no bin/ directory. Corepack shims, which the Mac and gtr use, switch correctly.

@drewstone
drewstone merged commit d83f854 into main Sep 28, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants