Skip to content

chore(deps): update all workspace dependencies (Copilot SDK 1.x, Zod 4, Tailwind 4, Biome 2) - #82

Merged
BOTOOM merged 14 commits into
masterfrom
devin/1790963176-update-deps
Oct 2, 2026
Merged

BOTOOM merged 14 commits into
masterfrom
devin/1790963176-update-deps

Conversation

@BOTOOM

@BOTOOM BOTOOM commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Description

Updates every workspace (backend, extension, website, shared, e2e, root tooling) to current stable releases, and replaces Dependabot PRs #69 (postcss), #73 (vitest), #74 (sharp), #78 (fastify) and #79 (next). I only picked versions published at least ~7 days ago. All root pnpm.overrides security pins are kept; postcss and undici were raised to match the new majors.

Key bumps

Area Before → After
Copilot CLI / SDK @github/copilot 1.0.64 → 1.0.88, @github/copilot-sdk 0.3.0 → 1.0.14
Backend runtime fastify 5.12.5, @fastify/cors 11, better-sqlite3 11 → 13, sharp 0.35, pino 10, zod 3 → 4, drizzle-orm 0.45.3
Extension wxt 0.21, Tailwind 3 → 4, tailwind-merge 3, jsdom 30, React 19.3, lucide-react 1.x
Website next 16.3.6, Tailwind 4.3, lucide-react 1.x
Tooling TypeScript 6.0, Biome 1.9 → 2.5, Vitest 5, semantic-release 25.0.9 + plugins, Playwright 1.63

Code adaptations

  • Zod 4: error.errors → error.issues in routes/chat.ts, routes/images.ts, routes/sessions.ts.
  • Copilot SDK 1.x: new CopilotClient({ cliPath }) → new CopilotClient({ connection: RuntimeConnection.forStdio({ path }) }). The CLI path now comes from import.meta.resolve('@github/copilot/npm-loader.js'), and the loader picks the platform binary itself, so the hand-written platform/musl candidate list is gone. session.destroy() → session.disconnect().
  • Tailwind 4 (extension): tailwind.config.js removed. The theme moved to @theme in styles.css, @layer components classes became @utility, and PostCSS uses @tailwindcss/postcss. A v3-compatible default border color is kept in @layer base.
  • lucide-react 1.x dropped brand icons, so the website uses a local GithubIcon SVG instead.
  • Biome 2: the config was migrated (files.includes, assist). Rules that Biome 2 newly enables in recommended are turned off, so the lint baseline stays the same. Generated packages/shared/src/**/*.js files are excluded. The biome format churn sits in its own style: commit.
  • better-sqlite3 13 ships N-API prebuilds for win/linux/mac and no longer depends on the deprecated prebuild-install. That removes the npm warn deprecated prebuild-install@7.1.3 users see on npx devmentorai-server. pnpm.neverBuiltDependencies: ["better-sqlite3"] keeps pnpm from running node-gyp on it; the prebuild is loaded instead.

Breaking: Node >= 22.12.0 is now required (root/backend/extension engines). better-sqlite3 13 and wxt 0.21 require Node 22, and the Copilot SDK requires ^20.19 || >=22.12. The release workflows already run on Node 22.

Not upgraded: ESLint stays on 9.x, because ESLint 10 crashes eslint-plugin-react@7.37.5 (react/display-name) in the website config. @types/node stays on 22.x to match the minimum runtime.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected) — Node >= 22.12 minimum
  • Documentation update
  • Refactoring (no functional changes)
  • Dependency update

Related Issues

Supersedes #69, #73, #74, #78, #79.

Checklist

  • My code compiles without errors (pnpm typecheck): backend, extension and website typecheck and build pass
  • Linter passes (pnpm lint): Biome reports 0 errors on an LF checkout, and website ESLint passes
  • Tests pass (pnpm test): extension 177/177. Backend 132 passed / 5 failed / 1 skipped on Windows; the 5 are the known Windows temp-path failures in tests/tools/devops-tools.test.ts, which also fail on master. CI (Linux) is authoritative.
  • I have added tests for new functionality (if applicable): N/A
  • I have updated documentation (if applicable)
  • My changes follow the project coding conventions

Other verification (Windows, Node 22.23.3):

  • pnpm install --frozen-lockfile works without a C++ toolchain, and so does npm install better-sqlite3@13.0.3; both load the prebuild.
  • node apps/backend/dist/server.js returns healthy on /api/health with copilotConnected: true, using the CLI resolved from npm-loader.js.
  • I loaded the built extension in Chrome; the options page and side panel (new-session modal, chat view) render correctly with Tailwind 4. A real chat round-trip was not tested because this box has no Copilot login.
  • pnpm audit: 37 advisories (1 low / 12 moderate / 24 high), down from 101 on master.
  • E2E (Playwright) not run: Chromium for Playwright is not installed here.

Screenshots (if applicable)

Options page (Tailwind 4 build):
options

Side panel chat view (Tailwind 4 build):
sidepanel

Link to Devin session: https://app.devin.ai/sessions/8b2b838f60104769933e2c0c4c7d3eb9
Open in Devin Desktop: https://app.devin.ai/desktop/session/8b2b838f60104769933e2c0c4c7d3eb9?variant=devin
Requested by: @BOTOOM

@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access that start with 'Devin'.

  • Disable automatic comment, CI, and merge conflict monitoring

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
devmentorai-website-cli Ready Ready Preview Oct 2, 2026 9:51pm UTC

@BOTOOM
BOTOOM marked this pull request as ready for review October 2, 2026 20:53

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 potential issues.

Devin Review

Comment thread apps/extension/src/entrypoints/content/SelectionToolbar.ts Outdated
Comment thread package.json
@@ -75,43 +75,7 @@ export class CopilotService {
try {
let cliPath: string | undefined;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Comprobar una conversación real tras migrar el SDK

La verificación descrita cubre el arranque, pero no un intercambio de chat autenticado. Conviene probar envío normal y SSE con Copilot SDK 1.x antes de publicar el backend.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

De acuerdo. No se puede hacer aquí: la máquina de pruebas no tiene sesión de Copilot, así que solo verifiqué arranque, /api/health (copilotConnected: true) y el modo mock. Antes de publicar, el autor tiene que probar con una cuenta autenticada un chat normal, un chat por SSE y una quick action. Dejo el hilo abierto hasta entonces.

@BOTOOM
BOTOOM merged commit dea543a into master Oct 2, 2026
9 checks passed

This branch was successfully deployed

1 active deployment
Preview — 63c01154 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant