Skip to content

chore: update dependencies to their latest compatible versions - #1630

Merged
joshunrau merged 2 commits into
DouglasNeuroInformatics:mainfrom
joshunrau:deps
Oct 5, 2026
Merged

joshunrau merged 2 commits into
DouglasNeuroInformatics:mainfrom
joshunrau:deps

Conversation

@joshunrau

Copy link
Copy Markdown
Collaborator

Moves every dependency outside vendor/ to its newest release that clears the 7-day minimumReleaseAge and whose breaking changes need no code change here. React stays on 19.1, because the react19 catalog feeds vendor/.

Changes

chore commit

  • 87 direct dependencies change version. The majors are:
    • @nestjs/jwt, passport and axios 12
    • mongodb 7, mongodb-memory-server 11, nodemailer 10, faker 10, msgpackr 2
    • esbuild 0.28 (bundled instrument output is byte-identical to 0.23), Vite 7, es-module-lexer 2, glob 13, commander 15, chalk 6
    • motion 13, react-dropzone 20, react-error-boundary 6, react-resizable-panels 3, immer 11, serialize-error 13
    • sirv 3, sqlite3 6, env-cmd 11, knip 6, prettier-plugin-tailwindcss 0.8, tailwind-merge 3
  • Three new exact or tilde pins hold packages below a release that breaks this repo: Storybook 10.5.6, faker ~10.2.0, happy-dom ~20.11.15.
  • The framer-motion override is replaced by fastify@5: ^5.12.5. @nestjs/platform-fastify 11.2.6 pins fastify to exactly 5.11.3, and without the override the server would miss the 5.12 security fixes.
  • @types/nodemailer is dropped, because nodemailer 10 ships its own types.
  • react-core's optional router peer floor is raised, so only one router version is installed.
  • The Dockerfile turbo pins move to 2.11.5, and the agent-guidance block turbo writes to AGENTS.md is kept.

style commit

  • Formatting only: Prettier 3.9, Tailwind classes re-sorted in v4 order, and route-tree.ts regenerated by the new router plugin (lines move, no route changes).

Not upgraded

Each of these has an issue with the exact reason and what is required:

Verification

  • pnpm lint: 34/34 tasks pass.
  • pnpm test: 179 files and 1,661 tests pass, with no unhandled errors.
  • pnpm build: 13/13 tasks pass. It was run with RELEASE_VERSION set, because the api's production build requires it.
  • pnpm test:e2e: 276 of 277 pass.

Exceptions:

  • record-file-deletion.spec.ts fails locally. The local .env has no STORAGE_ENABLED, so the api returns 503 before reaching S3. This is unrelated to the upgrade.
  • No new unit or e2e test. This is a dependency update, and the existing suites are the check.
  • Not exercised:
    • production bundles at runtime (e2e runs against the dev servers)
    • Docker image builds
    • the Storybook UI
    • knip, which cannot run in this checkout

Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com

joshunrau and others added 2 commits October 4, 2026 21:21
Move every dependency outside vendor/ to the newest release, aged past minimumReleaseAge, whose
breaking changes need no code change here. React stays on 19.1 because the react19 catalog
feeds vendor/.

Held at the last compatible release:
- storybook 10.5.6: 10.5.7+ loses the contextual type of decorator args in stories
- @faker-js/faker ~10.2.0: 10.3 adds 'generic' to sexType(), which the subject sex enum rejects
- happy-dom ~20.11.15: 20.12's Element.animate leaves cancelled animations' finished promise
  rejected and unhandled, which motion 13 triggers in tests
- vite 7, es-module-lexer 2, monaco-editor 0.54, react-resizable-panels 3, lucide-react 0.577,
  js-yaml 4, recharts 2, @cap.js/server 2, @casl/* 6/1, astro 5, starlight 0.34, typedoc 0.27

Blocked by the peer ranges of @douglasneuroinformatics/* packages: NestJS 12, Prisma 7, vitest 5,
ESLint 10, TypeScript 7, reflect-metadata 0.2, prettier-plugin-astro 1.

Alongside the version bumps:
- replace the framer-motion override with fastify@5, since @nestjs/platform-fastify pins
  fastify 5.11.3 and would otherwise keep the server off the 5.12 security fixes
- drop @types/nodemailer, now that nodemailer 10 ships its own types
- raise react-core's optional router peer floor so one router version is installed
- move the Dockerfile turbo pins to 2.11.5, and keep the agent guidance turbo writes to AGENTS.md
- remove the no-var disable directives ESLint 9.39 reports as unused

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Reformat with prettier 3.9 and prettier-plugin-tailwindcss 0.8. The plugin now sorts classes in
Tailwind v4 order, where 0.6 fell back to v3 order, and single-quotes @source paths in CSS.
Prettier 3.9 collapses short union types and empty-object comments onto one line.

Regenerate route-tree.ts with @tanstack/router-plugin 1.168, whose generator now orders routes
deterministically. The change only moves lines; no route is added, removed or altered.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@joshunrau
joshunrau merged commit 2c5f403 into DouglasNeuroInformatics:main Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant