Repair development tooling audit with unchanged runtime output - #7
Merged
Merged
Conversation
Update Vitest to 3.2.6 and scope esbuild 0.28.1 to tsup. Retain runtime requirements and document actual install/check/package continuity, full audit zero and the unchanged provider/UI limits.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The existing NodeAgent development installation retained nine advisory entries, including a critical Vitest finding. Update Vitest to 3.2.6, apply an esbuild 0.28.1 override only to tsup, and reconcile the affected development dependencies. Runtime requirements, exports, CLI, templates and test configuration stay unchanged.
The actual local installation passed ordinary npm ci, npm ls, the unchanged npm run check (57 tests in nine files, types, library/Vite build, tours and existing local scenarios), full npm audit with zero findings, and npm pack. Independent review reopened the exact three-owner diff and all native logs. The actual 37-member tar differs only in development package metadata; its other 36 bodies and all nine build outputs match the previously reviewed runtime package. Convex, tsx and tsup resolve the shared esbuild 0.28.1 installation; the Windows binary matches the preserved prior Convex binary.
Convex remains unconfigured and live-provider execution is skipped. Official Omnigent was absent locally; separate npm omniagent probes passed. Historical generated receipts were restored after preserving the new outputs. No browser, human/device, provider, deployment, package-registry publication or full-readiness claim is added. First shared CI passed on exact head f1ed9f0: NodeAgent CI run 34161296266 passed all 57 tests across nine files, types/build and production audit zero; conformance run 34161296806 passed its four contract declarations, and GitGuardian succeeded. Both Actions runs completed on attempt one. The dedicated official Omnigent probe passed through uv; its existing command checks help/run-help only. The separate prepush PATH probe still reports official Omnigent absent, and no provider execution is claimed. Full installed audit zero is separately bound local evidence. The conformance workflow's separate NodeKit installation reported three advisories; those are outside the NodeAgent lock.