You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dependabot #85 bumps only the plugin to 8.70.1; TypeScript 7.0.2 is outside the supported TypeScript range of current @typescript-eslint (verified: @typescript-eslint/eslint-plugin@8.71.0 peers typescript >=4.8.4 <6.1.0, eslint ^8.57.0 || ^9.0.0 || ^10.0.0), so #85 alone is insufficient.
Additional gaps found during PR 1 (#102) and its independent review (pre-existing on main):
No ESLint config file exists in vscode-extension (no eslint.config.* or .eslintrc*), so npm run lint exits 2 under ESLint 10 regardless of dependencies.
vsce package fails:ERROR @types/vscode ^1.138.0 greater than engines.vscode ^1.85.0. The extension cannot be packaged until @types/vscode and engines.vscode agree.
No engines.node / .nvmrc.
2. Outcome
From a clean checkout, npm ci, compile/typecheck, and ESLint pass with a mutually supported TypeScript/ESLint toolchain, enforced in CI against the exact lockfile.
3. Scope
vscode-extension/package.json, package-lock.json, ESLint config (flat eslint.config.*), tsconfig.json if needed, .nvmrc/engines, CI job (with Release gate 2).
4. Non-goals
No extension behavior/security changes (Release gate 5).
No unrelated dependency upgrades beyond what peer compatibility requires.
5. Dependencies
Unblocks Release gate 2 PR 3 (Node CI aggregate relevance) and Release gate 5 (security PRs need a working build).
6. PR breakdown
fix(vscode): align TypeScript and typescript-eslint peer ranges — pick versions from verified peer ranges; regenerate lockfile.
build(vscode): migrate lint configuration and scripts to the supported ESLint format — flat config; drop --ext.
ci(vscode): enforce clean install, compile, lint, and audit (coordinated with Release gate 2).
fix(vscode): align @types/vscode with engines.vscode — either raise engines.vscode (a support-policy decision; document it) or pin @types/vscode to the engine floor; prove with vsce package.
7. Acceptance criteria
npm ci passes without --force / --legacy-peer-deps.
Compile/typecheck and ESLint pass with zero newly suppressed findings.
Supported Node version documented and enforced consistently (engines + CI).
npx @vscode/vsce package succeeds from a clean checkout.
Dependabot cannot reintroduce an unsupported TypeScript major.
8. Risks and rollback
Lint migration may surface new findings — fix, do not suppress. Rollback by reverting the PR; the current state is already broken so regression risk is low.
9. Evidence to attach
Clean npm ci/compile/lint logs, peer-range verification output (npm view ... peerDependencies), CI run URL.
1. Problem / evidence
Reproduced 2026-10-03 (Node v24.19.0, npm 11.17.0) from a clean copy of
vscode-extension/package.json+package-lock.json:Declared devDependencies:
typescript ^7.0.2,eslint ^10.11.0,@typescript-eslint/eslint-plugin ^6.0.0,@typescript-eslint/parser ^8.70.1; lint scripteslint src --ext ts(legacy flag, removed in flat config).Dependabot #85 bumps only the plugin to 8.70.1; TypeScript 7.0.2 is outside the supported TypeScript range of current
@typescript-eslint(verified:@typescript-eslint/eslint-plugin@8.71.0peerstypescript >=4.8.4 <6.1.0,eslint ^8.57.0 || ^9.0.0 || ^10.0.0), so #85 alone is insufficient.Additional gaps found during PR 1 (#102) and its independent review (pre-existing on
main):vscode-extension(noeslint.config.*or.eslintrc*), sonpm run lintexits 2 under ESLint 10 regardless of dependencies.vsce packagefails:ERROR @types/vscode ^1.138.0 greater than engines.vscode ^1.85.0. The extension cannot be packaged until@types/vscodeandengines.vscodeagree.engines.node/.nvmrc.2. Outcome
From a clean checkout,
npm ci, compile/typecheck, and ESLint pass with a mutually supported TypeScript/ESLint toolchain, enforced in CI against the exact lockfile.3. Scope
vscode-extension/package.json,package-lock.json, ESLint config (flateslint.config.*),tsconfig.jsonif needed,.nvmrc/engines, CI job (with Release gate 2).4. Non-goals
5. Dependencies
Unblocks Release gate 2 PR 3 (Node CI aggregate relevance) and Release gate 5 (security PRs need a working build).
6. PR breakdown
fix(vscode): align TypeScript and typescript-eslint peer ranges— pick versions from verified peer ranges; regenerate lockfile.build(vscode): migrate lint configuration and scripts to the supported ESLint format— flat config; drop--ext.ci(vscode): enforce clean install, compile, lint, and audit(coordinated with Release gate 2).chore(deps): reconcile or supersede Node Dependabot PRs— close chore(deps-dev): bump @typescript-eslint/eslint-plugin from 6.21.0 to 8.70.1 in /vscode-extension #85 as superseded with link; re-evaluate chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /vscode-extension #82; add a Dependabotignorerule fortypescript >=6.1until typescript-eslint supports it.fix(vscode): align @types/vscode with engines.vscode— either raiseengines.vscode(a support-policy decision; document it) or pin@types/vscodeto the engine floor; prove withvsce package.7. Acceptance criteria
npm cipasses without--force/--legacy-peer-deps.engines+ CI).npx @vscode/vsce packagesucceeds from a clean checkout.8. Risks and rollback
Lint migration may surface new findings — fix, do not suppress. Rollback by reverting the PR; the current state is already broken so regression risk is low.
9. Evidence to attach
Clean
npm ci/compile/lint logs, peer-range verification output (npm view ... peerDependencies), CI run URL.10. Labels, milestone, estimate
Labels:
javascript,dependencies,bug. Milestone: v0.5.1 Release Readiness. Estimate: 1–2 days.