Skip to content

refactor: swap @inquirer/prompts umbrella for granular packages - #39

Merged
ManningWorks merged 2 commits into
mainfrom
refactor/granular-inquirer-deps
Sep 19, 2026
Merged

ManningWorks merged 2 commits into
mainfrom
refactor/granular-inquirer-deps

Conversation

@ManningWorks

Copy link
Copy Markdown
Owner

Follow-up to #38. Removes the tmp override that PR added, by removing the reason it existed.

Why

@inquirer/prompts is an umbrella that bundles ten prompts — including editor, which Projex never calls. editor is the only consumer of external-editor, which pins tmp 0.0.33 (2016-era, published advisories). No parent range reaches a patched tmp, which is why #38 needed an override.

The five prompts Projex actually uses are published granularly in the same scope, with identical call signatures, and none of them touch external-editor/tmp.

What

  • @inquirer/prompts → @inquirer/input + @inquirer/select + @inquirer/confirm as optional peers (matching the old umbrella contract)
  • 13 src files: named umbrella imports → default granular imports; call sites untouched
  • 10 test files: vi.mock('@inquirer/prompts', ...) → per-package vi.mock('@inquirer/input', () => ({ default: vi.fn() })) etc.
  • tmp override deleted from root package.json (vite override stays — unrelated vitepress reason)

Result

pnpm -r why tmp and pnpm -r why external-editor both return empty — the vulnerable packages no longer enter the dependency tree at all. pnpm audit: no known vulnerabilities.

Gate

  • build / typecheck / lint clean
  • 62 test files, 1036 tests pass
  • docs site builds (vite override untouched)

Note: @inquirer/search and @inquirer/number are declared as optional peers but imported nowhere — kept for parity with the umbrella's old surface; happy to drop them if you'd rather declare only what's used.

Refresh the lockfile with pnpm update -r so ranges resolve past the
published vulnerable ranges, then add two pnpm overrides for the deps
whose parent ranges can't reach a patched version: tmp ^0.2.6
(external-editor pins ^0.0.33) and vite ^7.3.6 (vitepress 1.x locks
vite 5 through plugin-vue). vitepress bumped to ^1.6.4.

30 alerts (40 advisories) -> 0. Docs site builds clean on vite 7.
Import only the five granular @InQuirer prompt packages the CLI uses,
as optional peers. This drops external-editor/tmp (2016-era pkg with
published advisories) from the tree, so the tmp pnpm override is no
longer needed and is removed. The prompts used are unchanged; tests
are re-mocked per package.
@vercel

vercel Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
projex-docs Ready Ready Preview Sep 19, 2026 11:06am UTC

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 17bfc49c-d80b-4657-8b0b-0d3e8ea55b74


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ManningWorks
ManningWorks marked this pull request as ready for review September 19, 2026 11:52
@ManningWorks
ManningWorks merged commit 7c97f14 into main Sep 19, 2026
7 checks passed

This branch was successfully deployed

1 active deployment
Preview — c8348069 Deployed Sep 19, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant