Skip to content

chore(deps): in-range refresh, Astro 7 docs, bun 1.4.2 pin, hold chat-react - #160

Merged
beeeku merged 4 commits into
masterfrom
chore/deps-refresh
Sep 29, 2026
Merged

beeeku merged 4 commits into
masterfrom
chore/deps-refresh

Conversation

@beeeku

@beeeku beeeku commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Summary

Prep for a dependency-only, non-breaking release. Four commits, each committed through maina commit with verification passing (13 tools, 0 errors). Please rebase-merge so they stay separate.

  1. chore(deps): in-range refresh + Astro 7 docs (closes docs: Astro 5 → 7 upgrade tracker (apps/docs) #115)
  2. chore(ci): pin bun 1.4.2 everywhere (closes test(pdf): bun test on packages/pdf red on master — module resolution / bun-vs-node vitest drift #146).
  3. chore(ci): drop the now-obsolete docs: Astro 5 → 7 upgrade tracker (apps/docs) #115 astro-major Dependabot ignore.
  4. chore(chat-react): mark private so the next release doesn't publish it for the first time.

Security

Trivy error findings in bun.lock: 25 → 0. This clears the critical Astro AVIF RCE and the other open Dependabot alerts on astro and vitest.

Verification (local, bun 1.4.2)

  • build 38/38, test 37/37, typecheck 51/51, lint: all green
  • constitution:check: 0 errors, 0 warnings
  • packages/pdf bun test: 51/51 (test(pdf): bun test on packages/pdf red on master — module resolution / bun-vs-node vitest drift #146 repro)
  • dist/ diff bun 1.3.8 vs 1.4.2 across 114 entry files: identical export sets; only identifier renames, chunk hashes, and .d.ts export order differ.
  • Docs: same 33 pages; astro check 0 errors. Landing and guide pages screenshot-compared against the Astro 5 build. The only visible change is the hero <h1>: leading-tight now applies as written, where Tailwind 3 had let text-5xl's line-height: 1 override it.

Release impact (changeset status)

Patch: ai, approval, mcp, mail, chat, notify (notify via its dependency on mail). chat-react is versioned but private, so it isn't published.

Closes #115, closes #146. Supersedes #148, #153, #154.

🤖 Generated with Claude Code

beeeku and others added 4 commits September 29, 2026 16:39
…#115)

Clears every error-level trivy finding in bun.lock (25 -> 0) so
`maina verify` passes without suppression.

Workspace refresh (`bun update -r`, no majors for shipped code):
- Runtime floors move only in approval/mcp (hono ^4.13.11, past the
  4.12.x advisories) and mail (mimetext ^3.0.28, postal-mime ^2.7.6);
  patch changeset included. Peer ranges unchanged.
- Folds in #153 (`@cloudflare/puppeteer` 1.4.0, dev-only) and #154
  (`valibot` 1.5.0). Pairs react + react-dom 19.3, superseding #148.
- Root override `@puppeteer/browsers` ^3.2.3 drops `extract-zip` 2.0.1
  (symlink file-write CVEs, no upstream fix). Dev-only; browser/pdf
  tests pass 35/35 and 51/51.

apps/docs (private, not published) — Astro 5 -> 7:
- astro ^7.2.10, @astrojs/starlight ^0.42.4, @astrojs/react ^7,
  @astrojs/starlight-tailwind ^5, tailwindcss ^4 via @tailwindcss/vite;
  drops @astrojs/tailwind and tailwind.config.ts (CSS-first config).
- Starlight 0.39+ sidebar: autogenerate moves into `items`.
- `bg-gradient-to-r` -> `bg-linear-to-r` (Tailwind 4 rename).
- Fixes the critical AVIF RCE plus SSRF/XSS advisories on astro.
- Same 33 pages built; `astro check` 0 errors; landing + guide pages
  screenshot-compared against the Astro 5 build.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
bun 1.3.9–1.3.11 shipped a Bun.build() regression that dropped sibling
modules from entry files made of pure named re-exports, breaking local
builds of 31/33 packages for anyone not on the 1.3.8 CI pin. bun 1.4.2
fixes it: the full workspace builds (38/38), tests (37/37), and
`packages/pdf` passes `bun test` 51/51.

dist/ output was diffed 1.3.8 vs 1.4.2 across all 114 entry files:
identical export sets; differences are limited to local identifier
renames, chunk hashes, and .d.ts export ordering.

Also pins deploy-docs.yml (was `latest`) and maina-ci.yml (was unpinned)
so every workflow runs the same bun.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Astro 7 migration landed in the previous commit, so the /apps/docs
ignore that held astro majors back is obsolete. Removing it per its own
comment so Dependabot resumes proposing astro majors.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@workkit/chat-react has never been published. `changeset publish`
pushes every public package whose version is missing from npm, so the
next release would ship it as a brand-new package. Holding it back for
this dependency-only release; flip `private` off when it is ready to
launch. The CLI's sync-versions script already skips private packages,
so `workkit init` will not scaffold it either.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 11:11
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 32 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 201f9705-d4f3-4593-a75c-58068b35c9c6

📥 Commits

Reviewing files that changed from the base of the PR and between 216a96f and ddad551.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (36)
  • .changeset/deps-refresh-2026-09.md
  • .github/dependabot.yml
  • .github/workflows/ci.yml
  • .github/workflows/deploy-docs.yml
  • .github/workflows/maina-ci.yml
  • .github/workflows/release.yml
  • .github/workflows/size-report.yml
  • .maina/constitution.md
  • apps/docs/astro.config.mjs
  • apps/docs/package.json
  • apps/docs/src/components/Landing.tsx
  • apps/docs/src/styles/global.css
  • apps/docs/tailwind.config.ts
  • integrations/hono/package.json
  • package.json
  • packages/agent/package.json
  • packages/api/package.json
  • packages/approval/package.json
  • packages/browser/package.json
  • packages/chat-react/package.json
  • packages/cli/package.json
  • packages/env/package.json
  • packages/features/package.json
  • packages/health/package.json
  • packages/kv/package.json
  • packages/logger/package.json
  • packages/mail/package.json
  • packages/mcp/package.json
  • packages/memory/package.json
  • packages/notify/package.json
  • packages/pdf/package.json
  • packages/realtime/package.json
  • packages/testing/package.json
  • packages/turnstile/package.json
  • packages/types/package.json
  • packages/workflow/package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Bundle Size Report

Package Base PR Delta
@workkit/agent 82KiB 82KiB no change
@workkit/ai 94KiB 94KiB no change
@workkit/ai-gateway 260KiB 260KiB no change
@workkit/api 119KiB 119KiB no change
@workkit/approval 106KiB 106KiB no change
@workkit/astro 18KiB 18KiB no change
@workkit/auth 48KiB 48KiB no change
@workkit/browser 32KiB 32KiB no change
@workkit/cache 39KiB 39KiB no change
@workkit/chat 47KiB 47KiB no change
@workkit/chat-react 20KiB 20KiB no change
@workkit/cli 286KiB 310KiB +25KiB
@workkit/cron 68KiB 68KiB no change
@workkit/crypto 41KiB 41KiB no change
@workkit/d1 90KiB 90KiB no change
@workkit/do 58KiB 58KiB no change
@workkit/env 43KiB 43KiB no change
@workkit/errors 40KiB 40KiB no change
@workkit/features 23KiB 23KiB no change
@workkit/health 19KiB 19KiB no change
@workkit/hono 36KiB 36KiB no change
@workkit/kv 52KiB 52KiB no change
@workkit/logger 24KiB 24KiB no change
@workkit/mail 54KiB 54KiB no change
@workkit/mcp 127KiB 127KiB no change
@workkit/memory 41KiB 41KiB no change
@workkit/notify 290KiB 290KiB no change
@workkit/pdf 36KiB 36KiB no change
@workkit/queue 54KiB 54KiB no change
@workkit/r2 57KiB 57KiB no change
@workkit/ratelimit 51KiB 51KiB no change
@workkit/realtime 44KiB 44KiB no change
@workkit/remix 34KiB 34KiB no change
@workkit/testing 115KiB 115KiB no change
@workkit/turnstile 14KiB 14KiB no change
@workkit/types 21KiB 21KiB no change
@workkit/workflow 46KiB 46KiB no change

@beeeku
beeeku merged commit 8d32646 into master Sep 29, 2026
10 checks passed
@beeeku
beeeku deleted the chore/deps-refresh branch September 29, 2026 11:13

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The docs Tailwind ranges do not match the committed lockfile workspace snapshot, risking frozen-install failures.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Refreshes dependencies, modernizes the documentation stack, standardizes Bun 1.4.2, and prevents premature publication of chat-react.

Changes:

  • Updates runtime and development dependencies with a patch changeset.
  • Migrates docs to Astro 7, Starlight, and Tailwind 4.
  • Pins Bun across CI and marks chat-react private.
File Description
.changeset/​deps-refresh-2026-09.md Records runtime dependency patches.
.github/​dependabot.yml Resumes Astro major updates.
.github/​workflows/​ci.yml Pins Bun 1.4.2.
.github/​workflows/​deploy-docs.yml Pins docs deployment Bun.
.github/​workflows/​maina-ci.yml Pins Maina CI Bun.
.github/​workflows/​release.yml Pins release Bun.
.github/​workflows/​size-report.yml Pins size-report Bun.
.maina/​constitution.md Updates the prescribed Bun version.
apps/​docs/​astro.config.mjs Migrates Astro and Tailwind configuration.
apps/​docs/​package.json Upgrades the docs stack.
apps/​docs/​src/​components/​Landing.tsx Uses Tailwind 4 gradient syntax.
apps/​docs/​src/​styles/​global.css Adopts Tailwind 4 CSS imports.
apps/​docs/​tailwind.config.ts Removes obsolete Tailwind 3 configuration.
bun.lock Resolves the refreshed dependency graph.
integrations/​hono/​package.json Refreshes Hono and Zod.
package.json Refreshes tooling, overrides, and Bun.
packages/​agent/​package.json Refreshes validation libraries.
packages/​api/​package.json Refreshes Zod.
packages/​approval/​package.json Raises Hono and Workers type floors.
packages/​browser/​package.json Updates Cloudflare Puppeteer.
packages/​chat-react/​package.json Marks the package private and updates types.
packages/​cli/​package.json Refreshes CLI development tooling.
packages/​env/​package.json Refreshes schema validators.
packages/​features/​package.json Refreshes Node types and Hono.
packages/​health/​package.json Refreshes Hono.
packages/​kv/​package.json Refreshes schema validators.
packages/​logger/​package.json Refreshes Node types and Hono.
packages/​mail/​package.json Raises mail dependency floors.
packages/​mcp/​package.json Refreshes Hono, Workers types, and Zod.
packages/​memory/​package.json Refreshes Workers types.
packages/​notify/​package.json Refreshes SQLite and Zod.
packages/​pdf/​package.json Updates Cloudflare Puppeteer.
packages/​realtime/​package.json Refreshes Workers types.
packages/​testing/​package.json Refreshes Node types.
packages/​turnstile/​package.json Refreshes Hono.
packages/​types/​package.json Refreshes Standard Schema.
packages/​workflow/​package.json Refreshes Workers types.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread apps/docs/package.json
"@astrojs/react": "^7.0.0",
"@astrojs/starlight": "^0.42.4",
"@astrojs/starlight-tailwind": "^5.0.0",
"@tailwindcss/vite": "^4.3.3",
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test(pdf): bun test on packages/pdf red on master — module resolution / bun-vs-node vitest drift docs: Astro 5 → 7 upgrade tracker (apps/docs)

2 participants