Repository navigation
chore(deps): in-range refresh, Astro 7 docs, bun 1.4.2 pin, hold chat-react - #160
Conversation
…#115) Clears every error-level trivy finding in bun.lock (25 -> 0) so `maina verify` passes without suppression. Workspace refresh (`bun update -r`, no majors for shipped code): - Runtime floors move only in approval/mcp (hono ^4.13.11, past the 4.12.x advisories) and mail (mimetext ^3.0.28, postal-mime ^2.7.6); patch changeset included. Peer ranges unchanged. - Folds in #153 (`@cloudflare/puppeteer` 1.4.0, dev-only) and #154 (`valibot` 1.5.0). Pairs react + react-dom 19.3, superseding #148. - Root override `@puppeteer/browsers` ^3.2.3 drops `extract-zip` 2.0.1 (symlink file-write CVEs, no upstream fix). Dev-only; browser/pdf tests pass 35/35 and 51/51. apps/docs (private, not published) — Astro 5 -> 7: - astro ^7.2.10, @astrojs/starlight ^0.42.4, @astrojs/react ^7, @astrojs/starlight-tailwind ^5, tailwindcss ^4 via @tailwindcss/vite; drops @astrojs/tailwind and tailwind.config.ts (CSS-first config). - Starlight 0.39+ sidebar: autogenerate moves into `items`. - `bg-gradient-to-r` -> `bg-linear-to-r` (Tailwind 4 rename). - Fixes the critical AVIF RCE plus SSRF/XSS advisories on astro. - Same 33 pages built; `astro check` 0 errors; landing + guide pages screenshot-compared against the Astro 5 build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
bun 1.3.9–1.3.11 shipped a Bun.build() regression that dropped sibling modules from entry files made of pure named re-exports, breaking local builds of 31/33 packages for anyone not on the 1.3.8 CI pin. bun 1.4.2 fixes it: the full workspace builds (38/38), tests (37/37), and `packages/pdf` passes `bun test` 51/51. dist/ output was diffed 1.3.8 vs 1.4.2 across all 114 entry files: identical export sets; differences are limited to local identifier renames, chunk hashes, and .d.ts export ordering. Also pins deploy-docs.yml (was `latest`) and maina-ci.yml (was unpinned) so every workflow runs the same bun. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Astro 7 migration landed in the previous commit, so the /apps/docs ignore that held astro majors back is obsolete. Removing it per its own comment so Dependabot resumes proposing astro majors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@workkit/chat-react has never been published. `changeset publish` pushes every public package whose version is missing from npm, so the next release would ship it as a brand-new package. Holding it back for this dependency-only release; flip `private` off when it is ready to launch. The CLI's sync-versions script already skips private packages, so `workkit init` will not scaffold it either. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 32 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (36)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bundle Size Report
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The docs Tailwind ranges do not match the committed lockfile workspace snapshot, risking frozen-install failures.
Review effort: Balanced
Findings: 1
What changed in this PR
Refreshes dependencies, modernizes the documentation stack, standardizes Bun 1.4.2, and prevents premature publication of chat-react.
Changes:
- Updates runtime and development dependencies with a patch changeset.
- Migrates docs to Astro 7, Starlight, and Tailwind 4.
- Pins Bun across CI and marks
chat-reactprivate.
| File | Description |
|---|---|
.changeset/deps-refresh-2026-09.md |
Records runtime dependency patches. |
.github/dependabot.yml |
Resumes Astro major updates. |
.github/workflows/ci.yml |
Pins Bun 1.4.2. |
.github/workflows/deploy-docs.yml |
Pins docs deployment Bun. |
.github/workflows/maina-ci.yml |
Pins Maina CI Bun. |
.github/workflows/release.yml |
Pins release Bun. |
.github/workflows/size-report.yml |
Pins size-report Bun. |
.maina/constitution.md |
Updates the prescribed Bun version. |
apps/docs/astro.config.mjs |
Migrates Astro and Tailwind configuration. |
apps/docs/package.json |
Upgrades the docs stack. |
apps/docs/src/components/Landing.tsx |
Uses Tailwind 4 gradient syntax. |
apps/docs/src/styles/global.css |
Adopts Tailwind 4 CSS imports. |
apps/docs/tailwind.config.ts |
Removes obsolete Tailwind 3 configuration. |
bun.lock |
Resolves the refreshed dependency graph. |
integrations/hono/package.json |
Refreshes Hono and Zod. |
package.json |
Refreshes tooling, overrides, and Bun. |
packages/agent/package.json |
Refreshes validation libraries. |
packages/api/package.json |
Refreshes Zod. |
packages/approval/package.json |
Raises Hono and Workers type floors. |
packages/browser/package.json |
Updates Cloudflare Puppeteer. |
packages/chat-react/package.json |
Marks the package private and updates types. |
packages/cli/package.json |
Refreshes CLI development tooling. |
packages/env/package.json |
Refreshes schema validators. |
packages/features/package.json |
Refreshes Node types and Hono. |
packages/health/package.json |
Refreshes Hono. |
packages/kv/package.json |
Refreshes schema validators. |
packages/logger/package.json |
Refreshes Node types and Hono. |
packages/mail/package.json |
Raises mail dependency floors. |
packages/mcp/package.json |
Refreshes Hono, Workers types, and Zod. |
packages/memory/package.json |
Refreshes Workers types. |
packages/notify/package.json |
Refreshes SQLite and Zod. |
packages/pdf/package.json |
Updates Cloudflare Puppeteer. |
packages/realtime/package.json |
Refreshes Workers types. |
packages/testing/package.json |
Refreshes Node types. |
packages/turnstile/package.json |
Refreshes Hono. |
packages/types/package.json |
Refreshes Standard Schema. |
packages/workflow/package.json |
Refreshes Workers types. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "@astrojs/react": "^7.0.0", | ||
| "@astrojs/starlight": "^0.42.4", | ||
| "@astrojs/starlight-tailwind": "^5.0.0", | ||
| "@tailwindcss/vite": "^4.3.3", |

Summary
Prep for a dependency-only, non-breaking release. Four commits, each committed through
maina commitwith verification passing (13 tools, 0 errors). Please rebase-merge so they stay separate.chore(deps): in-range refresh + Astro 7 docs (closes docs: Astro 5 → 7 upgrade tracker (apps/docs) #115)bun update -rwith no majors for shipped code. Runtime floors move only inapproval/mcp(hono^4.13.11, past the 4.12.x advisories) andmail(mimetext^3.0.28,postal-mime^2.7.6). Patch changeset included; peer ranges unchanged.@cloudflare/puppeteer1.4.0, dev) and chore(deps-dev): bump valibot from 1.3.1 to 1.5.0 #154 (valibot1.5.0), and pairsreact+react-dom19.3 (supersedes chore(deps): bump react-dom and @types/react-dom #148).@puppeteer/browsers^3.2.3 removesextract-zip2.0.1 (no upstream fix). Dev-only.apps/docs: Astro 7, Starlight 0.42,@astrojs/react7, Tailwind 4 via@tailwindcss/vite. Sidebarautogeneratemoved intoitems;bg-gradient-to-r→bg-linear-to-r.chore(ci): pin bun 1.4.2 everywhere (closes test(pdf):bun testonpackages/pdfred on master — module resolution / bun-vs-node vitest drift #146).chore(ci): drop the now-obsolete docs: Astro 5 → 7 upgrade tracker (apps/docs) #115 astro-major Dependabot ignore.chore(chat-react): markprivateso the next release doesn't publish it for the first time.Security
Trivy error findings in
bun.lock: 25 → 0. This clears the critical Astro AVIF RCE and the other open Dependabot alerts onastroandvitest.Verification (local, bun 1.4.2)
constitution:check: 0 errors, 0 warningspackages/pdfbun test: 51/51 (test(pdf):bun testonpackages/pdfred on master — module resolution / bun-vs-node vitest drift #146 repro)dist/diff bun 1.3.8 vs 1.4.2 across 114 entry files: identical export sets; only identifier renames, chunk hashes, and.d.tsexport order differ.astro check0 errors. Landing and guide pages screenshot-compared against the Astro 5 build. The only visible change is the hero<h1>:leading-tightnow applies as written, where Tailwind 3 had lettext-5xl'sline-height: 1override it.Release impact (
changeset status)Patch:
ai,approval,mcp,mail,chat,notify(notify via its dependency on mail).chat-reactis versioned but private, so it isn't published.Closes #115, closes #146. Supersedes #148, #153, #154.
🤖 Generated with Claude Code