Skip to content

chore(deps): bump dependencies and pinned GitHub Actions - #79

Merged
chybisov merged 1 commit into
mainfrom
chore/bump-deps-and-actions
Sep 18, 2026
Merged

chybisov merged 1 commit into
mainfrom
chore/bump-deps-and-actions

Conversation

@chybisov

Copy link
Copy Markdown
Member

Which Linear task is linked to this PR?

None — routine dependency maintenance.

Why was it implemented this way?

Refresh every dependency to latest except @noble/hashes, move the pinned package manager from pnpm 12.3.4 to 12.4.2, and re-pin the three GitHub Actions that have newer releases. Same shape as #75.

No runtime dependency changed, so this is chore-only and carries no changeset (per the CLAUDE.md exemption for .github/, lockfile and tooling-only changes).

Tooling

Package From To
vitest, @vitest/coverage-v8 5.0.0 5.0.1
@biomejs/biome 2.5.12 2.5.14
knip 6.35.1 6.36.0
@changesets/cli 3.0.2 3.0.3
@types/node 26.5.0 26.6.1
@types/react 19.2.18 19.3.0
@types/react-dom 19.2.7 19.3.0
react, react-dom (devDeps of @bigmi/react) 19.2.8 19.3.0
pnpm (packageManager) 12.3.4 12.4.2

GitHub Actions (SHA-pinned)

Action From To
pnpm/action-setup v6.0.10 v6.1.0
changesets/action v2.1.0 v2.1.2
linear/linear-release-action v0.15.1 v0.18.0

actions/checkout (v7.0.1) and actions/setup-node (v7.0.0) are already latest — confirmed against the tag list, not just the releases/latest endpoint.

Each bump was checked against the release path rather than taken on the version number:

  • pnpm/action-setup v6.1.0 adds a native pnpm 12 bootstrap (#288). readTargetVersion strips the +sha512 integrity suffix, so packageManager resolves to 12.4.2 and targetsPnpm12 routes it to the native lockfile — the action installs pnpm 12 directly instead of bootstrapping pnpm 11 and running self-update. This pairs with the 12.4.2 pin above.
  • changesets/action v2.1.2 is patches only and action.yml is byte-identical to v2.1.0 (all kebab-case inputs and the has-changesets / published-packages outputs unchanged). Two patches touch the release path: version commits now always switch + reset the branch (as with push-with-git-cli), and git-tag push errors are handled. The open Version PR chore: version packages #78 was generated by v2.1.0; expect its next regeneration to come from v2.1.2.
  • linear/linear-release-action v0.18.0 — the action.yml diff across those three minors is purely additive (one new no_branch_ref_detection input). All six inputs linear-release.yaml uses (access_key, command, release_version, name, links, stage) are unchanged, which matters because CLAUDE.md notes a stale input name in this pipeline fails silently.

@noble/hashes stays on ^1.8.0

pnpm update --latest moves it to ^2.4.0; that was reverted, for the reason recorded in #75. bitcoinjs-lib@7.0.2 and bs58check@4.0.0 both declare @noble/hashes: ^1.2.0, so v2 resolves two copies into the tree, and v2 removed the ./sha256, ./sha1 and ./ripemd160 subpaths that bitcoinjs-lib imports.

Notes

  • pnpm regen was run after the update to confirm the lockfile matches a from-scratch resolve. It came back byte-identical, so there is no hidden transitive churn in the lockfile diff.
  • The two packages/core source files are Biome 2.5.14 reformatting only (a Prettify<…> closing bracket moved to its own line).
  • Pre-existing and deliberately left alone: @types/node is on 26.x while setup-node pins node-version: '24', and madge@8 wants typescript ^5.4.4 against the repo's 7.0.2.

Visual showcase (Screenshots or Videos)

N/A — no user-facing change.

Checklist before requesting a review

  • I have performed a self-review and testing of my code.
  • This pull request is focused and addresses a single problem.
  • If this PR modifies the Bigmi API or adds new features that require documentation, I have updated the documentation in the public-docs repository. — N/A, no API change.

Verified locally with the exact Verify job sequence, after the regen reinstall: pnpm install --frozen-lockfile (lockfile up to date) → check → check:circular-deps (3/3 clean) → knip:check → build (3/3 built) → check:types → test (76 passed, 1 skipped).

Refresh every dependency to latest except `@noble/hashes`, move the pinned
package manager from pnpm 12.3.4 to 12.4.2, and re-pin the three actions that
have newer releases.

Runtime deps: none changed, so this is chore-only (no changeset).

Tooling:
- vitest + @vitest/coverage-v8 5.0.0 -> 5.0.1
- @biomejs/biome 2.5.12 -> 2.5.14
- knip 6.35.1 -> 6.36.0
- @changesets/cli 3.0.2 -> 3.0.3
- @types/node 26.5.0 -> 26.6.1
- @types/react 19.2.18 -> 19.3.0, @types/react-dom 19.2.7 -> 19.3.0
- react + react-dom 19.2.8 -> 19.3.0 (devDeps of @bigmi/react)
- pnpm 12.3.4 -> 12.4.2 (`packageManager`)

GitHub Actions (SHA-pinned):
- pnpm/action-setup v6.0.10 -> v6.1.0. v6.1.0 adds a native pnpm 12 bootstrap:
  `readTargetVersion` strips the `+sha512` integrity suffix, so `packageManager`
  resolves to 12.4.2 and the action installs it directly instead of bootstrapping
  pnpm 11 and running `self-update`. Directly relevant to the 12.4.2 pin above.
- changesets/action v2.1.0 -> v2.1.2. Patches only, but two touch the release
  path: version commits now always switch + reset the branch (as with
  `push-with-git-cli`), and git-tag push errors are handled. The open Version PR
  #78 was generated by v2.1.0 — expect the next regeneration to come from v2.1.2.
- linear/linear-release-action v0.15.1 -> v0.18.0. The `action.yml` diff across
  those three minors is purely additive (`no_branch_ref_detection`); all six
  inputs this repo uses — `access_key`, `command`, `release_version`, `name`,
  `links`, `stage` — are unchanged.
- actions/checkout v7.0.1 and actions/setup-node v7.0.0 are already latest.

`pnpm regen` was run afterwards to confirm the lockfile matches a from-scratch
resolve; it came back byte-identical, so no transitive churn is hiding in it.

`@noble/hashes` deliberately stays on ^1.8.0, for the same reason as #75:
bitcoinjs-lib@7.0.2 and bs58check@4.0.0 both declare `@noble/hashes: ^1.2.0`, so
v2 resolves two copies into the tree, and v2 removed the `./sha256`, `./sha1` and
`./ripemd160` subpaths that bitcoinjs-lib imports.

The two `packages/core` source files are Biome 2.5.14 reformatting only.

Known, pre-existing and left alone: `@types/node` is on 26.x while CI runs Node
24, and madge@8 wants typescript ^5.4.4 against the repo's 7.0.2.
@changeset-bot

changeset-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 87b6779

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@chybisov
chybisov merged commit 2ea6684 into main Sep 18, 2026
6 checks passed
@chybisov
chybisov deleted the chore/bump-deps-and-actions branch September 18, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant