Work through the open Dependabot PRs - #663
Conversation
|
| { src: `${cMapsDir}/*`, dest: "cmaps", rename: { stripBase: true } }, | ||
| { | ||
| src: `${standardFontsDir}/*`, | ||
| dest: "standard_fonts", | ||
| rename: { stripBase: true }, | ||
| }, |
There was a problem hiding this comment.
The new PDF.js asset layout depends on the copy plugin's glob and stripBase behavior, but no automated check verifies that files land directly under /cmaps/ and /standard_fonts/, where PdfViewer requests them. TypeScript and application builds can succeed even if these runtime assets are misplaced, so a build-output test should check representative cmap and standard-font files at those paths.
There was a problem hiding this comment.
Added a build step that asserts these land where they're served from. It caught something real on the rebase: the favicon targets from #665 were written for static-copy 3 and would have gone to dist/crates-tauri/.../release/favicon.ico under 4. Verified by reverting one target and watching the build fail.
| prost = "0.14.4" | ||
| prost-reflect = { version = "0.16.5", default-features = false, features = ["serde", "derive"] } | ||
| prost-types = "0.14.4" | ||
| serde = { workspace = true, features = ["derive"] } | ||
| serde_json = { workspace = true } | ||
| tokio = { workspace = true, features = ["macros", "rt-multi-thread", "fs", "process"] } | ||
| tokio-stream = "0.1.14" | ||
| tonic = { version = "0.12.3", default-features = false, features = ["transport"] } | ||
| tonic-reflection = "0.12.3" | ||
| tonic = { version = "0.14.6", default-features = false, features = ["transport"] } | ||
| tonic-reflection = "0.14.6" |
There was a problem hiding this comment.
This upgrades the full tonic/prost stack across major versions and changes the transport body type, but existing tests do not exercise server reflection, local proto loading, or the unary and streaming call modes. Compilation alone will not catch runtime framing or descriptor regressions, so focused integration coverage should exercise reflection and all four call shapes.
Knowledge Base Used:
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
There was a problem hiding this comment.
Fair, and it's a gap that predates this change. Integration coverage here means standing up a gRPC server in the test suite and driving reflection plus all four call shapes, which is its own piece of work rather than part of a dependency bump. What this branch does have is a single version of prost and tonic in the lock, the codec and reflection paths compiling unchanged against the new APIs, and the existing descriptor tests passing. Runtime behaviour is getting manual QA against a live server before this merges.
There was a problem hiding this comment.
That’s fair. Since the missing integration coverage predates this dependency bump and the branch validates the upgraded stack through lockfile consistency, compilation, descriptor tests, and planned live-server QA, I agree it shouldn’t block this PR. The reflection and call-shape coverage is better tracked as follow-up work.
Takes the weekly cargo group update, minus the oxc_resolver bump. rolldown_resolver depends on oxc_resolver "^11", so cargo is free to resolve it forward on its own. 11.11.0 renamed TsconfigOptions to TsconfigDiscovery and dropped the std::error::Error impl on JSONError, neither of which rolldown 0.1.0 compiles against. The oxc_resolver entry in yaak-cli isn't imported anywhere; it exists purely to hold that resolution down, so the exact version has to stay until rolldown ships against 11.11. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
It came in with the codebase split and was never imported anywhere. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
There are no SVG files in the repo and nothing imports one, so the plugin had nothing to transform. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
v4 stopped matching directory entries and now always mirrors the source tree into the output, so the old targets would have landed the pdf.js assets under dist/node_modules/pdfjs-dist/ instead of dist/cmaps/ and dist/standard_fonts/. Nothing would have failed at build time; the PDF viewer would just have 404'd on its cmap and font URLs. Globbing the directory contents and flattening with stripBase reproduces the old layout exactly, verified against the source file lists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
prost, prost-types, prost-reflect, tonic and tonic-reflection all have to move together: prost-reflect 0.14 is built on prost 0.13 and tonic-reflection 0.12 on tonic 0.12, so bumping prost-types or tonic on its own just puts two incompatible copies of each in the tree. Doing them in one go keeps a single version of each. The only source change is tonic::body::BoxBody, which is private in 0.14. tonic::body::Body is the public replacement and is what the hyper client's body parameter wanted anyway. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
0.11 moves onto the new RustCrypto stack: generic-array becomes hybrid-array, and OsRng gives way to the Generate trait. The cipher and the on-disk format are unchanged, so this is an API migration only. Since this code decrypts data users already have in their databases, added a test that decrypts a blob produced by 0.10.1 rather than relying on the round-trip tests, which would pass just as happily if both halves changed together. Also swapped the now-deprecated clone_from_slice for TryFrom. The master key path returns a proper error on a bad length instead of panicking, which matches how the decode failure just above it is handled. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Takes seven of the eight updates. codemirror-json-schema stays pinned at 0.6.1: 0.8 stopped exporting stateExtensions and updateSchema from the package root and has no ./features subpath in its exports map, so GrpcEditor can't reach them at all. Moving to the jsonSchema helper is a rewrite of how the gRPC editor swaps schemas on reflection, not a bump. 0.8 also pulls in shiki as a runtime dependency, which is a lot of bundle for schema hints in one editor. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
cpx2 and vite-plus both moved within their existing ranges, so this is mostly a lockfile update. vite-plus 0.3.1's breaking changes are all in `vp env` and the Corepack shim, neither of which this repo uses. The catch is that vite-plus checks the `vite` alias resolves to its own core version and refuses to start otherwise, so the alias has to move with it. It was still on ^0.2.9 while vite-plus was on ^0.3.0, which left two copies of the core in the tree; updating vite-plus alone collapsed that and broke the build outright. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
cm6-graphql and graphql-language-service both already allow ^17, so the whole tree dedupes onto one copy, which is the thing that usually goes wrong with this package. The APIs used here (buildClientSchema, introspectionFromSchema, the type guards, parse and Kind) are unchanged, and getIntrospectionQuery still produces a byte-identical query, so introspecting servers built on older implementations behaves the same. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Both pins are load-bearing and were getting re-proposed weekly, so the reasons now live next to the ignore entries. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The favicon targets that landed on main were written for static-copy 3 and would have gone to dist/crates-tauri/.../release/favicon.ico under 4, which is the same silent 404 the pdf.js assets nearly shipped with. Two near misses in a week is enough to check it. The copy targets decide where files land and PdfViewer and the page head decide where they're fetched from, with nothing tying the two together, so this asserts the served paths exist once the bundle is written. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Ten Dependabot PRs, one commit each, except tonic and prost-types which had to be done together.
Four of them don't do what they say:
oxc_resolverpast whatrolldown_resolverbuilds against. That entry isn't imported anywhere — it's only there to pin what rolldown resolves to, which nothing recorded. Kept the rest of the group.tonic-reflectionandprost-reflectbehind on the old major. Did the whole gRPC stack in one go instead.dist/node_modules/pdfjs-dist/whilePdfViewerasks for/cmaps/. Rewrote the targets and checked the output matches the old layout file for file.vitealias has to resolve to the same core version asvite-plus, and it had already drifted a minor behind.internal-ipandvite-plugin-svgrare both unused — there isn't a single.svgin the repo — so those are removed rather than bumped.codemirror-json-schemastays at 0.6.1. 0.8 droppedstateExtensionsandupdateSchemafrom the package root and doesn't expose a subpath to reach them, so GrpcEditor would need reworking around thejsonSchemahelper first. It also picks up shiki as a runtime dep.Both pins now say why they're pinned, and Dependabot ignores them so they stop coming back every Monday.
The chacha20poly1305 one is worth a look — it decrypts data people already have on disk, so there's a test that decrypts a blob written by the old version rather than trusting the round-trip tests.