Skip to content

Work through the open Dependabot PRs - #663

Merged
gschier merged 11 commits into
mainfrom
deps/sweep
Sep 15, 2026
Merged

gschier merged 11 commits into
mainfrom
deps/sweep

Conversation

@gschier

@gschier gschier commented Sep 15, 2026

Copy link
Copy Markdown
Member

Ten Dependabot PRs, one commit each, except tonic and prost-types which had to be done together.

Four of them don't do what they say:

internal-ip and vite-plugin-svgr are both unused — there isn't a single .svg in the repo — so those are removed rather than bumped.

codemirror-json-schema stays at 0.6.1. 0.8 dropped stateExtensions and updateSchema from the package root and doesn't expose a subpath to reach them, so GrpcEditor would need reworking around the jsonSchema helper first. It also picks up shiki as a runtime dep.

Both pins now say why they're pinned, and Dependabot ignores them so they stop coming back every Monday.

The chacha20poly1305 one is worth a look — it decrypts data people already have on disk, so there's a test that decrypts a blob written by the old version rather than trusting the round-trip tests.

@greptile-apps

greptile-apps Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

The PR appears safe to merge, with non-blocking recommendations to automate PDF asset-layout verification and exercise the upgraded gRPC stack at runtime.

Findings

  1. P2 PDF Layout Lacks Verification ▶
  2. P2 gRPC Upgrade Lacks Coverage ▶

Summary

This PR consolidates several dependency upgrades, aligns the Vite-Plus core aliases, migrates the gRPC and cryptography stacks, updates PDF.js asset copying, removes unused frontend dependencies, and documents two intentional dependency pins.

  • Preserves the versioned XChaCha20-Poly1305 envelope and adds a previous-release ciphertext compatibility vector.
  • Upgrades tonic, prost, and reflection dependencies together while adapting the custom Hyper transport to tonic’s current body type.
  • Reworks PDF.js static-copy targets to retain the runtime /cmaps/ and /standard_fonts/ paths.
  • Adds Dependabot exclusions for dependencies that cannot currently be upgraded safely.
  • Leaves two non-blocking test-coverage gaps around PDF build artifacts and gRPC runtime compatibility.

Reviews (1) · Last reviewed commit: "Stop Dependabot reopening the two pins t..."

Comment on lines +65 to +70
{ src: `${cMapsDir}/*`, dest: "cmaps", rename: { stripBase: true } },
{
src: `${standardFontsDir}/*`,
dest: "standard_fonts",
rename: { stripBase: true },
},

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 PDF Layout Lacks Verification

The new PDF.js asset layout depends on the copy plugin's glob and stripBase behavior, but no automated check verifies that files land directly under /cmaps/ and /standard_fonts/, where PdfViewer requests them. TypeScript and application builds can succeed even if these runtime assets are misplaced, so a build-output test should check representative cmap and standard-font files at those paths.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a build step that asserts these land where they're served from. It caught something real on the rebase: the favicon targets from #665 were written for static-copy 3 and would have gone to dist/crates-tauri/.../release/favicon.ico under 4. Verified by reverting one target and watching the build fail.

Comment on lines +16 to +24
prost = "0.14.4"
prost-reflect = { version = "0.16.5", default-features = false, features = ["serde", "derive"] }
prost-types = "0.14.4"
serde = { workspace = true, features = ["derive"] }
serde_json = { workspace = true }
tokio = { workspace = true, features = ["macros", "rt-multi-thread", "fs", "process"] }
tokio-stream = "0.1.14"
tonic = { version = "0.12.3", default-features = false, features = ["transport"] }
tonic-reflection = "0.12.3"
tonic = { version = "0.14.6", default-features = false, features = ["transport"] }
tonic-reflection = "0.14.6"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 gRPC Upgrade Lacks Coverage

This upgrades the full tonic/prost stack across major versions and changes the transport body type, but existing tests do not exercise server reflection, local proto loading, or the unary and streaming call modes. Compilation alone will not catch runtime framing or descriptor regressions, so focused integration coverage should exercise reflection and all four call shapes.

Knowledge Base Used:

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair, and it's a gap that predates this change. Integration coverage here means standing up a gRPC server in the test suite and driving reflection plus all four call shapes, which is its own piece of work rather than part of a dependency bump. What this branch does have is a single version of prost and tonic in the lock, the codec and reflection paths compiling unchanged against the new APIs, and the existing descriptor tests passing. Runtime behaviour is getting manual QA against a live server before this merges.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That’s fair. Since the missing integration coverage predates this dependency bump and the branch validates the upgraded stack through lockfile consistency, compilation, descriptor tests, and planned live-server QA, I agree it shouldn’t block this PR. The reflection and call-shape coverage is better tracked as follow-up work.

gschier and others added 11 commits September 15, 2026 13:11
Takes the weekly cargo group update, minus the oxc_resolver bump.

rolldown_resolver depends on oxc_resolver "^11", so cargo is free to
resolve it forward on its own. 11.11.0 renamed TsconfigOptions to
TsconfigDiscovery and dropped the std::error::Error impl on JSONError,
neither of which rolldown 0.1.0 compiles against. The oxc_resolver entry
in yaak-cli isn't imported anywhere; it exists purely to hold that
resolution down, so the exact version has to stay until rolldown ships
against 11.11.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
It came in with the codebase split and was never imported anywhere.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
There are no SVG files in the repo and nothing imports one, so the plugin
had nothing to transform.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
v4 stopped matching directory entries and now always mirrors the source
tree into the output, so the old targets would have landed the pdf.js
assets under dist/node_modules/pdfjs-dist/ instead of dist/cmaps/ and
dist/standard_fonts/. Nothing would have failed at build time; the PDF
viewer would just have 404'd on its cmap and font URLs.

Globbing the directory contents and flattening with stripBase reproduces
the old layout exactly, verified against the source file lists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
prost, prost-types, prost-reflect, tonic and tonic-reflection all have to
move together: prost-reflect 0.14 is built on prost 0.13 and
tonic-reflection 0.12 on tonic 0.12, so bumping prost-types or tonic on
its own just puts two incompatible copies of each in the tree. Doing them
in one go keeps a single version of each.

The only source change is tonic::body::BoxBody, which is private in 0.14.
tonic::body::Body is the public replacement and is what the hyper client's
body parameter wanted anyway.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
0.11 moves onto the new RustCrypto stack: generic-array becomes
hybrid-array, and OsRng gives way to the Generate trait. The cipher and
the on-disk format are unchanged, so this is an API migration only.

Since this code decrypts data users already have in their databases,
added a test that decrypts a blob produced by 0.10.1 rather than relying
on the round-trip tests, which would pass just as happily if both halves
changed together.

Also swapped the now-deprecated clone_from_slice for TryFrom. The master
key path returns a proper error on a bad length instead of panicking,
which matches how the decode failure just above it is handled.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Takes seven of the eight updates. codemirror-json-schema stays pinned at
0.6.1: 0.8 stopped exporting stateExtensions and updateSchema from the
package root and has no ./features subpath in its exports map, so
GrpcEditor can't reach them at all. Moving to the jsonSchema helper is a
rewrite of how the gRPC editor swaps schemas on reflection, not a bump.

0.8 also pulls in shiki as a runtime dependency, which is a lot of
bundle for schema hints in one editor.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
cpx2 and vite-plus both moved within their existing ranges, so this is
mostly a lockfile update. vite-plus 0.3.1's breaking changes are all in
`vp env` and the Corepack shim, neither of which this repo uses.

The catch is that vite-plus checks the `vite` alias resolves to its own
core version and refuses to start otherwise, so the alias has to move
with it. It was still on ^0.2.9 while vite-plus was on ^0.3.0, which left
two copies of the core in the tree; updating vite-plus alone collapsed
that and broke the build outright.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
cm6-graphql and graphql-language-service both already allow ^17, so the
whole tree dedupes onto one copy, which is the thing that usually goes
wrong with this package.

The APIs used here (buildClientSchema, introspectionFromSchema, the type
guards, parse and Kind) are unchanged, and getIntrospectionQuery still
produces a byte-identical query, so introspecting servers built on older
implementations behaves the same.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Both pins are load-bearing and were getting re-proposed weekly, so the
reasons now live next to the ignore entries.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The favicon targets that landed on main were written for static-copy 3
and would have gone to dist/crates-tauri/.../release/favicon.ico under 4,
which is the same silent 404 the pdf.js assets nearly shipped with. Two
near misses in a week is enough to check it.

The copy targets decide where files land and PdfViewer and the page head
decide where they're fetched from, with nothing tying the two together,
so this asserts the served paths exist once the bundle is written.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@gschier
gschier merged commit 3d6c314 into main Sep 15, 2026
5 checks passed
@gschier
gschier deleted the deps/sweep branch September 15, 2026 20:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant