From 0cd52bd8c31ec90c3988eb2f50862fc8a72ace71 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 12 Sep 2026 23:12:17 -0700 Subject: [PATCH 1/3] =?UTF-8?q?ci:=20bump=20Node=20CI=20matrix=20for=20vit?= =?UTF-8?q?est=205=20(max=E2=86=9226,=20min=E2=86=9222.12.0)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit vitest@5.0.0's published engines.node is "^22.12.0 || ^24.0.0 || >=26.0.0" (checked via npm view) — it won't run below Node 22.12. 26 is the next even-major LTS-track ceiling. --- .github/workflows/ci.yml | 12 ++++++------ .github/workflows/publish.yml | 12 ++++++------ 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7ae96db..3c11218 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -54,15 +54,15 @@ on: required: false default: "lts/*" min_node_version: - description: "Minimum Node.js version for matrix testing (default: 20, oldest non-EOL)" + description: "Minimum Node.js version for matrix testing (default: 22.12.0 — the floor vitest 5 actually runs on)" type: string required: false - default: "20" + default: "22.12.0" max_node_major: - description: "Override max Node.js major version (default: 22)" + description: "Override max Node.js major version (default: 26)" type: string required: false - default: "22" + default: "26" lts_only_matrix: description: "Only include even-numbered (LTS) Node.js major versions in the test matrix" type: boolean @@ -197,8 +197,8 @@ jobs: .gitignore debug: ${{ github.event.inputs.debug == 'true' }} node_version: ${{ github.event.inputs.node_version || 'lts/*' }} - min_node_version: ${{ github.event.inputs.min_node_version || '20' }} - max_node_major: ${{ github.event.inputs.max_node_major || '22' }} + min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} + max_node_major: ${{ github.event.inputs.max_node_major || '26' }} # LTS-only matrix (even majors: 20, 22, 24, …) on every event. Odd majors # (21, 23, …) are non-LTS interim releases, and the native-binding test # toolchain (vitest 4 / rolldown / vite 8) excludes them via `engines` diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 27ba71e..9acb04c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -60,15 +60,15 @@ on: required: false default: true min_node_version: - description: "Minimum Node.js version for matrix testing (enables matrix when set)" + description: "Minimum Node.js version for matrix testing (default: 22.12.0 — the floor vitest 5 actually runs on)" type: string required: false - default: "20" + default: "22.12.0" max_node_major: - description: "Override max Node.js major version (default: 22)" + description: "Override max Node.js major version (default: 26)" type: string required: false - default: "22" + default: "26" use_gpg: description: "Enable GPG signing (if GPG secrets provided)" type: boolean @@ -101,8 +101,8 @@ jobs: publish_to_github_packages: false publish_command: "" github_packages_publish_command: "" - min_node_version: ${{ github.event.inputs.min_node_version || '20' }} - max_node_major: ${{ github.event.inputs.max_node_major || '22' }} + min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} + max_node_major: ${{ github.event.inputs.max_node_major || '26' }} test_command: "npm test" # Use defaults: NODE_ENV=development, NODE_OPTIONS=--conditions=development # test_command: "NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override NODE_OPTIONS only # test_command: "NODE_ENV=test npm test" # Override NODE_ENV only From d92c9ce1055b1941d1f1ecad066d7809a0938024 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 13 Sep 2026 14:31:34 -0700 Subject: [PATCH 2/3] docs(dependabot): group vitest + @vitest/* into one bump vitest and @vitest/coverage-v8 peer each other exactly, so opening separate PRs for each breaks npm ci with an ERESOLVE the moment one bumps without the other. Group them so future bumps land together in one PR. --- .github/dependabot.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 585ad76..36dc9ca 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -68,6 +68,15 @@ updates: commit-message: prefix: "deps" groups: + # vitest and @vitest/coverage-v8 (and other @vitest/* packages) peer + # each other exactly, so bumping one without the other breaks + # `npm ci` with an ERESOLVE. Bump the whole family together in one + # PR. Must come before security/patch/minor below — Dependabot + # assigns each update to the FIRST matching group. + vitest: + patterns: + - "vitest" + - "@vitest/*" security: applies-to: security-updates patterns: ["*"] From de50ac5efbcc6747547579e6948235648e96a93f Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 13 Sep 2026 14:41:01 -0700 Subject: [PATCH 3/3] docs(dependabot): group eslint + prettier families into one bump each @eslint/js peers eslint with a major-locked range ("^10.0.0"), and @cldmv/prettier-plugin-jsonv peers prettier the same way ("^3.0.0") -- both verified via npm view, not memory. Neither is broken today, but a future major bump would hit the same npm ci ERESOLVE class the vitest + @vitest/coverage-v8 split just did. Group them proactively. --- .github/dependabot.yml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 36dc9ca..388da65 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -77,6 +77,22 @@ updates: patterns: - "vitest" - "@vitest/*" + # @eslint/js peers eslint with a major-locked range ("^10.0.0"), so a + # future eslint major bump without @eslint/js moving too would hit + # the same npm ci ERESOLVE class as the vitest/coverage-v8 split. + # @cldmv/eslint-plugin-jsonv doesn't peer eslint directly but is + # bundled here to keep the lint-config family moving together. + eslint: + patterns: + - "eslint" + - "@eslint/*" + - "@cldmv/eslint-plugin-*" + # @cldmv/prettier-plugin-jsonv peers prettier with a major-locked + # range ("^3.0.0") — same reasoning as the eslint group above. + prettier: + patterns: + - "prettier" + - "@cldmv/prettier-plugin-*" security: applies-to: security-updates patterns: ["*"]