Move the web app to Next 16 and pin the transitive deps that lagged - #6
Merged
Merged
Conversation
The frontend was on next 15.0.3 with a lockfile that had not been
regenerated since. Two transitive packages were the reason to move rather
than sit: nanoid resolved to 3.3.14 and sharp to 0.33.5, both below the
versions their maintainers now ship, and neither is a direct dependency
so neither could be raised by editing the dependency list.
* next 15.0.3 -> ^16.3.4, postcss ^8.4.49 -> ^8.5.18
* an "overrides" block forces nanoid ^3.3.18 and sharp ^0.35.0 through
the whole tree, because overrides is the only lever npm gives you for
a version you do not depend on directly
* package-lock.json regenerated: nanoid 3.3.14 -> 3.3.18,
sharp 0.33.5 -> 0.35.4, next 15.0.3 -> 16.3.4
tsconfig.json carries the changes Next 16 writes for itself on first run:
jsx moves from "preserve" to "react-jsx", and .next/dev/types is added to
include so the dev server's generated route types resolve. The
reformatting to one entry per line is the same tool's doing and is not a
setting change.
The attest workflow runs npm ci from this lockfile and then next build on
every push, so the build is checked against exactly these bytes rather
than against whatever a local node_modules happened to hold.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why now
The frontend was on
next15.0.3 with a lockfile that had not been regenerated since. Two transitive packages were the reason to move rather than sit:nanoidsharpnextpostcssNeither
nanoidnorsharpis a direct dependency, so neither could be raised by editing the dependency list. Anoverridesblock forces them through the whole tree, becauseoverridesis the only lever npm gives you for a version you do not depend on directly.tsconfig
tsconfig.jsoncarries the changes Next 16 writes for itself on first run:jsxmoves from"preserve"to"react-jsx", and.next/dev/typesis added toincludeso the dev server's generated route types resolve. The reformatting to one entry per line is the same tool's doing, not a setting change.How the upgrade is checked
The
attestworkflow that landed in #2 runsnpm cifrom this lockfile and thennext buildon every push. So the Next 16 build is exercised against exactly these bytes on this branch, rather than against whatever a localnode_moduleshappened to hold. The green check on this PR is that build.Tests
No Python changed, so the Python suite is reported for completeness only.
.agent-work/is excluded from discovery: worktrees under it hold duplicate copies of these same test files.test_token_merge.pytest_model_guard.pyattentionrag/test_core.pyexperiments/test_data.py🤖 Generated with Claude Code