Repository navigation
chore(ast-grep): upgrade to ast-grep 0.45.3 - #334
Merged
Merged
Conversation
theCodeDrift
added this pull request to stack #338
September 15, 2026 23:58
theCodeDrift
force-pushed
the
vendor/ast-grep/upgrade
branch
from
September 16, 2026 17:24
e0ed680 to
80d656c
Compare
theCodeDrift
removed this pull request from stack #338
September 16, 2026 17:36
… line The pin bump alone left four things behind: - AST_GREP_VERSION still said 0.45.2, so engine-version-consistency and the vendor contract's version pin both failed, and the reconciliation marker recorded the wrong engine. - The vendored rule schema is fetched from the tagged upstream, so it is regenerated. The only change is the Severity enum's order: `off` now sorts first, because `--min-severity` compares severities as an ordered type. No consumer of ours reads the order. - The severity-vocabulary pin asserted the old order in ast-grep's error text. The vocabulary is unchanged; the pin records the reorder. - The reconciliation marker test's deliberate literal, which exists so an upgrade cannot refresh it silently, is refreshed by hand.
ast-grep 0.45.3 (ast-grep/ast-grep#2909) stopped treating any comment that CONTAINS `ast-grep-ignore` as a directive; it now has to be the comment's first alphabetic text. Nothing of ours writes these, but `check` scans whatever code a project has, so the change reaches a user as a finding that appears under a prose comment, or an `unused-suppression` hint that vanishes, with nothing saying why. Measured against both binaries, swapped in place: the prose-mention, unused-hint and first-alphabetic cases all fail on 0.45.2 and pass on 0.45.3, and the two baseline cases (the directive works; a genuinely unused one is reported as a hint on the stream) fail when their fixture is broken. Not pinned, deliberately: `--min-severity`. `check` has no severity filter and `runAstGrepScan` passes no such flag, so there is no path by which it reaches a user. tree-sitter 0.27 moved nothing the existing language-alias, kind and pattern pins can see.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stack (root → tip):
Upstream ast-grep is ahead of the version this repository pins.
This moves every
@ast-grep/cli*pin inpackages/cli/package.jsonfrom
0.45.2to0.45.3and regeneratespnpm-lock.yaml. The pins move together on purpose: the platformpackages are selected by optional dependency, so a straggler left at
the old version is a different ast-grep on one platform than on the
others.
sg-detect.cjsfails the run rather than open a partial bump.Nothing else is edited. The rewrite replaces a version string in pins
it can already enumerate and refuses if the count does not match, so
it cannot add a dependency or reformat the file — the diff below is
eight version strings, a resolved lockfile, and a changeset.
This pull request rolls: if upstream releases again before it merges,
the branch, title, and body are rewritten to the newer version rather
than a second pull request being opened. Push a commit to the branch
and that stops — the workflow will not force-push over a commit it did
not write.
Upstream release notes — 0.45.3
https://github.com/ast-grep/ast-grep/releases/tag/0.45.3
Contains #337
#334 moves the
@ast-grep/cli*pins to 0.45.3 and touches nothing else. This is what makes that bump correct.What the pin bump alone left broken
AST_GREP_VERSIONstill read0.45.2, failingengine-version-consistency, the vendor contract's version pin, and the reconciliation marker, which records this constant as the engine the rules are valid against. Bumped, and the marker test's deliberate literal (it exists so an upgrade cannot refresh it silently) refreshed by hand.src/generated/ast-grep-rule-schema.jsonis fetched from the tagged upstream, so it was version-bound. Regenerated for 0.45.3; the only change is theSeverityenum's order (offnow first, since--min-severitycompares severities as an ordered type). Nothing of ours reads the order.Full CLI suite after the fixes: 88 files, 1444 tests, all passing. No 0.45.3 regression found: every existing language-alias, kind,
$$$, Markdown and binding pin held unchanged under tree-sitter 0.27.New vendor-contract pins
ast-grep-vendor-contract.test.tsgains aninline ast-grep-ignore commentsblock. 0.45.3 (ast-grep/ast-grep#2909) stopped treating any comment that containsast-grep-ignoreas a directive; it must now be the comment's first alphabetic text. Nothing of ours writes those comments, butcheckscans whatever code a project has, so it reaches a user as findings appearing under prose or hints vanishing.Measured against both binaries (0.45.2 swapped into the platform package path), each case records its side of the bump:
// ast-grep-ignore/// ast-grep-ignore: no-evalabove a match suppresses itunused-suppressionhint/* */, extra spaces, and// 1.still count;// NOTE ast-grep-ignoreis prose--json=streamasruleId: unused-suppression,severity: hint,note: nullThe two baseline cases were also mutated at the fixture level (directive removed; scope changed) and fail as expected.
Not pinned, deliberately:
--min-severity.checkhas no severity filter andrunAstGrepScanpasses no such flag, so there is no path by which it reaches a user. Outline changes are not exposed by the CLI.Changeset
.changeset/ast-grep-0-45-3.mdis grown in place (stillpatch) with the two user-observable directions. Noupdate.mdledger entry: nothing installed under.taskless/migrates, and the ledger exists only for that.One aside worth knowing: the repo's own
taskless checkflagged a wrapped comment line in the new test whose text began with the token, exactly the anchor being pinned. Reflowed.Stacked on #334 — merges down into vendor/ast-grep/upgrade.