Skip to content

chore(ast-grep): upgrade to ast-grep 0.45.3 - #334

Merged
theCodeDrift merged 4 commits into
mainfrom
vendor/ast-grep/upgrade
Sep 16, 2026
Merged

theCodeDrift merged 4 commits into
mainfrom
vendor/ast-grep/upgrade

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Stack (root → tip):

Upstream ast-grep is ahead of the version this repository pins.

This moves every @ast-grep/cli* pin in packages/cli/package.json
from 0.45.2 to 0.45.3 and regenerates
pnpm-lock.yaml. The pins move together on purpose: the platform
packages are selected by optional dependency, so a straggler left at
the old version is a different ast-grep on one platform than on the
others. sg-detect.cjs fails the run rather than open a partial bump.

Nothing else is edited. The rewrite replaces a version string in pins
it can already enumerate and refuses if the count does not match, so
it cannot add a dependency or reformat the file — the diff below is
eight version strings, a resolved lockfile, and a changeset.

This pull request rolls: if upstream releases again before it merges,
the branch, title, and body are rewritten to the newer version rather
than a second pull request being opened. Push a commit to the branch
and that stops — the workflow will not force-push over a commit it did
not write.


Upstream release notes — 0.45.3

https://github.com/ast-grep/ast-grep/releases/tag/0.45.3

  • chore(deps): update dependency dprint to v0.57.0 #2916
  • feat: add min-severity cli #2917
  • fix(outline): anchor fallback signatures to names #2913
  • feat(outline): add Markdown heading support #2912
  • chore(deps): update dependency oxlint to v1.80.0 #2908
  • chore(deps): update dependency @ast-grep/napi to v0.45.2 #2906
  • feat: add min-severity cli (#2917) #2720
  • fix: ast-grep-ignore must be at first be the frist alphabet to take effect #2909
  • chore: update tree-sitter 0.27 bb74529
  • fix: fix clippy c6b32d7

Contains #337

#334 moves the @ast-grep/cli* pins to 0.45.3 and touches nothing else. This is what makes that bump correct.

What the pin bump alone left broken

  • AST_GREP_VERSION still read 0.45.2, failing engine-version-consistency, the vendor contract's version pin, and the reconciliation marker, which records this constant as the engine the rules are valid against. Bumped, and the marker test's deliberate literal (it exists so an upgrade cannot refresh it silently) refreshed by hand.
  • src/generated/ast-grep-rule-schema.json is fetched from the tagged upstream, so it was version-bound. Regenerated for 0.45.3; the only change is the Severity enum's order (off now first, since --min-severity compares severities as an ordered type). Nothing of ours reads the order.
  • The severity-vocabulary pin asserted ast-grep's error text in the old order. The vocabulary is unchanged; the pin records the reorder and why.

Full CLI suite after the fixes: 88 files, 1444 tests, all passing. No 0.45.3 regression found: every existing language-alias, kind, $$$, Markdown and binding pin held unchanged under tree-sitter 0.27.

New vendor-contract pins

ast-grep-vendor-contract.test.ts gains an inline ast-grep-ignore comments block. 0.45.3 (ast-grep/ast-grep#2909) stopped treating any comment that contains ast-grep-ignore as a directive; it must now be the comment's first alphabetic text. Nothing of ours writes those comments, but check scans whatever code a project has, so it reaches a user as findings appearing under prose or hints vanishing.

Measured against both binaries (0.45.2 swapped into the platform package path), each case records its side of the bump:

case 0.45.2 0.45.3
// ast-grep-ignore / // ast-grep-ignore: no-eval above a match suppresses it pass pass
a prose comment mentioning the directive above a match no longer suppresses it fail pass
a prose mention with nothing to suppress no longer yields an unused-suppression hint fail pass
anchor is the first alphabetic char: /* */, extra spaces, and // 1. still count; // NOTE ast-grep-ignore is prose fail pass
a genuinely unused directive reaches --json=stream as ruleId: unused-suppression, severity: hint, note: null pass pass

The two baseline cases were also mutated at the fixture level (directive removed; scope changed) and fail as expected.

Not pinned, deliberately: --min-severity. check has no severity filter and runAstGrepScan passes no such flag, so there is no path by which it reaches a user. Outline changes are not exposed by the CLI.

Changeset

.changeset/ast-grep-0-45-3.md is grown in place (still patch) with the two user-observable directions. No update.md ledger entry: nothing installed under .taskless/ migrates, and the ledger exists only for that.

One aside worth knowing: the repo's own taskless check flagged a wrapped comment line in the new test whose text began with the token, exactly the anchor being pinned. Reflowed.

Stacked on #334 — merges down into vendor/ast-grep/upgrade.

@theCodeDrift theCodeDrift changed the title chore(ast-grep): pin ast-grep 0.45.3 chore(ast-grep): upgrade to ast-grep 0.45.3 Sep 15, 2026
@theCodeDrift
theCodeDrift added this pull request to stack #338 September 15, 2026 23:58
@theCodeDrift
theCodeDrift force-pushed the vendor/ast-grep/upgrade branch from e0ed680 to 80d656c Compare September 16, 2026 17:24
@theCodeDrift
theCodeDrift removed this pull request from stack #338 September 16, 2026 17:36
… line

The pin bump alone left four things behind:

- AST_GREP_VERSION still said 0.45.2, so engine-version-consistency and
  the vendor contract's version pin both failed, and the reconciliation
  marker recorded the wrong engine.
- The vendored rule schema is fetched from the tagged upstream, so it is
  regenerated. The only change is the Severity enum's order: `off` now
  sorts first, because `--min-severity` compares severities as an
  ordered type. No consumer of ours reads the order.
- The severity-vocabulary pin asserted the old order in ast-grep's error
  text. The vocabulary is unchanged; the pin records the reorder.
- The reconciliation marker test's deliberate literal, which exists so an
  upgrade cannot refresh it silently, is refreshed by hand.
ast-grep 0.45.3 (ast-grep/ast-grep#2909) stopped treating any comment
that CONTAINS `ast-grep-ignore` as a directive; it now has to be the
comment's first alphabetic text. Nothing of ours writes these, but
`check` scans whatever code a project has, so the change reaches a user
as a finding that appears under a prose comment, or an
`unused-suppression` hint that vanishes, with nothing saying why.

Measured against both binaries, swapped in place: the prose-mention,
unused-hint and first-alphabetic cases all fail on 0.45.2 and pass on
0.45.3, and the two baseline cases (the directive works; a genuinely
unused one is reported as a hint on the stream) fail when their fixture
is broken.

Not pinned, deliberately: `--min-severity`. `check` has no severity
filter and `runAstGrepScan` passes no such flag, so there is no path by
which it reaches a user. tree-sitter 0.27 moved nothing the existing
language-alias, kind and pattern pins can see.
@theCodeDrift
theCodeDrift merged commit 057ddfb into main Sep 16, 2026
4 checks passed
@theCodeDrift
theCodeDrift deleted the vendor/ast-grep/upgrade branch September 16, 2026 17:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant