Skip to content

fix(templates): move generator dependency ranges with the dependabot wave (#4098) - #4099

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4098-template-dep-ratchets
Aug 10, 2026
Merged

fix(templates): move generator dependency ranges with the dependabot wave (#4098)#4099
yinlianghui merged 1 commit into
mainfrom
claude/issue-4098-template-dep-ratchets

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4098

This morning's dependabot wave (07:45–08:03Z) moved this repo's own manifests but not the ranges hard-coded in the scaffold generators — dependabot does not know the templates exist. Two anchor ratchets went red on every PR branched off current main.

Premise re-verified

Both reported failures reproduce on unmodified origin/main (361dfdc01):

FAIL |unit| packages/cli/src/__tests__/app-generator.test.ts
AssertionError: routed manifest's lucide-react must match its in-repo range:
expected '^1.28.0' to be '^1.29.0'
FAIL |unit| packages/create-plugin/src/__tests__/templates.test.ts
AssertionError: vite range must match the repo root:
expected '^8.2.0' to be '^8.2.1'

Direction confirmed from the ratchets' own documentation rather than assumed — templates.test.ts states it outright: "Bumping an in-repo manifest and leaving the template behind is the drift this test exists to catch — update src/templates.ts in the same PR." Templates follow the repo, not the reverse.

The sweep found a third drift

Each ratchet aborts at its first failing assertion, so each file reports one drift however many it has. Rather than fix-and-re-run, I replicated both anchor rules in a throwaway script and judged all 21 anchored ranges across all four generator maps at once:

rangedeclaredanchor sayswherereported?
lucide-react^1.28.0^1.29.0app-generator.ts routed deps (in-repo)yes
vite^8.2.0^8.2.1create-plugin/templates.ts (root)yes
vite^8.2.0^8.2.1cli/utils/scaffold-dependencies.ts (root)no

The third was invisible because lucide-react sorts before vite in DEPENDENCY_ANCHORS, so the CLI test never reached it. Fixing only the two named ranges would have turned shard 1 red again on the very next lap. The other 18 anchored ranges are already correct, and the wave's other bumps (shiki, maplibre-gl, react-hook-form, next) are not declared by any generator, so no ratchet points at them.

lucide-react^1.29.0 is unanimous across all 23 in-repo manifests that declare it; root vite is ^8.2.1.

Reverse verification

Predicted before running, and the direction is plain red — this rule compares a generated string against a repo fact, so there is no schema underneath to re-judge the same input differently (the file says as much). Restoring only the third, previously-invisible drift:

AssertionError: routed manifest's vite must match the repo root:
expected '^8.2.0' to be '^8.2.1'
at packages/cli/src/__tests__/app-generator.test.ts:531:66
Tests 1 failed | 32 passed (33)

That is the second red lap this PR avoids, made visible.

One test line changed, and why

app-generator.test.ts:1082 asserted expect(manifest.dependencies?.['lucide-react']).toBe('^1.28.0') — a hard-coded second copy of the anchor rule pointing the other way, which went red the moment the template was moved onto the repo's real range, i.e. it scored a correct fix as a regression. It now reads the same inRepoRangesOf anchor the rest of the file uses, so it cannot fossilise again. No assertion strength is lost: it still judges the manifest actually written to disk.

Verification

  • pnpm test --shard=1/4Test Files 289 passed (289), Tests 3599 passed | 1 skipped
  • pnpm test --shard=2/4Test Files 289 passed (289), Tests 3569 passed

Both were 1 failed | 288 passed (289) on main, so each shard is green exactly where the issue reported it red.

  • pnpm exec vitest run packages/cli/ packages/create-plugin/5 passed (5), 116 passed
  • type-check (both packages) → clean
  • lint (both packages) → 0 errors (15 pre-existing warnings in untouched files)
  • node scripts/check-control-bytes.mjs → OK

Changeset: patch for @object-ui/cli and @object-ui/create-plugin. Both are published and in the fixed release group, and the change is user-visible — it alters the package.json a scaffolded project receives.

Out of scope

The issue's durable question — whether a dependabot bump touching a mirrored range could update the template in the same PR or fail its own CI — is a workflow change beyond this card and is left for triage. Filed nothing new: the sweep turned up no defect outside the three ranges above.


Generated by Claude Code

…wave (#4098)
The 2026-08-10 dependabot wave bumped this repo's own manifests but not the
ranges hard-coded in the scaffold generators, breaking two anchor ratchets and
turning `Test (shard 1/4)` and `Test (shard 2/4)` red on every PR off main.
Re-anchors three ranges (the third was invisible: the anchor test aborts at its
first mismatch, and `lucide-react` sorts before `vite`):
- `lucide-react` ^1.28.0 -> ^1.29.0 (app-generator routed deps, in-repo anchor)
- `vite` ^8.2.0 -> ^8.2.1 (scaffold-dependencies, root anchor)
- `vite` ^8.2.0 -> ^8.2.1 (create-plugin templates, root anchor)
Also de-fossilises a hard-coded `'^1.28.0'` assertion in app-generator.test.ts
that duplicated the anchor rule pointing the other way -- it went red on the
correct fix. It now reads the same in-repo anchor.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 10, 2026 8:35am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.3 KB350 KB
Entry fileindex-CF5C3utx.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.66KB3.13KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)484.15KB106.78KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)140.66KB36.25KB
fields (index.js)229.40KB56.93KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)9.48KB3.27KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.87KB10.80KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.49KB17.48KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.50KB30.66KB
plugin-designer (index.js)210.51KB42.51KB
plugin-detail (index.js)237.80KB59.48KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)162.81KB39.67KB
plugin-grid (index.js)187.85KB49.83KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)109.96KB26.64KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.95KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)2.71KB1.34KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 10, 2026 08:44
@yinlianghui
yinlianghui added this pull request to the merge queueAug 10, 2026
Merged via the queue into main with commit c29ceffAug 10, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4098-template-dep-ratchets branch August 10, 2026 08:44
yinlianghui pushed a commit that referenced this pull request Aug 17, 2026
…pendabot wave
The scaffolded plugin's generated devDependencies declared
@testing-library/jest-dom at ^7.0.0 while the repo root had moved to ^7.0.1
(#4948's dev-dependencies group), so templates.test.ts's anchor rule was red
on main independently of the lucide-react drift in the previous commit.
Same defect class, same wave, and the same pairing the previous occurrence of
this incident was fixed as (#4098 / PR #4099 moved these two templates in one
PR). Found only by sweeping the class rather than the package: the anchor rule
throws on its first mismatch, so this second template reported nothing until
the first was green.
The doc table above the map is moved with it -- it states each anchored range,
so leaving it would just relocate the fossil into a comment.
Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Aug 17, 2026
…ack-ai#4977) (objectstack-ai#4978)
* fix(cli): catch the app-generator lucide-react range up to the workspace
The routed temp app's generated manifest declared lucide-react at ^1.29.0
while all 22 sibling manifests that declare it had moved to ^1.31.0, so a
generated app asked npm for an icon library older than the one every
@object-ui/* package it installs alongside was built against.
app-generator.test.ts derives its expectation from the in-repo range, so the
drift was caught -- both pins were red. They just went red too late to stop
anything: the dependency PR merged while those shards were still running, and
the failure then surfaced on the merge ref of every unrelated open PR.
The other 12 anchored ranges were swept against the same dependabot batch and
are all in sync. Deriving the value rather than quoting it was considered and
rejected; the reasoning is recorded at the call site.
Fixesobjectstack-ai#4968
Co-authored-by: Claude <noreply@anthropic.com>
* fix(create-plugin): move the jest-dom template range with the same dependabot wave
The scaffolded plugin's generated devDependencies declared
@testing-library/jest-dom at ^7.0.0 while the repo root had moved to ^7.0.1
(objectstack-ai#4948's dev-dependencies group), so templates.test.ts's anchor rule was red
on main independently of the lucide-react drift in the previous commit.
Same defect class, same wave, and the same pairing the previous occurrence of
this incident was fixed as (objectstack-ai#4098 / PR objectstack-ai#4099 moved these two templates in one
PR). Found only by sweeping the class rather than the package: the anchor rule
throws on its first mismatch, so this second template reported nothing until
the first was green.
The doc table above the map is moved with it -- it states each anchored range,
so leaving it would just relocate the fossil into a comment.
Co-authored-by: Claude <noreply@anthropic.com>
* fix(ga-pin): follow the quick-reference spec/client rows to GA, cite $like/$ilike as undecided
Two residues of the `@objectstack/spec` 17.0.0 GA pin were red on `main` itself, so
every open PR inherited a red `Test (shard 3/4)` (objectui#4977).
1. `QUICK_REFERENCE.md`'s "Current Release" block still stated `^17.0.0-rc.6` for
`@objectstack/spec` and `@objectstack/client` while the manifests it names as its
anchors declare `^17.0.0`. Both rows now quote the anchor. The pin derives its
expectation from the manifest, so the doc followed the manifest; nothing in
`scripts/__tests__/quick-reference-current-release-4143.test.ts` was relaxed.
2. GA's `FieldOperatorsSchema` added `$like` and `$ilike`, which no builder operator
authors, so the objectstack-ai#2942 reachability sweep reported them exactly as designed. They
are excluded through that gate's own citation mechanism as "undecided — see objectstack-ai#4911"
with the harvest condition written on the entry: a ruling on objectstack-ai#4911 must either
delete the members and add the operators, or restate the paragraph as a decision
carrying its reopen condition. No operator is implemented, no other gate logic
moves, and the authoring-surface ruling stays with the maintainer.
Co-authored-by: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Test (shard 1/4) and Test (shard 2/4) are red on main: the generator-template dependency ratchets were not moved by this morning's dependabot bumps

2 participants

@yinlianghui@claude