release: prepare 1.7.3 squash inheritance fix - #1158
Merged
Merged
Conversation
`engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0` for that reason: the types describe the oldest runtime this package supports, not the newest one that exists. Dependabot opened the 22 -> 26 bump as #1151. It typechecks cleanly, which is exactly the problem -- types from a later major admit APIs node 22 does not have, and the type checker is the only thing that would refuse them, so a release would compile here and fail on a runtime the package claims to support. A major bump here is a decision about the support floor, made by hand next to `engines`. The ignore rule says so instead of leaving a pull request to be closed unread every month. Minor and patch updates inside the pinned major still arrive, and a security advisory ignores the block entirely. Limit: `engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0`, so the types track the oldest supported runtime rather than the newest that exists Ruled-out: taking the 22 -> 26 major bump of @types/node (#1151) | types from a later major describe APIs node 22 does not have, and the type checker is the only thing that would refuse them, so a release would compile here and fail on a supported runtime Warn: a green typecheck on a `@types/node` major bump is not evidence the bump is safe; the floor is `engines.node`, and nothing in the suite asks whether an API exists on the oldest runtime Blast: module Undo: easy Certainty: firm Record-Id: r-typesnodefloor Provenance: drafted
CommitLore — record lintTrailers: clean — 2 commits in Active constraints for the paths this PR touchesLimits (252)
Ruled out (409)
Truncated: 454 lines omitted — the comment hit GitHub's 65000 character limit. Trailer violations fail this check. Active constraints are informational — they are what the repository already decided, not a verdict on this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No-Issue: a release preparation and a dependency policy decision, neither of which was filed as an issue
Two commits:
@types/nodestays on the supported runtime floor.engines.nodeis>=22.23.2and the dependency is pinned^22.10.0. Dependabot's 22 → 26major bump (chore(deps-dev): bump @types/node from 22.20.1 to 26.6.3 #1151) typechecks cleanly, which is the problem: types from a
later major admit APIs node 22 does not have, and the type checker is the
only thing that would refuse them. A major bump here is a decision about the
support floor, made by hand next to
engines, so the ignore rule says sorather than leaving a pull request to be closed unread every month. Minor and
patch updates inside the major still arrive; a security advisory ignores the
block entirely.
Release 1.7.3. 59 version pins across eleven files, measured rather than
recalled, plus the CHANGELOG entry. The lockfile fields are set by parsing
JSON, and nothing else in the tree still names 1.7.2 except the CHANGELOG's
own
## 1.7.2heading, which is that release's section and stays.What ships: the #1153 squash-inheritance fix,
@modelcontextprotocol/sdk1.30.1,
js-yaml5.4.2 (dev), anddocker/setup-qemu-actionv4.4.0 in CI.Verification
test/manifest.test.ts,test/readme.test.ts,test/release-version.test.ts— 115 tests, green, which is the surface that pins the version strings.
dist/is absent on purpose:canonical-merge.ymlrebuilds it and regeneratesthe manifest.