Canonical merge of #1158 - #1159
Merged
Merged
Conversation
`engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0` for that reason: the types describe the oldest runtime this package supports, not the newest one that exists. Dependabot opened the 22 -> 26 bump as #1151. It typechecks cleanly, which is exactly the problem -- types from a later major admit APIs node 22 does not have, and the type checker is the only thing that would refuse them, so a release would compile here and fail on a runtime the package claims to support. A major bump here is a decision about the support floor, made by hand next to `engines`. The ignore rule says so instead of leaving a pull request to be closed unread every month. Minor and patch updates inside the pinned major still arrive, and a security advisory ignores the block entirely. Limit: `engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0`, so the types track the oldest supported runtime rather than the newest that exists Ruled-out: taking the 22 -> 26 major bump of @types/node (#1151) | types from a later major describe APIs node 22 does not have, and the type checker is the only thing that would refuse them, so a release would compile here and fail on a supported runtime Warn: a green typecheck on a `@types/node` major bump is not evidence the bump is safe; the floor is `engines.node`, and nothing in the suite asks whether an API exists on the oldest runtime Blast: module Undo: easy Certainty: firm Record-Id: r-typesnodefloor Provenance: drafted
`build:canonical` on the merged tree, so the commit that lands matches the source it lands with. The pull request carried source only, which is what a contributor on a host that cannot run a linux/amd64 Docker build can produce (#720). Limit: this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for Blast: system Undo: easy Certainty: firm Record-Id: r-canonmerge1158 Provenance: authored Verified: artifact:verify passed against the regenerated manifest in the same job, before any credential was available to it CommitLore-Version: 2.0.0
CommitLore — record lintTrailers: clean — 4 commits in Active constraints for the paths this PR touchesLimits (375)
Truncated: 622 lines omitted — the comment hit GitHub's 65000 character limit. Trailer violations fail this check. Active constraints are informational — they are what the repository already decided, not a verdict on this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The commit that will land for #1158:
mainplus that source plus a canonical rebuild, built together so all eleven required contexts run on the tree that merges rather than on one that resembles it.#1158 carries source only, which is what a contributor on a host that cannot run a
linux/amd64Docker build can produce (#720). Nothing was rebuilt by hand.Merge this with a merge commit, not a squash. This branch merged #1158 with
--no-ff, so its head commit is an ancestor here: a merge commit lands that commit onmain, and GitHub then records #1158 as merged because its head is reachable -- which is what T-1502 asks for. A squash lands new bytes instead, and #1158 stays open with nothing to point at.This body deliberately carries no closing keyword. GitHub binds one only to the number straight after it, and a pull request closed by keyword is recorded closed rather than merged -- the opposite of the line above. Reachability does the closing here.
Opened by
canonical-merge.ymlfor #719.