Skip to content

Update all outdated Swift package dependencies - #550

Merged
bradleymackey merged 2 commits into
mainfrom
maintain/dependency-audit
Sep 13, 2026
Merged

bradleymackey merged 2 commits into
mainfrom
maintain/dependency-audit

Conversation

@bradleymackey

@bradleymackey bradleymackey commented Sep 13, 2026 •

Copy link
Copy Markdown
Member

Audits every Swift package dependency and brings the outdated ones current.

Audit result

Checked all 12 declared dependencies (10 source packages + 2 binary targets) against their latest upstream release. Six were behind:

Dependency From To
swift-snapshot-testing 1.19.2 1.19.4
BigInt 5.7.0 6.0.1
swift-argument-parser 1.6.2 1.8.2
swift-syntax 600.0.1 603.0.2
SwiftLintPlugins 0.63.3 0.65.1
SwiftFormat (binary) 0.61.1 0.63.0

Already current, left alone: CryptoSwift 1.10.0, swiftui-toasts 1.1.1, CodeScanner 2.5.2, swift-security 2.5.1, swift-markdown-ui 2.4.1, mockolo 2.6.1.

No transitive dependency moved — xctest-dynamic-overlay, swift-custom-dump, NetworkImage, swift-cmark and swiftui-window-overlay all resolve to the same revisions as before.

Notes on the interesting ones

swift-syntax was silently stuck. It was the only dependency declared from: "600.0.0" instead of exact:. SwiftPM treats 600 and 603 as separate major versions, so that range could never reach the current release — it had been pinned at 600.0.1 with no signal that anything newer existed. It is now exact: "603.0.2" — the latest release — matching every other dependency in the manifest and keeping future drift visible in the diff.

BigInt's major bump is not a breaking change. v6.0.0 contains only a WASI _mantissa fix and added CI runners; v6.0.1 is a test-suite migration to Swift Testing. The major version reflects a swift-tools-version move to 6.0. Platform requirements are unchanged and no API used by CryptoEngine was touched.

swift-argument-parser 1.8.0 raises its minimum to Swift 6 — satisfied, the project is on 6.4. 1.8.1 reverted the 1.8.0 source-compatibility regression around parse()/parseAsRoot(), so no call-site change is needed.

SwiftLint 0.64.0 has a config-breaking change to force_unwrapping's ignored_literal_argument_functions, and renames allow_implicit_init on optional_data_string_conversion. Neither rule is configured in .swiftlint.yml, so no config migration was required.

Source changes the tooling required

Two changes, both mechanical:

SwiftLint 0.65.1 added legacy_swiftui_aspect_ratio, which flagged the single use of .aspectRatio(contentMode:) with a constant content mode, in PDFPageViewerView.swift:24. Replaced with .scaledToFit() — these are exactly equivalent (scaledToFit() is defined as aspectRatio(nil, contentMode: .fit)). It was the only occurrence in the package.

SwiftFormat 0.63.0 reformatted 17 files under two rules:

  • Single-line if x { stmt } bodies expanded onto their own lines (15 files).
  • Redundant SwiftUI Group wrappers removed, with @ViewBuilder added where the wrapper had been supplying the builder context — OTPCodeDetailView.descriptionSection and VaultAutofillView.body.

All of it is layout-only. No branch, condition, or error path changed. That matters for the files touching killphrase and search-passphrase handling (VaultDataModel, VaultDetailKillphraseEditView, and the two rehash service test doubles) — the reformatting preserves branch structure exactly, so the indistinguishability requirements in MANIFESTO.md are unaffected.

The Group removals are the only changes with any theoretical rendering risk, since they alter the resulting view's static type. Both sites sit inside a Form alongside sibling Sections, where Group is transparent. The snapshot suite confirms this empirically — see below.

Verification

Local, Xcode 27.0 RC1 (27A266a), iPhone 18 Pro Max / iOS 27.0:

  • xcodebuild build-for-testing — TEST BUILD SUCCEEDED, no warnings. Note -warnings-as-errors is enabled package-wide, so any new deprecation from the updated dependencies would have failed the build.
  • Full suite, -parallel-testing-enabled NO — TEST EXECUTE SUCCEEDED, 2848 tests passed, 0 failures, 0 crashes, across both test plan configurations (Default and TSAN).
  • 112 snapshot assertions passed with zero mismatches and zero re-recordings, and git status shows no change under any __Snapshots__ directory. This is the direct evidence that the Group removals did not alter rendering.
  • make format then make lint — clean and idempotent.

One cosmetic upstream warning now appears during make lint, from BigInt's own manifest:

'bigint': .../BigInt/Package.swift:18:19: warning: 'v4' is deprecated: watchOS 9.0 is the oldest supported version

It originates inside the dependency's Package.swift, not our sources, and does not fail the build or lint.

⚠️ Automatic CI is still disabled (#548), so none of this ran on a runner — the verification above is entirely local.

SwiftFormat's declared Swift version

Vault/.swiftformat declared --swiftversion 6.2 while the project builds with the Xcode 27 toolchain, which is Swift 6.4. SwiftFormat uses this value to gate version-conditional rules, so a stale value silently suppresses rules that only apply at newer language versions.

Bumped to 6.4. Re-running make format against it produces no source changes whatsoever — the entire diff is the config line. So this carries no rendering or behavioural risk; it only ensures future version-gated rules evaluate against the right version. make lint is clean with it.

Because no source file changed, the build and test results above still hold and were not re-run for this commit.

🤖 Generated with Claude Code

bradleymackey and others added 2 commits September 13, 2026 17:25
Brings every dependency to its latest release. Six were behind:

- swift-snapshot-testing  1.19.2 -> 1.19.4
- BigInt                  5.7.0  -> 6.0.1
- swift-argument-parser   1.6.2  -> 1.8.2
- swift-syntax            600.0.1 -> 603.0.2
- SwiftLintPlugins        0.63.3 -> 0.65.1
- SwiftFormat             0.61.1 -> 0.63.0

swift-syntax was the only dependency declared with `from:` rather than
`exact:`, which is why it stayed on 600.0.1 — SwiftPM treats 600 and 603
as separate majors, so the range never reached the current release. It is
now pinned `exact:` to match every other dependency and to keep drift
visible.

BigInt's 5.x -> 6.x major bump carries no API change; it reflects a
swift-tools-version move to 6.0. Platform requirements are unchanged.

Tooling updates required two source changes:

- SwiftLint 0.65.1 adds `legacy_swiftui_aspect_ratio`, which flagged the
  single use of `.aspectRatio(contentMode: .fit)`. Replaced with the
  equivalent `.scaledToFit()`.
- SwiftFormat 0.63.0 expands single-line `if` bodies onto their own lines
  and strips redundant SwiftUI `Group` wrappers, adding `@ViewBuilder`
  where the wrapper was load-bearing for the builder context.

All formatting changes are layout-only — no branch, condition, or error
path was altered.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`.swiftformat` declared `--swiftversion 6.2` while the project builds with
the Xcode 27 toolchain, which is Swift 6.4. SwiftFormat uses this value to
gate version-conditional rules, so a stale value silently holds back rules
that only apply at newer language versions.

Reformatting with 6.4 produces no source changes at all — the only diff is
the config line itself. The bump is purely so future version-gated rules
evaluate against the correct version.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@bradleymackey
bradleymackey merged commit d6cb738 into main Sep 13, 2026
@bradleymackey
bradleymackey deleted the maintain/dependency-audit branch September 13, 2026 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant