Skip to content

chore(deps): relax the dexie pin now that nextcloud-vue loads it lazily - #765

Merged
rubenvdlinde merged 1 commit into
developmentfrom
chore/relax-dexie-pin
Sep 27, 2026
Merged

rubenvdlinde merged 1 commit into
developmentfrom
chore/relax-dexie-pin

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

Relaxes the fleet dexie rule: dexie goes from the exact pin 4.4.6 back to ^4.4.6, and the Dependabot ignore entry for dexie is removed. The resolved version stays 4.4.6, so nothing is reinstalled.

Why now. The exact pin, the ignore and the "move all apps at once" rule existed because every app evaluated Dexie on every page, and Dexie throws "Two different versions of Dexie loaded in the same app" when two copies differ. Since 2026-09-27, every in-scope app is on @conduction/nextcloud-vue 2.57.1, which imports Dexie on first use of the offline database (nextcloud-vue#1266). The main and every-page bundles no longer carry it, so a Dexie difference between apps can no longer blank a page that doesn't use offline collection.

What still holds. A page where two different apps both open the offline database still needs them on one Dexie version. That is rare, and why this is a caret range and not a free-for-all.

Changes: pkg 4.4.6 -> ^4.4.6 | dependabot: no dexie ignore

Verified: a real npm ci --ignore-scripts installs from the lockfile with the new range (npm refuses when package.json and the lockfile disagree), and .github/dependabot.yml still parses as YAML.

🤖 Generated with Claude Code

@conduction/nextcloud-vue 2.57.1 imports Dexie on first use of the offline
database, so this app's main bundle no longer carries it. The exact pin and
the Dependabot ignore existed to keep every app on one Dexie version because
every page evaluated it; the pin goes back to a caret range and Dependabot
may bump dexie here again.
@rubenvdlinde
rubenvdlinde merged commit 4c214a9 into development Sep 27, 2026
37 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/keepiq @ ead2e8d

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
test-l10n ✅
format ✅
check-l10n-js ✅
check-schema-l10n ✅
composer ✅ ✅ 114/114
npm ✅ ✅ 660/660
app:check-code ⏭️
info.xml ✅
REUSE ✅
lockfile sync ✅
PHPUnit ✅
Newman ✅
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ✅

Quality workflow — 2026-09-27 17:55 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant