chore!: upgrade dependencies, adopt Fallow, and fix json-render panels - #93
Merged
Merged
Conversation
Make locally consumed helpers and schema fragments private, remove unused forwarders and orphan declarations, and retain error fields with production or structural-test consumers. Document the current package and error surface. Fallow findings decrease from 183 to 53, with unused exports and types at zero. The remaining findings match the reviewed retention ledger. BREAKING CHANGE: unused schema/type exports and four unconsumed error code properties have been removed. Consumers must use the current documented validation entry points and error classes.
Retain the Node 26 toolchain and Fallow dependency checks while merging main's browser collection, smoke-server regression test, desktop coverage script, and memory-only tabletop test setup.
7 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Update workspace dependencies, standardize the Node toolchain on 26.x, and fix draft synchronization and interaction state in json-render plugin panels. Replace Knip with Fallow and remove unused code and exports based on references and test evidence.
Upgrade json-render to 0.21. Fix numeric object keys becoming arrays, equivalent external arrays overwriting local drafts, stale dynamic button parameters, and old callbacks bypassing panel interaction locks. Add focused regression tests.
Use Fallow for dependency checks and comprehensive analysis, with dynamic plugin entry points configured. Two cleanup passes reduced static candidates from 234 to 53, eliminated unused exports/types, and reduced module cycles from 9 to 0.
Retain 40 groups of same-named exports across modules, 12 class members with production callers or test coverage, and one development-script dependency advisory. Preserve fields required by structured-error tests without weakening tests or adding ignore rules to reduce findings.
Include the CI fixes from main: start smoke services once, collect browser tests, and provide the desktop coverage script.
Fix clean-checkout dependency checks by constructing the generated lifecycle-probe ZIP output with
path.resolve. Fallow previously treated itsnew URL(..., import.meta.url)expression as an asset import and failed before the ZIP existed.Add
pnpm hooks:installandpnpm check:push. The automatic pre-push hook verifies each pushed commit in a disposable clean checkout with a frozen install, the static gate, bounded unit tests, and E2E collection. It blocks failed pushes, preserves existing pre-commit hooks, and excludes developer database settings. PostgreSQL integration, browser smoke, and packaging remain separate gates.BREAKING CHANGE: Remove unused schema/type exports and the code property from four error objects while retaining implementations that have consumers. Plugins should use the documented full-manifest validation entry point and identify the affected errors by error class.
Type of change
Verification
Validation for the clean-checkout CI fix and automatic pre-push checks:
pnpm check, including lint, dependency/import checks, package boundaries, manifests, localization, script tests, and actionlint.VITEST_MAX_WORKERS=2 pnpm test --concurrency=2: 46/46 tasks passed, with 44 cache hits. The server suite reran with 200 passing test files and 1,662 passing tests (2 skipped).pnpm pack:test-pluginin that snapshot and verify the generated ZIP has 18 valid entries, includingPLUGIN.mdandpackage.json, at the expected output path.a4a42206) and the final pre-push implementation (3e5a6633): final CI run.Previously completed validation for the broader PR:
pnpm lintandpnpm test --concurrency=2: 46/46 tasks and 7,793 Vitest tests passed. An initial high-concurrency run failed one test with a 20 ms real-time deadline; both its focused rerun and the complete lower-concurrency run passed.pnpm e2e --workers=2plus reruns of failed files: the initial run had 115 passed, 6 skipped, and 3 failed. Both affected files then passed in full against isolated services (7/7). All 118 runnable cases passed at least once; the initial run was not fully green.pnpm exec fallow dead-code --format json --no-cache: 53 findings, each matched to retention records. The comprehensive scan exited with code 1 for retained findings; the dependency/import gate passed locally.pnpm install --frozen-lockfile.After merging main, validation also passed for
pnpm check,pnpm test --concurrency=2(46/46 tasks, 42 cache hits), full E2E collection (124 cases),pnpm e2e:smoke --workers=2(4/4), and tabletop E2E (2/2). The comprehensive scan still reported 53 findings. Gitleaks passed for the full PR diff and outgoing commit history.Related issue / context
Requested dependency updates, a Node 26 major-version constraint, focused json-render verification, and a detailed Fallow audit and cleanup. This PR targets main and retains the merged CI fixes from #92.
Docs sync
docs/reference/ui-panels.md,plugins.md, andapi.mdfor panel synchronization rules and the narrowed public interfaces.