Skip to content

chore(deps): update runtimes and supporting dependencies - #2803

Merged
justinhelmer merged 2 commits into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-259153772d
Oct 6, 2026
Merged

justinhelmer merged 2 commits into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-259153772d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

TL;DR

Updates the grouped runtime and development dependencies, keeping the installed Pi/OpenCode packages and all execution images on the same exact versions. Regenerated dashboard captures and complete protocol handling make the upgraded dependency set verifiable.

Why

The grouped update previously left image/client pins behind the installed packages and omitted a new OpenCode metadata event. Those mismatches failed readiness and CI; renderer dependency changes also invalidated screenshot records.

Where to look

  1. Runtime pins: Pi 0.87.1 and OpenCode 2.0.18 agree with the image installs and their version proofs.
  2. Metadata event handling: Opaque session annotations are structure, with no turn, error, or execution settlement.
  3. Protocol samples: Complete response samples must decode against the upgraded schema.
  4. Real runtime proof: Fresh starts, rebuilds, and reattachments verify the actual installed server version.
  5. Capture inputs: All 22 surfaces have regenerated light/dark captures and current dependency hashes.

Feedback wanted

Check the runtime/library/image agreement and metadata-event classification; the unknown-event and strict version guards must remain intact.

Risk

Dependency installs and runtime protocols change. Generated lockfile churn exceeds 400 lines; keeping manifests and images together avoids mixed versions. Roll back the dependency/image pins and regenerate captures together if needed.

Verified

Full npm run verify and all workspace checks pass; 176 focused harness tests pass, including the real OpenCode binary. Required current-head CI and local review pass.

Decisions and validation
  • Preserve exact Pi/OpenCode pins across the root package, published package, client, and all three execution images. Do not weaken readiness checks.
  • Classify session.metadata.updated as structure because the upgraded schema defines opaque host-supplied annotations. The bridge must not treat it as a new turn, error, or terminal event.
  • Keep the pinned event catalogue equality test and add the metadata case to the existing bridge behavior family. The baseline fails both the catalogue and metadata classification; the repaired tests pass.
  • Regenerate screenshot records and PNGs through screenshots:gen after rebasing; no generated hash or capture was manually edited. Visual checks cover light/dark surfaces and the embedded costs image.
  • Keep the lockfile/workspace record for @cloudflare/vitest-plugin exactly at 1.3.1. The root test runner and memory Worker retain their separate supported Vitest versions.
Criterion Proof
Failed behavior reproduced before repair bridge.test.ts: catalogue equality and metadata structural handling both fail at the unmodified table.
Runtime and protocol compatibility Five named harness/image files: 176 passed, including six real OpenCode CLI/proxy tests.
Full local acceptance npm run verify exits 0; root 16,795 passed/6 skipped, web 605, Worker suites 99/359/12/625, published package 29; one Worker expected failure remains expected.
Static/generated acceptance Consistency, root/workspace typechecks, lint, formatting, specs, registry, lockfile, builds and docs-site checks pass.
Behavioral coverage specs:coverage --changed origin/main --require passes; the metadata criterion has an exact existing test reference.
Rendering All 44 captures regenerated; screenshot freshness passes. A final forced repeat retained all 44 PNGs byte-for-byte, with no tracked tree changes.
Remote acceptance Current-head CI passes; exact-head local review is approved. No deployment is claimed.

Rebased onto a8d347d on the original Dependabot branch. Scratch logs remain outside the repository.

@dependabot
dependabot Bot requested a review from justinhelmer as a code owner October 6, 2026 03:15
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested: The harness upgrades leave runtime pins inconsistent, and rendering dependency changes leave all screenshot artifacts stale.

Warning

Changes requested · head 2debd9a · 3 findings: 1 major, 2 minor

Severity Finding Where
major F1 Spec contradiction — harness.md item 12: OpenCode dependencies upgrade without the runtime pin package.json:105
minor F2 Spec contradiction — harness-pi.md item 3: pi packages and execution images use different versions package.json:93
minor F3 Spec contradiction — docs-site.md item 20: rendering dependencies change without screenshot regeneration web/package.json:17

F1 invariant: OpenCode CLI, protocol/schema packages, adapter version checks and every execution image must use one supported exact version, so the installed CLI passes readiness and compatible sessions can reattach.

  • A fresh local npm-run OpenCode request starts the installed @opencode/cli 2.0.18; launchOpenCode receives /api/info version 2.0.18. → The supported adapter version matches 2.0.18 and readiness proceeds without OpenCodeNotReadyError.
  • A local OpenCode rebuild or relaunch starts the same installed 2.0.18 CLI. → The replacement server passes the same supported-version readiness check.
  • The client contract is checked against installed @opencode/protocol and @opencode/schema 2.0.18. → Both packages match OPENCODE_VERSION, and the adapter's routes and consumed response shapes conform to that version.
  • A preset without a workspace starts OpenCode from the root Dockerfile runtime stage, currently pinned and proven at 2.0.12. → The bot image installs and proves the same 2.0.18 version as the upgraded CLI, schema and adapter.
  • A resident-backed run starts OpenCode from deploy/cloudflare-resident/Dockerfile, including the worker1 version proof, currently 2.0.12. → The global install and thread-user proof both match the upgraded adapter's exact 2.0.18 pin.
  • A cold sandbox run starts OpenCode from deploy/cloudflare-sandbox/Dockerfile, currently installed and proven at 2.0.12. → The sandbox install and build-time proof match the same supported 2.0.18 pin.
  • A same-container resume probes a live 2.0.18 OpenCode server in reattachOpenCode. → Version identity alone does not reject the supported server; remaining session, authentication and feed checks still apply.

F2 invariant: The bot's pi-ai library, development pi-coding-agent, published runtime dependency and all three image installs and proofs must move together at one exact pi version.

  • Root package.json and packages/switchboard/package.json resolve @earendil-works/pi-ai 0.87.1. → The library pin equals the pi-coding-agent version used by every image.
  • npm-run CLI requests and SDK/real-binary checks use the development @earendil-works/pi-coding-agent 0.87.1. → The development harness version equals the deployed harness version and the exact version guard.
  • The root Dockerfile globally installs and proves pi 0.87.0 for bot-host runs. → Its install and version proof use 0.87.1 consistently with the upgraded package dependencies.
  • deploy/cloudflare-sandbox/Dockerfile installs and proves pi 0.87.0 for cold workspace runs. → Its install and proof use the same upgraded 0.87.1 pin.
  • deploy/cloudflare-resident/Dockerfile globally installs pi 0.87.0 and separately proves that version as worker1. → Both global and thread-user proofs use 0.87.1, with imagePiHarness.test.ts retaining exact cross-image/library equality.

F3 invariant: Every screenshot surface's committed manifest must hash its current rendering dependency closure, with its light and dark pictures regenerated through screenshots:gen when those inputs change.

  • home-empty light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current package.json, web/package.json and projected package-lock.json hashes.
  • home-conversation light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • home-live light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • runs-index light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • runs-index-viewing-as light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • run-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • residents light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • costs light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • plane light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • costs-users light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • metrics light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • costs-models light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • scheduled light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • unit-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • unit-page-coding-only light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • unit-search light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • unit-search-landed light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • conductor-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • review-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • settings-mcps light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • settings-channel light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
  • settings-installation light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
Full review

F1 (high confidence): The installed OpenCode CLI is now 2.0.18, but OPENCODE_VERSION remains 2.0.12. A local OpenCode request therefore fails immediately at process.ts:711–712: “the opencode on PATH is 2.0.18; this build drives 2.0.12.” Reattachment rejects that version too, while all three images still ship the older binary. Move the adapter, image installs/proofs and spec to 2.0.18 together, preserving strict version checks and validating the upgraded protocol behavior.

F2 (high confidence): Both pi packages move to 0.87.1, but the bot, resident and sandbox images—and their exact-version guard—remain at 0.87.0. This violates the required library/CLI/image equality: local verification exercises a different pi version from deployed runs. Update every image install and version proof, including the resident’s worker1 proof, together with the guard.

F3 (high confidence): The rendering dependency changes invalidate all 22 screenshot surfaces, but no pictures or manifests are regenerated. Their dependency hashes match the merge-base and differ at this head; screenshots:check reports all surfaces stale. Run npm run screenshots:gen and commit the generated artifacts rather than editing hashes or weakening the freshness check.

@coreplane-switchboard
coreplane-switchboard Bot force-pushed the dependabot/npm_and_yarn/minor-and-patch-259153772d branch from 2debd9a to 7dc37c8 Compare October 6, 2026 03:35
dependabot Bot and others added 2 commits October 5, 2026 21:43
Co-Authored-By: coreplane-switchboard[bot] <318072483+coreplane-switchboard[bot]@users.noreply.github.com>
@justinhelmer
justinhelmer force-pushed the dependabot/npm_and_yarn/minor-and-patch-259153772d branch from 7dc37c8 to bf46f92 Compare October 6, 2026 04:54
@justinhelmer justinhelmer changed the title chore(deps): bump the minor-and-patch group across 1 directory with 19 updates chore(deps): update runtimes and supporting dependencies Oct 6, 2026

@justinhelmer justinhelmer left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed locally at exact head bf46f92.

F1 fixed: OpenCode CLI, protocol/schema packages, client readiness pin, and all image install/version proofs agree at 2.0.18. Complete protocol samples and real start/rebuild/reattach tests pass.
F2 fixed: Pi library/development CLI/published package pins and all image proofs agree at 0.87.1.
F3 fixed: All 22 surface manifests and 44 captures were regenerated after rebase. The final repeat retained all 44 PNGs byte-for-byte; freshness and output checks pass.

The additional CI failure is fixed by treating session.metadata.updated as opaque structural metadata. Exact event-catalogue equality, unknown-event guards, and the bridge's non-terminal behavior remain covered.

Validation: npm run verify (root and all workspaces) passed; 176 focused harness/image tests and 66 screenshot tests passed; required spec coverage passed. No actionable issue found in the final dependency/compatibility diff. Current-head remote CI must finish successfully before merge.

@justinhelmer
justinhelmer merged commit da8f733 into main Oct 6, 2026
32 checks passed
@justinhelmer
justinhelmer deleted the dependabot/npm_and_yarn/minor-and-patch-259153772d branch October 6, 2026 05:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant