Skip to content

deps: hold eventsource-parser at v3, take the rest of the npm group - #493

Merged
EricAndrechek merged 1 commit into
mainfrom
deps-eventsource-hold
Aug 18, 2026
Merged

EricAndrechek merged 1 commit into
mainfrom
deps-eventsource-hold

Conversation

@EricAndrechek

Copy link
Copy Markdown
Member

Holds eventsource-parser at major 3 and takes the other two bumps from
Dependabot #491.

Closes #491. Tracked by #492.

Why hold it

eventsource-parser@4.0.0 is not a routine major — it drops the CJS build:

exports["."]
3.1.0 { import, require: "./dist/index.cjs", default } — dual
4.0.0 { source, default: "./dist/index.js" } — ESM-only, no require

and raises engines.node from >=18.0.0 to >=22.12. Those are one
decision: 22.12 is where Node's require(esm) went unflagged, so upstream
dropped CJS and set the floor to match.

@wavehouse/sdk ships a CJS build and does not bundle this dependency:

  • main: "./dist/index.cjs", exports["."].require: "./dist/index.cjs"
  • clients/ts/dist/index.cjs contains a literal require("eventsource-parser")
    (tsup externalises dependencies by default)
  • engines.node: ">=22"

So v4 gives:

  • Node ≥ 22.12 — fine, require(esm) resolves it
  • Node 22.0 – 22.11 — ERR_REQUIRE_ESM; the SDK's CJS entry point is broken

That window is inside our advertised range, and >=22 is a deliberate choice
(CHANGELOG: "engines.node floor back to >=22, matching the only line we
test"
). It is also the SDK's only runtime dependency.

The API surface is unaffected — clients/ts/src/stream/sse.ts uses only
createParser({ onEvent }) and parser.feed(), both unchanged in v4 — so
holding at v3 costs nothing functionally.

Why CI didn't catch it

Nothing exercises the CJS entry point. .nvmrc is 22, which resolves to the
latest 22.x (22.23.x, above 22.12), and every suite runs ESM. #491 went fully
green while proposing this break. A suggested guard is written up in #492.

Unblock is a decision, not an upstream wait

Take v4 when we either raise the SDK's floor to >=22.12, or stop shipping
CJS. Both are user-visible changes to supported Node, which is why neither
should ride in on a dependency bump. #492 holds the detail; the
.github/dependabot.yml comment points at it.

Also landed

The two harmless rows from the same group, so #491 doesn't sit stale waiting
for Monday:

  • astro-vtbot ^3.0.1 → ^3.1.0
  • @biomejs/biome ^2.4.16 → ^2.5.8

The regenerated lockfile changes exactly those two (plus biome's eight
platform binaries). eventsource-parser is untouched:

@biomejs/biome:  2.5.6 -> 2.5.8   (+ 8 @biomejs/cli-* binaries)
astro-vtbot:     3.0.1 -> 3.1.0

Both cleared the 7-day minimumReleaseAge cooldown (each published 2026-08-11).

Verification

  • make ci green locally (Docker up).
  • Lockfile delta verified package-by-package against HEAD — no additions,
    no removals, no transitive drift beyond the two intended packages.
  • Every factual claim above re-checked against primary sources: the npm
    registry exports/engines for eventsource-parser@4.0.0, the literal
    require() in the built dist/index.cjs, the SDK's engines.node and
    dependencies, and sse.ts's import surface.

Review note

Both pre-push reviewers were deliberately skipped at the repo owner's
explicit direction, recorded via scripts/skip-pre-push-review.sh (reasons in
tmp/review-skips-<sha>.log). The script warned that a review was probably
warranted in both lanes; flagging that here rather than leaving it in a local
log. make ci was not skipped.

eventsource-parser@4.0.0 removes the `require` condition from its exports
map (ESM-only) and raises engines.node to >=22.12 -- the release where
Node's require(esm) went unflagged. Those are the same decision upstream.

@wavehouse/sdk ships a CJS build and externalises this dependency
(clients/ts/dist/index.cjs contains a literal require("eventsource-parser"))
while advertising engines.node ">=22", so v4 breaks the CJS entry point on
Node 22.0-22.11 -- inside our supported range. Nothing in CI exercises that
path: .nvmrc is `22`, which resolves above 22.12, and every suite runs ESM,
which is why #491 went fully green while proposing it.

It is the SDK's only runtime dependency. The API surface is unaffected --
sse.ts uses just createParser({onEvent}) and parser.feed() -- so holding at
v3 costs nothing functionally. The unblock is a decision rather than an
upstream wait (raise the SDK floor to >=22.12, or stop shipping CJS), so it
gets a tracking issue: #492.

Takes the other two bumps from #491: astro-vtbot ^3.0.1->^3.1.0 and
@biomejs/biome ^2.4.16->^2.5.8. Lockfile changes exactly those two (plus
biome's platform binaries); eventsource-parser is untouched.

Closes #491.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEwX2gCkH2BSzEfX6bUvDV
@github-actions github-actions Bot added documentation Improvements or additions to documentation dependencies Pull requests that update a dependency file area/docs Documentation, site/, README area/infra CI, build, deploy, Docker, release labels Aug 18, 2026
@coderabbitai

coderabbitai Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@EricAndrechek, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 13 minutes

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 88559e3d-4d7d-4e74-be12-ca8dbf7da7b8

📥 Commits

Reviewing files that changed from the base of the PR and between f479b0d and 520252b.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .github/dependabot.yml
  • CHANGELOG.md
  • docs/package.json
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@EricAndrechek
EricAndrechek marked this pull request as ready for review August 18, 2026 22:14
@EricAndrechek
EricAndrechek requested review from a team and taitelee August 18, 2026 22:14
@github-actions

Copy link
Copy Markdown

📚 Docs preview is live → https://c9f27eb8-wavehouse-docs.wave-rf.workers.dev

  • Commit — 520252b: deps: hold eventsource-parser at v3, take the rest of the npm group
  • Author — @EricAndrechek, Claude Opus 5 (1M context)
  • Committed — 2026-08-18 18:10 (UTC-04:00)
  • Deployed — 2026-08-18 18:17 EDT

@github-code-quality

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: Go

Go

The overall coverage in commit 520252b in the deps-eventsource-hol... branch remains at 91%, unchanged from commit f479b0d in the main branch.

@EricAndrechek
EricAndrechek merged commit ce9fa77 into main Aug 18, 2026
27 of 34 checks passed
@EricAndrechek
EricAndrechek deleted the deps-eventsource-hold branch August 18, 2026 22:19
@github-project-automation github-project-automation Bot moved this from Backlog to Done in WaveHouse Task Board Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Documentation, site/, README area/infra CI, build, deploy, Docker, release dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

1 participant