Repository navigation
deps: hold eventsource-parser at v3, take the rest of the npm group - #493
Conversation
eventsource-parser@4.0.0 removes the `require` condition from its exports
map (ESM-only) and raises engines.node to >=22.12 -- the release where
Node's require(esm) went unflagged. Those are the same decision upstream.
@wavehouse/sdk ships a CJS build and externalises this dependency
(clients/ts/dist/index.cjs contains a literal require("eventsource-parser"))
while advertising engines.node ">=22", so v4 breaks the CJS entry point on
Node 22.0-22.11 -- inside our supported range. Nothing in CI exercises that
path: .nvmrc is `22`, which resolves above 22.12, and every suite runs ESM,
which is why #491 went fully green while proposing it.
It is the SDK's only runtime dependency. The API surface is unaffected --
sse.ts uses just createParser({onEvent}) and parser.feed() -- so holding at
v3 costs nothing functionally. The unblock is a decision rather than an
upstream wait (raise the SDK floor to >=22.12, or stop shipping CJS), so it
gets a tracking issue: #492.
Takes the other two bumps from #491: astro-vtbot ^3.0.1->^3.1.0 and
@biomejs/biome ^2.4.16->^2.5.8. Lockfile changes exactly those two (plus
biome's platform binaries); eventsource-parser is untouched.
Closes #491.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEwX2gCkH2BSzEfX6bUvDV
|
Warning Review limit reached
Next review available in: 13 minutes Limit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits within each organization. For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
📚 Docs preview is live → https://c9f27eb8-wavehouse-docs.wave-rf.workers.dev
|
Holds
eventsource-parserat major 3 and takes the other two bumps fromDependabot #491.
Closes #491. Tracked by #492.
Why hold it
eventsource-parser@4.0.0is not a routine major — it drops the CJS build:exports["."]3.1.0{ import, require: "./dist/index.cjs", default }— dual4.0.0{ source, default: "./dist/index.js" }— ESM-only, norequireand raises
engines.nodefrom>=18.0.0to>=22.12. Those are onedecision: 22.12 is where Node's
require(esm)went unflagged, so upstreamdropped CJS and set the floor to match.
@wavehouse/sdkships a CJS build and does not bundle this dependency:main: "./dist/index.cjs",exports["."].require: "./dist/index.cjs"clients/ts/dist/index.cjscontains a literalrequire("eventsource-parser")(tsup externalises
dependenciesby default)engines.node: ">=22"So v4 gives:
require(esm)resolves itERR_REQUIRE_ESM; the SDK's CJS entry point is brokenThat window is inside our advertised range, and
>=22is a deliberate choice(CHANGELOG: "
engines.nodefloor back to>=22, matching the only line wetest"). It is also the SDK's only runtime dependency.
The API surface is unaffected —
clients/ts/src/stream/sse.tsuses onlycreateParser({ onEvent })andparser.feed(), both unchanged in v4 — soholding at v3 costs nothing functionally.
Why CI didn't catch it
Nothing exercises the CJS entry point.
.nvmrcis22, which resolves to thelatest 22.x (22.23.x, above 22.12), and every suite runs ESM. #491 went fully
green while proposing this break. A suggested guard is written up in #492.
Unblock is a decision, not an upstream wait
Take v4 when we either raise the SDK's floor to
>=22.12, or stop shippingCJS. Both are user-visible changes to supported Node, which is why neither
should ride in on a dependency bump. #492 holds the detail; the
.github/dependabot.ymlcomment points at it.Also landed
The two harmless rows from the same group, so #491 doesn't sit stale waiting
for Monday:
astro-vtbot^3.0.1 → ^3.1.0@biomejs/biome^2.4.16 → ^2.5.8The regenerated lockfile changes exactly those two (plus biome's eight
platform binaries).
eventsource-parseris untouched:Both cleared the 7-day
minimumReleaseAgecooldown (each published 2026-08-11).Verification
make cigreen locally (Docker up).HEAD— no additions,no removals, no transitive drift beyond the two intended packages.
registry
exports/enginesforeventsource-parser@4.0.0, the literalrequire()in the builtdist/index.cjs, the SDK'sengines.nodeanddependencies, andsse.ts's import surface.Review note
Both pre-push reviewers were deliberately skipped at the repo owner's
explicit direction, recorded via
scripts/skip-pre-push-review.sh(reasons intmp/review-skips-<sha>.log). The script warned that a review was probablywarranted in both lanes; flagging that here rather than leaving it in a local
log.
make ciwas not skipped.