Skip to content

ci(renovate): pin the napi-rs toolchain and hold flate2 - #604

Merged
derodero24 merged 2 commits into
developfrom
ci/issue-575-renovate-toolchain
Oct 3, 2026
Merged

derodero24 merged 2 commits into
developfrom
ci/issue-575-renovate-toolchain

Conversation

@derodero24

@derodero24 derodero24 commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

Problem (#575)

Fix

  • renovate.json:
    • New "napi-rs toolchain" group: @napi-rs/* plus the napi, napi-derive and napi-build crates, major updates included, never automerged. It comes after the generic rules, because later rules win.
    • @napi-rs/* stays at exact versions in package.json (rangeStrategy: pin, npm only), so a toolchain update shows in the reviewed diff. The crates keep their "3" and "2" requirements.
    • flate2 is limited to <=1.1.9, with a description pointing at perf(gzip): flate2 1.1.10 regresses gzip/deflate throughput with the zlib-rs backend #509.
    • Lock file maintenance runs monthly and is not automerged.
      • The schedule is * * 1-7 * * because the Renovate workflow runs once a week, on Sunday at 19:00 UTC. The built-in monthly schedule ("before 4am on the 1st") would never coincide with a run.
      • Cargo.lock gets its own PR through the rust-dependencies group.
      • minimumReleaseAge: null: a lock refresh has no release timestamp, so the inherited 3-day age would keep its stability check pending for good.
    • GitHub Actions updates, digests included, wait 3 days, with minimumReleaseAgeBehaviour: "timestamp-optional".
      • Renovate checks a digest update's age at lookup time, against the release its tag resolves to, but the update itself carries no timestamp.
      • Under the default timestamp-required, the branch would never pass the stability check or automerge.
      • With timestamp-optional, the 3-day hold still applies at lookup time.
      • Rationale: a retargeted tag is how the tj-actions/changed-files compromise reached SHA-pinned workflows, as ordinary digest updates.
    • Everything else is unchanged.
  • package.json / pnpm-lock.yaml: @napi-rs/cli is pinned to the locked 3.9.1. Only the specifier changes.
  • ci.yml, changes job: a pull request now also gets the full native matrix, and with it the all-targets Release Dry Run, when a changed line in package.json, pnpm-lock.yaml or pnpm-workspace.yaml names napi as a word. That covers the @napi-rs packages, including the ones the CLI pulls in, and the napi scripts.
    • Trade-off: treating these files as native outright would send every npm update, including the weekly Renovate group, through 8 builds plus the macOS and Windows test legs.
    • The narrower check can miss a toolchain change that names no napi package, such as a transitive dependency of the CLI moving on its own. An edit to the napi.targets list is not matched either, but it always comes with its npm/ package, which already counts as native. develop runs the full matrix after every merge, so such a change cannot reach a release untested.
    • The diff is captured before grep -q reads it, so the check keeps working if the step ever runs under pipefail.

Tests

  • renovate-config-validator --strict passes with Renovate 44.115.13, the release that last ran on this repository.
  • A local Renovate lookup run shows:
    • CLI 3.10.5, napi 3.14.0, napi-derive 3.6.10 and napi-build 2.6.0 all go to renovate/napi-rs-toolchain.
    • flate2 1.1.10 is no longer proposed, in either Cargo.toml or the fuzz crate.
    • Two lock file maintenance branches appear.
  • A harness built on Renovate's own preset-resolution and branch-grouping code confirms automerge, grouping, schedule and stability for each branch. It also shows that both timestamp settings are needed: without them, both lock file maintenance PRs and the actions digest update stay pending for good.
  • The changes filter was replayed old vs new on chore(deps): update github-actions (non-major) #532, chore(deps): update npm dependencies (non-major) #533, chore(deps): update rust-dependencies #534 and synthetic commits, under both bash -e and bash -eo pipefail.
    • chore(deps): update npm dependencies (non-major) #533 and a CLI bump in package.json give native=false before and native=true after.
    • biome-only, openapi-types-only and middleware-only changes stay on Linux.
    • Over the last 15 develop commits that touch these files, the check fires only for CLI or emnapi bumps and for changes that were already native.
  • Repo checks pass: Rust fmt, clippy and tests, Biome, typecheck, Vitest, and build:debug with no drift in generated files.
  • There is no committed regression test: these are config and workflow changes, so they were checked with the replays above.

Notes

Related issue

Closes #575
Part of #535

Breaking changes / Deprecations

N/A

Checklist

  • Lint passes (pnpm run check)
  • TypeScript type-check passes (pnpm run typecheck)
  • JS tests pass (pnpm test)
  • Rust tests pass (cargo test): cargo test --workspace; cargo fmt --all -- --check passes
  • Clippy passes (cargo clippy): no warnings with --all-targets -- -W clippy::all
  • Build succeeds (pnpm run build): verified with pnpm run build:debug, no drift in generated files; cross-target builds and the Release Dry Run are left to CI, which runs the full matrix for this PR
  • Changeset included (if crates/ changed) — N/A, crates/ is unchanged; CI and dev tooling only
  • Benchmarks run for performance-sensitive changes — N/A, no runtime code changes

🤖 Generated with Claude Code

https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS

Summary by CodeRabbit

  • CI
    • 依存関係の設定にネイティブ関連の変更がある場合、Linuxに加えて全プラットフォームでビルド・テストを実行するようになりました。
  • 開発環境
    • 開発用CLIのバージョンを固定しました。
  • 依存関係の更新
    • ロックファイルの定期更新を有効にし、更新の対象や自動マージのルールを調整しました。

claude added 2 commits October 3, 2026 16:06
The changes job runs every build target, and with them the release
packaging dry run over all eight platform packages, only when a pull
request touches crates/, npm/, scripts/, the Cargo files or the
workflows. @napi-rs/cli drives every native build and the packaging,
but its updates land in package.json and pnpm-lock.yaml, so they were
built for Linux alone. Renovate's open PR #533 moves the CLI from 3.9.1
to 3.10.5 in the lockfile only; the 3.9.1 update itself broke the first
two 2.0.2 publish attempts (#526, #529).

Also run the full matrix when a changed line in package.json,
pnpm-lock.yaml or pnpm-workspace.yaml names napi as a word: the
@napi-rs packages, including those the CLI pulls in, and the napi
scripts. Treating those files as native outright would send every npm
update, the weekly Renovate group included, through eight builds and
the macOS and Windows test legs, although nothing in them reaches a
binary. The narrower check can miss a toolchain change that names no
napi package, such as a transitive dependency of the CLI moving on its
own, or an edit to the targets in the napi field, which comes with its
npm/ package anyway. develop runs the full matrix after every merge,
so such a change cannot reach a release untested.

The diff is captured before grep -q reads it. Piped straight in, grep
stops at the first match and, under pipefail, the git diff it cuts off
would turn a match into a miss on a large lockfile diff.

Refs #575

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS
Renovate treated the packages that build and package comprs like any
other dependency. @napi-rs/cli sat behind a ^3.7.1 range in the
automerged non-major npm group, so a new CLI arrived as a lockfile-only
change and merged once CI passed; 3.9.1 came that way and broke the
first two 2.0.2 publish attempts (#526, #529). Now that the napi crates
are no longer held (#518), their minor and patch updates would be
automerged with the other crates as well. The cargo automerge rule also
overrode the deliberate flate2 =1.1.9 pin (#509): open PR #534 rewrites
it to =1.1.10, and only a test that happens to catch another behaviour
change in 1.1.10 keeps it from merging.

- Group @napi-rs/* and the napi, napi-derive and napi-build crates as
  "napi-rs toolchain", majors included, and never automerge it. The
  rule follows the generic ones because later rules win.
- Pin @napi-rs/cli to the locked 3.9.1 and keep the @napi-rs packages
  pinned, so a toolchain update shows in the reviewed package.json
  diff. The crates keep their major-version requirements; pinning
  them would turn "3" into "=3.13.0".
- Allow flate2 only up to 1.1.9 until #509 is resolved.
- Refresh the lock files once a month, without automerge. The workflow
  runs Renovate weekly, so the schedule covers the first seven days of
  the month; the built-in monthly schedule, before 4am on the 1st,
  would never coincide with a run. Cargo.lock gets its own PR through
  the rust-dependencies group. A refresh has no release timestamp to
  age, so it opts out of the minimum release age, which would keep
  its stability check pending for good.
- Hold GitHub Actions updates, digests included, for 3 days instead of
  0 (#385): retargeted tags are how the tj-actions/changed-files
  compromise reached even SHA-pinned workflows, as ordinary digest
  updates. Renovate ages a digest update by the release its tag
  resolves to, but the update carries no timestamp of its own, and
  with the default timestamp-required behaviour its branch would never
  pass the stability check or automerge. timestamp-optional keeps the
  3-day hold at lookup time and lets the branch merge afterwards.

renovate-config-validator 44.115.13, the Renovate release that last
ran on this repository, accepts the config. A local lookup with it
puts @napi-rs/cli 3.10.5 and napi 3.14.0, napi-derive 3.6.10 and
napi-build 2.6.0 in the napi-rs toolchain branch and no longer
proposes flate2 1.1.10, which the current config offers for both
Cargo.toml and the fuzz crate.

Closes #575

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS
@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 0a0a1e26-8fe3-44ce-8970-5a0802c16f4a
📥 Commits

Reviewing files that changed from the base of the PR and between dd3f2b6 and a08e610.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • package.json
  • renovate.json
 ________________________________________________
< Squeezing intelligence out of LLMs since 2023. >
 ------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

WASM Binary Size

File Size
comprs-wasm_bg.wasm 2103 KB

@derodero24
derodero24 merged commit b10e121 into develop Oct 3, 2026
33 of 34 checks passed
@derodero24
derodero24 deleted the ci/issue-575-renovate-toolchain branch October 3, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci(renovate): toolchain-sensitive updates are automerged and the flate2 pin is overridden

2 participants