Skip to content

Revert "fix(deps): update npm dependencies (major) (#1128)" - #1136

Merged
rekmarks-consensys-1 merged 2 commits into
mainfrom
grypez/fix-stale-lockfile
Oct 1, 2026
Merged

rekmarks-consensys-1 merged 2 commits into
mainfrom
grypez/fix-stale-lockfile

Conversation

@ci-belphegor

Copy link
Copy Markdown
Contributor

Explanation

Reverts #1128 and regenerates yarn.lock.

#1128 bumped package.json ranges without updating yarn.lock, so yarn install --immutable fails on main. CI stays green because it caches node_modules keyed on yarn.lock. Any PR that changes the lockfile (e.g. by adding a dependency) gets a fresh install and fails.

Resolving #1128's ranges also breaks the build, so a lockfile update alone won't fix it:

  • @endo/patterns 2 / @endo/pass-style 2 don't work with @endo/exo 1.7.0, the latest release, which still depends on @endo/patterns ^1.9.0. Guards built with the new M fail to type-check against makeExo (first failure: remote-iterables/src/reader-ref.ts).
  • @metamask/utils 12 clashes with the utils 11 copy that @metamask/snaps-execution-environments brings, and ocap-kernel fails to build on JsonRpcError in VatSupervisor.ts.

The lockfile also picks up #1123's design-system bump, the only other drift (16 lines).

Verified locally on a clean install: yarn install --immutable, yarn build, yarn lint, and yarn test:dev:quiet all pass.

Renovate will propose these majors again. The @endo pair has to wait for an @endo/exo release built on patterns 2.

References

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

🤖 Generated with Claude Code

This reverts commit cd587d6. #1128 bumped package.json ranges without
updating yarn.lock, so `yarn install --immutable` fails on main. CI stays
green only because it caches node_modules keyed on yarn.lock, and any PR
that changes the lockfile goes red.

Resolving the bumped ranges also breaks the build:
- @endo/patterns 2 and @endo/pass-style 2 are incompatible with
  @endo/exo 1.7.0 (latest), which still depends on @endo/patterns ^1.9.0.
  Guards built with the new M no longer type-check against makeExo.
- @metamask/utils 12 clashes with the utils 11 that
  @metamask/snaps-execution-environments brings, failing ocap-kernel's
  build on JsonRpcError.

The lockfile is also regenerated for the design-system bump in #1123,
which was the only other drift.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ci-belphegor ci-belphegor added the no-changelog Indicates that no changelog updates are required, and that related CI checks should be skipped. label Oct 1, 2026
@ci-belphegor
ci-belphegor requested a review from a team as a code owner October 1, 2026 19:00

@rekmarks-consensys-1 rekmarks-consensys-1 left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 73.33%
🟰 ±0%
9968 / 13593
🔵 Statements 73.12%
🟰 ±0%
10097 / 13808
🔵 Functions 73.75%
🟰 ±0%
2332 / 3162
🔵 Branches 67.69%
🟰 ±0%
4110 / 6071
File CoverageNo changed files found.
Generated in workflow #5081 for commit 2782701 by the Vitest Coverage Report Action

@rekmarks-consensys-1
rekmarks-consensys-1 added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 11ffd4e Oct 1, 2026
27 checks passed
@rekmarks-consensys-1
rekmarks-consensys-1 deleted the grypez/fix-stale-lockfile branch October 1, 2026 19:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Indicates that no changelog updates are required, and that related CI checks should be skipped.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants