Skip to content

chore(deps): update dependencies except TypeScript - #947

Merged
harlan-zw merged 2 commits into
mainfrom
chore/dependency-updates-no-typescript
Oct 6, 2026
Merged

harlan-zw merged 2 commits into
mainfrom
chore/dependency-updates-no-typescript

Conversation

@harlan-zw

@harlan-zw harlan-zw commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

🔗 Linked issue

Related to #943, #942, #922, #921 and #450.

📚 Description

Update dependencies across the catalog, packages, examples and packed consumers. Keep both existing TypeScript compiler pins unchanged.

Include H3 2, VueUse 15 and Stripe 10. The dev asset handler now returns Web responses. H3 HTTP fixtures use Web request bodies and streams. Vimeo types come from @vimeo/player, replacing the deprecated DefinitelyTyped stub. Refresh the pinned Nuxt 5 nightly and both lockfiles.

MapLibre 6.12 changes its worker queue. Defer cluster changes until pending data loads settle, so the latest options win.

Keep stable channels for @nuxt/devtools-kit and Miniflare. Their newer releases are prereleases. Retain the existing cssnano override and install trust policy.

Dependency migrations: Web responses, SDK-owned Vimeo types, and ordered MapLibre updates

📝 Migration

If you use Stripe types, update @stripe/stripe-js to version 10.
If you use Vimeo types, install @vimeo/player and remove @types/vimeo__player.

🤖 AI disclosure: Harlan Agent Kit modified this description. My AI open-source policy.

@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
scripts-playground Ready Ready Preview Oct 6, 2026 11:38am UTC

Request Review

@harlan-zw harlan-zw added harlan-agent-review Approve automated work for the current issue state or pull request head commit. harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit. and removed harlan-agent-review Approve automated work for the current issue state or pull request head commit. labels Oct 6, 2026
@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/nuxt/scripts/@nuxt/scripts-devtools@947
npm i https://pkg.pr.new/nuxt/scripts/@nuxt/scripts@947

commit: 06dc344

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

📦 Package Size

⚠️ 2 size metrics grew

📚 22 runtime dependencies (🟢 -1 vs 23)

Package output Gzipped Δ
@nuxt/scripts · runtime dependencies 548 kB → 543 kB 🟢 -4.6 kB (-0.8%)
@nuxt/scripts · dependency @vueuse/core 174 kB → 178 kB 🔴 +3.9 kB (+2.3%)
@nuxt/scripts · dependency @vueuse/shared 39 kB → 39 kB 🟢 -363 B (-0.9%)
@nuxt/scripts · dependency h3 34 kB → — 🟢 removed
@nuxt/scripts · dependency lru-cache 115 kB → 141 kB 🔴 +26 kB (+22.8%)
@nuxt/scripts · export . 26 kB → 26 kB 🟢 -24 B (-0.1%)
@nuxt/scripts · published payload 222 kB → 222 kB 🟢 -24 B (-0.0%)
All tracked output (26)
Package output Gzipped Raw
@nuxt/scripts-cli · runtime dependencies 72 kB 355 kB ✅
@nuxt/scripts-cli · dependency magicast 72 kB 355 kB ✅
@nuxt/scripts-cli · export . 3.4 kB 12 kB ✅
@nuxt/scripts-cli · published payload 3.4 kB 12 kB ✅
@nuxt/scripts · runtime dependencies 543 kB 2.40 MB 🟢
@nuxt/scripts · dependency @oxc-project/types 0 B 0 B ✅
@nuxt/scripts · dependency @vueuse/core 178 kB 720 kB 🔴
@nuxt/scripts · dependency @vueuse/shared 39 kB 152 kB 🟢
@nuxt/scripts · dependency h3 34 kB 146 kB 🟢
@nuxt/scripts · dependency lru-cache 141 kB 623 kB 🔴
@nuxt/scripts · dependency semver 25 kB 72 kB ✅
@nuxt/scripts · dependency sirv 8.8 kB 21 kB ✅
@nuxt/scripts · dependency unstorage 70 kB 225 kB ✅
@nuxt/scripts · dependency valibot 82 kB 590 kB ✅
@nuxt/scripts · dist/runtime 104 kB 306 kB ✅
@nuxt/scripts · export . 26 kB 106 kB 🟢
@nuxt/scripts · export ./registry 30 kB 94 kB ✅
@nuxt/scripts · export ./stats 13 kB 92 kB ✅
@nuxt/scripts · export ./types-source 49 kB 247 kB ✅
@nuxt/scripts · published payload 222 kB 845 kB 🟢
@nuxt/scripts · app runtime 176 B 658 B ✅
@nuxt/scripts · components runtime 2.5 kB 6.4 kB ✅
@nuxt/scripts · composables runtime 7.8 kB 26 kB ✅
@nuxt/scripts · registry runtime 46 kB 136 kB ✅
@nuxt/scripts · server runtime 30 kB 89 kB ✅
@nuxt/scripts · utils runtime 2.9 kB 8.1 kB ✅
Runtime dependencies (22)
Package Dependency Requested Resolved Cost
@nuxt/scripts-cli magicast ^0.5.5 0.5.5 📦 72 kB gzip
@nuxt/scripts-cli pathe ^2.0.3 2.0.3 ♻️ free via Nuxt 4.6.0
@nuxt/scripts @nuxt/kit ^4.6.0 4.6.0 ♻️ free via Nuxt 4.6.0
@nuxt/scripts @oxc-project/types ^0.153.0 0.153.0 📦 0 B gzip
@nuxt/scripts @vueuse/core ^15.0.0 15.0.0 📦 178 kB gzip
@nuxt/scripts @vueuse/shared ^15.0.0 15.0.0 📦 39 kB gzip
@nuxt/scripts consola ^3.4.2 3.4.2 ♻️ free via Nuxt 4.6.0
@nuxt/scripts defu ^6.1.7 6.1.7 ♻️ free via Nuxt 4.6.0
@nuxt/scripts lru-cache ^11.5.3 11.5.3 📦 141 kB gzip
@nuxt/scripts magic-string ^1.4.3 1.4.3 ♻️ free via Nuxt 4.6.0
@nuxt/scripts ofetch ^1.5.1 1.5.1 ♻️ free via Nuxt 4.6.0
@nuxt/scripts ohash ^2.0.12 2.0.12 ♻️ free via Nuxt 4.6.0
@nuxt/scripts oxc-walker ^1.1.1 1.1.1 ♻️ free via Nuxt 4.6.0
@nuxt/scripts pathe ^2.0.3 2.0.3 ♻️ free via Nuxt 4.6.0
@nuxt/scripts semver ^7.8.5 7.8.5 📦 25 kB gzip
@nuxt/scripts sirv ^3.0.2 3.0.2 📦 8.8 kB gzip
@nuxt/scripts std-env ^4.3.0 4.3.0 ♻️ free via Nuxt 4.6.0
@nuxt/scripts ufo ^1.6.4 1.6.4 ♻️ free via Nuxt 4.6.0
@nuxt/scripts ultrahtml ^1.7.0 1.7.0 ♻️ free via Nuxt 4.6.0
@nuxt/scripts unplugin ^3.4.0 3.4.0 ♻️ free via Nuxt 4.6.0
@nuxt/scripts unstorage ^1.17.5 1.17.5 📦 70 kB gzip
@nuxt/scripts valibot ^1.5.0 1.5.0 📦 82 kB gzip

Baseline: main_@_0041431e___2026-10-06 · gzip is the comparison metric · changes below 16 B gzip are ignored

@harlan-zw

harlan-zw commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator Author

🤖 Harlan Agent Kit Agent assessment of head 15dbb8e.

The review queue had 11 Review or Repair tasks and 2 free host slots. The PR skill fallback stopped Service Review for this exact head before an independent review.

The independent review found no defects. It checked the complete diff, surrounding code, lock graph, compiler pins, and description diagram. It passed 39 asset and proxy tests. It verified Web responses, UTF-8 bytes, and 404 responses through Nuxt 4’s H3 HTTP adapter. Vimeo SDK exports match the component event types.

Assessment confidence: 90/100. Deductions: 5 for broad dependency changes; 5 for limited independent local coverage.

This assessment covers the original head above. Subsequent CI exposed a MapLibre 6.12 queue regression. Commit 06dc344a676792bbbcc0917692941d7998228da3 fixes it. All 21 real WebGL tests and all 1,205 unit, type, and runtime tests passed.

Harlan merged the repaired head as 2893f7104a719293af5864371840d4958a8ac70d. GitHub Actions passed on both the repaired PR head and the merged commit. The merged commit's Nightly build and package publish also passed.

CI on the merged commit.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: aa2559cb-d41c-44e0-b04a-9ca2ba3fd1a5
📥 Commits

Reviewing files that changed from the base of the PR and between 0041431 and 15dbb8e.

⛔ Files ignored due to path filters (2)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
  • test/packed/fixtures/nuxt-5/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (21)
  • .github/workflows/ci.yml
  • .nuxtrc
  • examples/cookie-consent/package.json
  • examples/custom-script/package.json
  • examples/granular-consent/package.json
  • examples/performance/package.json
  • examples/regional-consent/package.json
  • package.json
  • packages/script/package.json
  • packages/script/src/assets.ts
  • packages/script/src/runtime/components/ScriptVimeoPlayer.vue
  • pnpm-workspace.yaml
  • test/fixtures/basic/package.json
  • test/fixtures/first-party/package.json
  • test/packed/fixtures/nuxt-5/package.json
  • test/packed/fixtures/nuxt-5/pnpm-workspace.yaml
  • test/packed/verify.ts
  • test/unit/__mocks__/portable-server.ts
  • test/unit/proxy-handler-binary.test.ts
  • test/unit/proxy-handler-body.test.ts
  • test/unit/public-assets.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The changes update workspace and package dependency versions, including the H3 and Vimeo package contracts. The development script asset handler now returns Web Response objects. Vimeo component types now come from @vimeo/player. Unit tests update their request-body and streaming handling.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to 15dbb

The asset-handler change is compatible with the development server, and no merge-blocking issue was identified.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 6 files. (15 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the dependency updates and notes that TypeScript remains unchanged.
Description check ✅ Passed The description explains the dependency updates, related code and test changes, and migration steps covered by the pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 6 files. (15 skipped: 15 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

MapLibre 6.12 drops cluster requests while data waits in its worker queue. Apply the latest request after the data load settles, including failures.
@harlan-zw harlan-zw added the harlan-agent-review Approve automated work for the current issue state or pull request head commit. label Oct 6, 2026
@harlan-zw
harlan-zw merged commit 2893f71 into main Oct 6, 2026
19 of 20 checks passed
@harlan-zw
harlan-zw deleted the chore/dependency-updates-no-typescript branch October 6, 2026 11:41
@harlan-zw harlan-zw removed the harlan-agent-review Approve automated work for the current issue state or pull request head commit. label Oct 6, 2026

This branch was successfully deployed

1 active deployment
Preview — 06dc344a Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

harlan-agent-review-required Pull request triage requires an adversarial Review for this head commit.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant