Skip to content

chore: bump @types/node from 22.19.17 to 26.2.0 - #28

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/types/node-26.2.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/types/node-26.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @types/node from 22.19.17 to 26.2.0.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 11, 2026
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 22.19.17 to 26.2.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-26.2.0 branch from cb23b16 to 4b87548 Compare August 11, 2026 14:46
@claude

claude Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 3m 30s —— View job


Dependency review: @types/node 22.19.17 → 26.2.0

  • Read the PR diff
  • Check semver / major-version implications
  • Check how @types/node is used (tsconfig, engines, CI Node versions)
  • Verify build + tests
  • Post review

Verdict: safe to merge. One thing worth a deliberate decision (inline comment on package.json:43), no blockers.

What changed

Four majors, 22 → 26, plus a transitive undici-types 6.21 → 8.3. Both are dev-only and types-only — no runtime code ships from either. The lockfile also gained license/bin/engines on the root entry; that's npm re-normalizing metadata that was missing from the old lockfile, not something Dependabot introduced.

Risks I actually checked

1. Type/runtime skew — the only real finding. package.json:13 declares engines: node >=20 and ci.yml builds on Node 20, but the types now describe Node 26. Nothing in src/ uses a post-20 API (process.env, process.exit, and global fetch/FormData/Blob are the entire Node surface), so nothing breaks — but tsc stops being a guard against future use of a Node 21–26-only API, which would then fail at runtime on the minimum supported version. Details inline. Fix this →

2. undici-types 8.x is the highest-signal surface here. tsconfig.json sets no lib, so the global fetch/Response/RequestInit/Headers/FormData/Blob types all come from @types/node → undici-types. That is exactly what src/client/kosli-client.ts is built on (FetchFn = typeof globalThis.fetch at line 22, RequestInit at line 99, buildFormData at line 39, response.json() at lines 159/172). The await response.json() result is cast through as Record<string, string> at line 160, so a Promise<unknown> return signature is already handled. Build is green, so no tightening in v8 bit us.

3. TypeScript compat. typescript resolves to 5.9.3 in the lockfile — comfortably inside DefinitelyTyped's support window for @types/node 26. strict: true, NodeNext, and the .js-extension convention are untouched.

4. Verification. I could not npm install in this sandbox, so I did not run tsc/vitest locally. Relying on the PR's own CI run, which is green on Node 20 (build + tests + .mcpb smoke test).

Follow-up worth considering (pre-existing, not from this PR)

tsconfig.json has include: ["src"] and exclude: [..., "test"], so npm run build typechecks neither test/ nor scripts/, and vitest doesn't typecheck either. That matters specifically for a types bump: the FormData/Blob assertions in test/client/kosli-client.test.ts:211-256 and node:fs/node:url imports in scripts/generate-catalog.ts are outside the compiler's view, so a green CI proves less about a @types/node major than it looks like it does. A typecheck script over the whole repo (tsc --noEmit -p tsconfig.typecheck.json) would close that gap and make future @types/node bumps genuinely self-verifying. Fix this →
· dependabot/npm_and_yarn/types/node-26.2.0

Comment thread package.json
},
"devDependencies": {
"@types/node": "^22.0.0",
"@types/node": "^26.2.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Type/runtime skew worth a conscious decision: this package declares "engines": { "node": ">=20" } (line 13) and ci.yml builds on Node 20, but the type definitions now describe Node 26.

Nothing in src/ uses a post-20 API today (process.env, process.exit, and the global fetch/FormData/Blob), so this is not a breakage — but tsc will no longer reject a Node 21–26-only API if one gets added later, and it would fail at runtime on the minimum supported Node. The conventional fix is to keep @types/node at the lowest supported runtime major (^20) rather than the newest.

Either pin back to ^20 or raise engines to match — but don't leave the two four majors apart silently.

dangrondahl added a commit that referenced this pull request Aug 11, 2026
…rompts

claude-review.yaml still told the dependency reviewer that engines was
node >= 20 — the very instruction that produced the review on #28. Left
alone, the next @types/node major would be judged against a floor that no
longer exists. Rewritten to read the floor from package.json instead of
naming a version, so it can't drift again.

CI now runs a ['22','24'] matrix: 22 is the declared floor, 24 is what
release.yml publishes from, and previously only the floor was exercised
before a tag. fail-fast is off so one version failing still reports the
other.

CLAUDE.md gains the list of files that must move together when the floor
changes — the 'raise deliberately' instruction previously lived only in
dependabot.yml, which now goes silent by design.
@dependabot @github

dependabot Bot commented on behalf of github Aug 13, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/types/node-26.2.0 branch August 13, 2026 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants