Repository navigation
Refresh workspace and GitHub Actions dependencies - #170
Conversation
There was a problem hiding this comment.
Pull request overview
Refreshes dependency versions across the Exceptionless.JavaScript monorepo (core SDK packages plus example apps) to align on current compatible tooling, reduce known vulnerabilities via overrides, and keep the build/test toolchain consistent across workspaces.
Changes:
- Bumps
esbuildacross all SDK packages and updates rootallowScriptsaccordingly. - Updates framework/example dependencies (React, Vue, Vite, SvelteKit, Next.js, Expo/RN) and adds the missing
@testing-library/domdependency for the React example. - Adds root
overridesto pin@react-native-async-storage/async-storageand patch vulnerable transitive dependencies (cookie,postcss,uuid).
Reviewed changes
Copilot reviewed 14 out of 15 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| package.json | Updates shared dev deps (React/Vitest), updates allowScripts, and adds dependency overrides for security/compatibility pins. |
| packages/core/package.json | Bumps esbuild used for bundling core package outputs. |
| packages/browser/package.json | Bumps esbuild used for bundling browser package outputs. |
| packages/angularjs/package.json | Bumps esbuild used for bundling AngularJS wrapper outputs. |
| packages/node/package.json | Bumps esbuild and updates @types/node for Node package development/build. |
| packages/react/package.json | Updates React type dependencies and bumps esbuild for the React wrapper bundle. |
| packages/react-native/package.json | Pins AsyncStorage dev dependency for Expo/RN compatibility and updates React types. |
| packages/vue/package.json | Bumps esbuild used for bundling Vue wrapper outputs. |
| example/browser/package.json | Updates Vite for the browser sample app. |
| example/react/package.json | Updates React/Vite tooling and adds @testing-library/dom to satisfy testing-library peer requirements. |
| example/vue/package.json | Updates Vue/compiler and Vite for the Vue sample app. |
| example/svelte-kit/package.json | Updates SvelteKit/Svelte/Vite/Vitest versions for the SvelteKit sample app. |
| example/nextjs/package.json | Updates Next.js and aligns React versions for the Next.js sample app. |
| example/expo/package.json | Upgrades Expo SDK and React Native version while keeping Expo-pinned React and AsyncStorage versions. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 19e8d457aa
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Dependency/security recheck (2026-07-31)
Validation passed:
The samples successfully rendered and queued their log/error events. Submission failures were expected because the local Exceptionless backend at ports 7110/7111 was not running. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 92e79b4c52
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
bcd340e to
060ee6e
Compare
Refresh compatible SDK/sample dependencies, including Expo SDK 57 and Vitest 5. SDK source and APIs are unchanged.
build.ymlhas only five Action-version edits; the added scripts and ESLint changes are removed. Removed the unused browser-example Vitest project after its test was deleted, and reduced overrides from six to two without changing the lockfile.Validation: clean install, builds, lint, 346 tests, sample dogfooding, Expo exports, and SDK runtime audit passed. Updated-head Linux/macOS/Windows CI and CodeQL are green.
Merge gates: unpatched high-severity
braces/node-forgeadvisories in Expo tooling require risk acceptance or fixes. Expo Doctor remains 20/21 due to cooling-held patches. Backend delivery/native crash reporting are unverified. Human review is required.Verification and implementation details
ConsoleLog.ts, all other SDK source, andeslint.config.mjsmatch main. Removed the added publication/versioning scripts and their tests. GitHub Actions changes are only checkout v7, setup-node v7 (two uses), cache v6, and setup-dotnet v6.70d57c63) hosted proof: PR build, push build, and CodeQL passed. The workflow retains main's publication behavior; green job status is not a separate proof of registry delivery because main's CI publish step permits publication failures.npm ci,npm run build,npm run lint,npm test,npm run check --workspace=example/svelte-kit,npm audit,npm audit signatures, andosv-scanner scan --lockfile=package-lock.json. Runexpo install --check/expo-doctorfrom example/expo to see the unsuppressed cooling-window mismatch.