Skip to content

fix: declare one supported Node.js range, ^22.18.0 || ^24.11.0 || >=26.0.0 - #343

Open
wmadden-electric wants to merge 2 commits into
mainfrom
fix/node-range
Open

wmadden-electric wants to merge 2 commits into
mainfrom
fix/node-range

Conversation

@wmadden-electric

Copy link
Copy Markdown
Contributor
$ npm view prisma@next engines
{ node: '>=22.18.0' }
$ npm view create-prisma engines
{ node: '^22.18.0 || ^24.11.0 || >=26.0.0', bun: '>=1.3.0' }

The CLI accepts any Node from 22.18 up. create-prisma, and every project it generates, accepts a narrower range. After this PR the CLI declares the same range.

Decision

Every Prisma 8 tool supports one Node.js range: ^22.18.0 || ^24.11.0 || >=26.0.0. In prose: Node.js 22.18 or newer on the 22 line, 24.11 or newer on the 24 line, or 26 or newer.

Why one range

The packages, the docs and the generated projects disagreed. prisma and @prisma/cli declared >=22.18.0. @prisma/compute declared >=22.12.0. The repo README said "Node.js 24 or newer". create-prisma and its generated projects said ^22.18.0 || ^24.11.0 || >=26.0.0 (prisma/create-prisma#128). A user could not tell which Node to install.

The range covers the Node 22 line from 22.18, the Node 24 line from 24.11, and everything from 26.

It leaves out Node 24.0 to 24.10 because 24.11 is Node 24's first LTS release. Releases before it were the "Current" line, which we do not test.

What changes for users

  • Node 24.0 to 24.10 are now outside the declared range. What happens on install depends on the package manager:
    • npm and pnpm print a warning. pnpm fails instead when engine-strict is set.
    • Yarn 1 refuses to install a package whose engines does not match. A Yarn 1 user on one of these Node versions can no longer install prisma.
    • Bun and Yarn 2 or newer ignore engines.
  • Node 22.18 or newer on the 22 line, 24.11 or newer on the 24 line, and 26 or newer: nothing changes.
  • There is no runtime version check in the CLI, before or after this PR. The range is enforced only by the package manager.

Changes

  • engines.node is the range in prisma, @prisma/cli and @prisma/compute, and in the private @repo/cli-telemetry and @repo/cli-conformance.
  • The prisma and @prisma/cli READMEs state the range in prose.
  • The root package.json (contributors' Node) is ^24.11.0 || >=26.0.0. The repo README, CONTRIBUTING and onboarding guide say "Node.js 24.11 or newer on the 24 line, or 26 or newer". Contributors stay on Node 24 or newer because the startup-isolation test cannot run on Node 22.
  • New scripts/node-engines.test.mjs, run by pnpm test:scripts. It fails if any package with an engines field declares a different range, or if a package gains or loses an engines field.
  • @prisma/cli-engine keeps >=22.12.0 for now. Any change to its manifest needs a new engine version (scripts/check-engine-version.mjs). @prisma/composer-cli and @prisma/orm-toolchain peer the engine at exactly 0.7.0, so a new engine version would make the shell ship an engine they do not accept until both publish again. Users never install the engine on its own; it comes with prisma, which declares the narrower range. The test holds the engine's current value and fails when someone changes it, which reminds them to remove the exception.

Testing

  • pnpm typecheck, pnpm lint, pnpm test:scripts, the @prisma/cli-engine unit tests and the @repo/cli-conformance tests pass.
  • scripts/node-engines.test.mjs fails against main and passes on this branch.
  • tsdown derives its compile target from the lowest version engines.node allows. For prisma and @prisma/cli that stays Node 22.18. For @prisma/compute it moves from 22.12 to 22.18. I built prisma, @prisma/cli and @prisma/compute with the old and the new manifests, and the output is byte-for-byte identical.
  • node scripts/check-engine-version.mjs origin/main exits 0 with "Engine version 0.7.0 is consistent with this change set." Nothing under packages/cli-engine/ changes.

Alternatives considered

  • Keep >=22.18.0. That keeps accepting Node 24.0 to 24.10, which we do not test, and keeps the CLI out of step with the projects create-prisma generates.
  • Change the engine's range in this PR too and bump it to 0.8.0. That forces composer-cli and orm-toolchain to publish versions that peer 0.8.0 before the next prisma release can pass conformance, for a field users never see on the engine. The engine takes the range with its next real change instead.
  • Add a runtime Node version check to the CLI. npm already reports the mismatch at install time. A runtime check would also refuse users who saw the npm warning and chose to continue.

Agent: maui-32

prisma, @prisma/cli and @prisma/compute now declare the same engines.node range as create-prisma and the projects it generates. The package READMEs and contributor docs state it in prose. A scripts test fails if a package declares anything else.

@prisma/cli-engine keeps >=22.12.0 until its next real change: any change to its manifest needs a new engine version, which composer-cli and orm-toolchain must peer before the shell can ship it.

Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
…anifest

Reverts a comment edit in packages/cli-engine/tests, which counts as an engine change and fails check-engine-version. The engines test now skips folders under packages/ that have no package.json. CONTRIBUTING notes that @prisma/cli-engine keeps its own wider range until its next version.

Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 3d7c10e5-eb84-48c7-9414-7492b6c028dd

📥 Commits

Reviewing files that changed from the base of the PR and between 35cc595 and 451bd0a.


📒 Files selected for processing (12)
  • CONTRIBUTING.md
  • README.md
  • docs/onboarding/getting-started.md
  • package.json
  • packages/cli-conformance/package.json
  • packages/cli-telemetry/package.json
  • packages/cli/README.md
  • packages/cli/package.json
  • packages/compute/package.json
  • packages/prisma/README.md
  • packages/prisma/package.json
  • scripts/node-engines.test.mjs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



Summary by CodeRabbit

  • Compatibility

    • Published Prisma packages now support Node.js 22.18 or newer on the 22 line, 24.11 or newer on the 24 line, or 26 and newer. Node.js 23 and 25 are not included in the supported versions.
    • Repository development requires Node.js 24.11 or newer on the 24 line, or 26 and newer.
  • Documentation

    • Updated the setup guides and package documentation to reflect the Node.js requirements.

Walkthrough

The repository and package Node.js engine ranges now specify supported versions. Documentation reflects the updated requirements, and a new script test checks runtime package names and engine ranges.

Priority: ⬇️ Low

Merge Risk

Merge Risk: ⚪ Minimal · up to 451bd

The declared Node.js support ranges and contributor guidance are aligned; no actionable merge risk is evident.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 451bd

The change narrows installation compatibility without changing production entrypoints or privileges. The new test checks repository manifests; no material security risk introduced or worsened by this PR was identified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The supported exposure change is package installation eligibility and repository test validation, rather than expanded production authority. The reviewed manifest changes leave production entrypoints and dependency boundaries intact.

Trust Boundaries and Controls

  • observed — The new test consumes repository-owned manifests as JSON data and compares selected fields with constants. Its source contains no evaluation or subprocess sink and accepts no request-supplied path, credential, or identity input. This resolves the flagged test entrypoint without treating unknown production security coverage as safe.



🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check Passed The title clearly identifies the main change: standardizing the supported Node.js engine range. It is concise and related to the package and documentation updates.
Description check Passed The description directly explains the Node.js range changes, affected packages, documentation updates, exception for @prisma/cli-engine, testing, and user impact.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

✨ Simplify code
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

npx https://pkg.pr.new/@prisma/cli@343
npx https://pkg.pr.new/@prisma/cli-engine@343

commit: 451bd0a

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant