Skip to content

fix(form-core): bump devtools-event-client to 0.5.0 - #2410

Open
TiagoGranelli wants to merge 1 commit into
TanStack:mainfrom
TiagoGranelli:fix/form-core-event-client-production
Open

TiagoGranelli wants to merge 1 commit into
TanStack:mainfrom
TiagoGranelli:fix/form-core-event-client-production

Conversation

@TiagoGranelli

@TiagoGranelli TiagoGranelli commented Sep 27, 2026 •

Copy link
Copy Markdown

🎯 Changes

Bumps @tanstack/devtools-event-client in form-core from ^0.4.1 to ^0.5.0.

Since 0.5.0 (TanStack/devtools#471) the root EventClient export is a no-op unless NODE_ENV is development, and bundlers drop the real client. Pacer already made the same bump. On 0.4.x the first form emit fires tanstack-connect and starts a retry interval even with no devtools installed, which also keeps a Node SSR process alive for about 5s after rendering a form.

v2 alpha already removes the event client from form-core, so this is only for 1.x. One side effect: react-form-devtools/production won't get form events in production builds anymore, same as Pacer after its bump.

Added a test that mounts a form and checks nothing is sent to the devtools bus. It fails on 0.4.3. I also checked a minified production bundle of form-core (35.8 kB to 32.0 kB, no tanstack-connect left), and a Node script that mounts a form now exits right away instead of after ~5s.

Fixes #2132

✅ Checklist

  • I have followed the steps in the Contributing guide.
  • I have tested code changes locally with pnpm test:pr, or these tests do not apply to this pull request.
  • I fully understand the code in this pull request, including any code generated with AI assistance.

🚀 Release Impact

  • This change affects published code, and I have generated a changeset.
  • This change is docs/CI/dev-only (no release).

Summary by CodeRabbit

  • Bug Fixes
    • Form-core no longer connects to the TanStack Devtools event bus outside development. The event-bus connection remains available during development, while non-development environments no longer register the connection listener. No changes to the public form API are included.

The root EventClient export is a no-op outside development since 0.5.0,
so forms stop connecting to the devtools bus in production builds and SSR.

Fixes TanStack#2132
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​tanstack/​devtools-event-client@​0.5.01001009094100

View full report

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: TanStack/form/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 7f21a146-d0e9-4124-9678-c75844a9ef59

📥 Commits

Reviewing files that changed from the base of the PR and between 555509c and b80ec8d.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (3)
  • .changeset/quiet-forms-sleep.md
  • packages/form-core/package.json
  • packages/form-core/tests/EventClient.spec.ts

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

form-core updates its @tanstack/devtools-event-client dependency range to ^0.5.0. A new test mounts a form and checks that the tanstack-connect listener is not called. A patch changeset records the dependency update.

Changes

Form-core event client

Layer / File(s) Summary
Dependency update and connection-event test
packages/form-core/package.json, packages/form-core/tests/EventClient.spec.ts, .changeset/quiet-forms-sleep.md
The dependency range changes from ^0.4.1 to ^0.5.0. The test checks that mounting a form does not call the tanstack-connect listener. The changeset records a patch release.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to b80ec

The updated client does not start a connection retry outside development, and the dependency resolution matches the update. No issue identified here prevents merging after normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to b80ec

The change affects 1 system.

Changed systems: packages/form-core

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — packages/form-core (library) was modified; 2 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in packages/form-core/package.json: The @tanstack/devtools-event-client dependency range changes from ^0.4.1 to ^0.5.0.
  • observed — Modified behavior in packages/form-core/tests/EventClient.spec.ts: Adds a test that listens for tanstack-connect, mounts a form with an empty name default value, removes the listener, and expects it not to have been called.
  • observed — Modified behavior in .changeset/quiet-forms-sleep.md: Adds a patch changeset for @tanstack/form-core describing the @tanstack/devtools-event-client 0.5.0 bump and its stated effect on devtools event-bus connections outside development.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: updating the form-core devtools event client dependency to version 0.5.0.
Description check ✅ Passed The description explains the change, motivation, effects, testing, linked issue, checklist completion, and changeset release impact. It satisfies the required template sections.
Linked Issues check ✅ Passed Issue [#2132] requires removal of production devtools event-client activity from form-core. The PR upgrades @tanstack/devtools-event-client from ^0.4.1 to ^0.5.0. The reported 0.5.0 behavior m…
Out of Scope Changes check ✅ Passed The reviewed changes are limited to the dependency update, its changeset, and an automated regression test. These changes directly support issue [#2132]. No unrelated source, API, or feature changes a…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

@tanstack/devtools-event-client ships unconditionally in production bundles via form-core

1 participant