Skip to content

Lift tsup and tn-forms to clear 21 Dependabot alerts - #3

Merged
whusterj merged 2 commits into
mainfrom
fix/dependabot-tsup
Sep 9, 2026
Merged

whusterj merged 2 commits into
mainfrom
fix/dependabot-tsup

Conversation

@whusterj

@whusterj whusterj commented Sep 9, 2026

Copy link
Copy Markdown
Member

What This Does

Clears all 21 open Dependabot alerts. Every one was development scope, and they arrived through two separate chains.

The larger chain was not this repo's doing. The lockfile held @thinknimble/tn-forms@3.3.4, which declares babel-loader as a runtime dependency and therefore drags webpack, ajv, browserslist, serialize-javascript and terser into every install of this package. tn-forms@3.4.0 dropped babel-loader (along with install, another placeholder package), so moving the lock to 3.4.0 removes that branch entirely. That single change accounts for 16 of the 21 alerts.

The smaller chain is tsup's own: sucrase → glob → minimatch → brace-expansion, plus esbuild. Going from tsup 6.5.0 to 8.5.1 does not lift those far enough by itself, so four pnpm.overrides finish the job. Three of them sit comfortably inside their depender's range. The fourth does not: tsup 8.5.1 asks for esbuild ^0.27.0 and the patched version is 0.28.1, so that override deliberately steps outside. It is a low-severity dev-server advisory, and this package never starts a dev server, so I verified the override by comparing build output rather than by trusting the range.

The workflow file is new because this repo had no CI at all.

pnpm audit reports no known vulnerabilities.

Note for reviewers

There is no test suite here, so the build output is the evidence. dist/index.js and dist/index.mjs export the same two names as before, FormProvider and useTnForm, both still functions. The rest of the diff against the previous build is newer-esbuild formatting (if (x) return; collapsed onto one line) and one internal variable rename, tn_forms_react_exports to index_exports. The type declaration moves by exactly one line: ConvertToFieldTuple now carries the type modifier, which needs TypeScript 4.5 or later in a consumer.

The decision I did not make for you: peerDependencies still reads @thinknimble/tn-forms: >=3.3.3. A consumer who installs this package alongside tn-forms 3.3.4 still pulls the whole webpack tree into their own project, and their own Dependabot will say so. Raising that floor to >=3.4.0 would protect them, but it narrows the supported range for everyone, so it is your call rather than mine.

Two pre-existing problems I left alone. npx tsc --noEmit reports three errors in src/form-provider.tsx line 99 (Object.entries needs lib at es2017 or later, and two implicit any bindings). They are identical on main before this change, which is why the new workflow runs the build and not tsc. Also, tsup 8 now emits dist/index.d.mts next to index.d.ts; nothing references it, and it improves type resolution for ESM consumers.

All 21 alerts were dev scope, and they came from two chains.

The larger one was not this repo's doing. The lockfile held
@thinknimble/tn-forms 3.3.4, which declares babel-loader as a runtime
dependency and so drags webpack, ajv, browserslist, serialize-javascript
and terser into every install. tn-forms 3.4.0 dropped babel-loader, so
moving to it removes that whole branch. The peer range still accepts
3.3.3 and later, so a consumer is free to stay on an older version.

The smaller chain is tsup's own: sucrase to glob to minimatch to
brace-expansion, plus esbuild. tsup 6.5.0 to 8.5.1 does not move those
far enough on its own, so four pnpm overrides lift them.

- @thinknimble/tn-forms: 3.3.4 to 3.4.0
- tsup: 6.5.0 to 8.5.1
- Add pnpm overrides for glob, minimatch, brace-expansion and esbuild
- Add a GitHub Actions workflow, because the repo had no CI

`pnpm audit` reports no known vulnerabilities. The build output holds:
dist/index.js and dist/index.mjs export the same two names,
FormProvider and useTnForm, and the diff against the previous build is
esbuild formatting plus one internal variable rename. The type
declaration changes by one line, where ConvertToFieldTuple now carries
the `type` modifier.
pnpm/action-setup needs a version from either its own config or a
packageManager field in package.json. Neither was present, so the job
failed before it installed anything.
@whusterj
whusterj merged commit 6e02bab into main Sep 9, 2026
1 check passed
@whusterj
whusterj deleted the fix/dependabot-tsup branch September 9, 2026 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant