chore: bump @ts-bridge/cli to v0.6.4 and drop unused shims - #320
cryptodev-2s wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning MetaMask internal reviewing guidelines:
|
124f717 to
743cee8
Compare
c9e655d to
d0b303d
Compare
743cee8 to
361c13c
Compare
c9e655d to
d0b303d
Compare
d0b303d to
ffd8335
Compare
361c13c to
83f363a
Compare
ffd8335 to
50dbb76
Compare
83f363a to
710ff2e
Compare
50dbb76 to
e70e07f
Compare
710ff2e to
529d2d5
Compare
e70e07f to
29dd8bb
Compare
529d2d5 to
49c1eec
Compare
29dd8bb to
9c11b3e
Compare
49c1eec to
81ee668
Compare
|
We don't use |
9c11b3e to
325f083
Compare
81ee668 to
647a7d9
Compare
@ts-bridge/cli ^0.1.2 -> ^0.6.4
@ts-bridge/shims ^0.1.1 -> removed
This builds the published artifacts, so the output was diffed rather than
just checked for a zero exit. 216 files before and after, none added or
removed, and only two of them changed:
versions.mjs switches from a default import of semver plus destructuring
to direct named imports. semver is CJS, so this now leans on
Node's cjs-module-lexer resolving the names.
logging.mjs gains an $importDefault helper that honours __esModule when
importing debug, which is more correct than the old plain
default import.
The semver change is the risky one, and the test suite cannot catch it
because tests run against src/ through ts-jest, never against dist/. Both
entry points were therefore imported directly from the built output on Node
18, 20, 22 and 24, in ESM and CJS. All pass, so the named imports resolve
everywhere we support.
@ts-bridge/shims was never referenced by src/ or by the build output, and
core does not carry it. Removing it produces a byte identical dist/.
325f083 to
7c6f95b
Compare
647a7d9 to
a78473f
Compare
Top of stack #315, on #320. Last of the PR#2 bumps. | Dep | From | To | | --- | --- | --- | | `@ethereumjs/tx` | `^4.2.0` | `^5.4.0` | ## This is not breaking, but only because of a one word change The bump compiles with **no source change at all**, which is the trap. `@ethereumjs/tx@5` reuses the name `TxData` for something entirely different: ```ts // v4 interface TxData { nonce?, gasPrice?, gasLimit?, to?, value?, data?, v?, r?, s? } // v5 interface TxData { [TransactionType.Legacy]: LegacyTxData; [TransactionType.AccessListEIP2930]: AccessListEIP2930TxData; ... } ``` v4's meaning is now called `LegacyTxData`. `keyring.ts` declares `signTransaction` as returning `Promise<TxData>`, so bumping alone would silently change that public type from "a signed legacy transaction" into "an object carrying every transaction type at once", **and still build clean**. Typechecking a v4 era consumer against the unpatched build confirms it: ``` Type '{ nonce, gasPrice, gasLimit, to, value, data, v, r, s }' is missing the following properties from type 'TxData': [TransactionType.Legacy], [TransactionType.AccessListEIP2930], ... ``` Mapping `TxData` to `LegacyTxData` restores the original contract exactly, and that same consumer typechecks again. `TypedTxData` would also accept it, but it is a union, so callers would have to narrow the result. `LegacyTxData` keeps the API identical to v4. Note `Keyring` is already deprecated in favour of `@metamask/keyring-utils`, so the blast radius is small either way. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Touches transaction typing on a deprecated but public Keyring API; the explicit LegacyTxData fix avoids a silent type break, but downstream packages must align with @ethereumjs/tx v5. > > **Overview** > Upgrades **`@ethereumjs/tx`** from `^4.2.0` to **`^5.4.0`** (with transitive bumps to `@ethereumjs/common`, `util`, `rlp`, and related crypto packages in the lockfile). > > Because v5 redefines **`TxData`** as a per–transaction-type map instead of a single legacy field bag, the deprecated **`Keyring.signTransaction`** return type is updated from **`Promise<TxData>`** to **`Promise<LegacyTxData>`**, preserving the same runtime shape and v4-era TypeScript contract for consumers. No implementation changes are required for keyring authors. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 7d78cba. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
Top of stack #315, on #319.
@ts-bridge/cli^0.1.2^0.6.4@ts-bridge/shims^0.1.1Output diff
This builds the published artifacts, so
dist/was diffed rather than just checked for a zero exit. 216 files before and after, none added or removed, and only two changed:versions.mjsswitches from a default import plus destructuring to direct named imports:semveris CJS, so this now leans on Node'scjs-module-lexerresolving those names.logging.mjsgains an$importDefaulthelper honouring__esModulewhen importingdebug, which is more correct than the old plain default import.Why that needed checking by hand
The semver change cannot be caught by the test suite: tests run against
src/through ts-jest and never touchdist/. If the lexer failed to resolve a name, it would surface as a runtimeSyntaxErrorfor consumers, not a test failure.So both entry points were imported directly from the built output, in ESM and CJS, on every Node version we support:
Dropping shims
@ts-bridge/shimswas never referenced bysrc/or by the build output, and core does not carry it. Removing it produces a byte identicaldist/.Note
Medium Risk
Build-tool upgrade can change published
dist/ESM/CJS interop at runtime without failing existing unit tests.Overview
Upgrades the
ts-bridgebuild dev dependency from^0.1.2to^0.6.4and drops@ts-bridge/shims, which was not referenced by source or scripts. The lockfile picks up the new CLI stack (@ts-bridge/resolver,cjs-module-lexer) and dropsresolve.exports.The newer CLI emits slightly different
dist/interop for CommonJS dependencies (e.g. named imports fromsemver, safer default imports fordebugvia__esModule). That behavior is not exercised by Jest againstsrc/, so reviewers should treat a clean rebuild and smoke imports of built entry points as the main validation signal alongside this dependency bump.Reviewed by Cursor Bugbot for commit a78473f. Bugbot is set up for automated code reviews on this repo. Configure here.