Skip to content

chore: update Start fixture dependencies - #1

Merged
tannerlinsley merged 1 commit into
mainfrom
chore/start-fixture-dependencies
Oct 1, 2026
Merged

tannerlinsley merged 1 commit into
mainfrom
chore/start-fixture-dependencies

Conversation

@tannerlinsley

@tannerlinsley tannerlinsley commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Update the Start fixture inputs to React Start 1.168.60 and React Router 1.170.41.

The root dependency graph, browser fixture generator, and eight install/site fixture lockfiles use the published patch versions. The four site fixture manifests and source hashes are refreshed from Router main at d35aab425b07b46e222a507c0f0239644669757b, retaining their declared portable substitutions.

The native npm conflict control now reads a small npm-generated lock fragment from the previous committed graph. This keeps the same conflict assertions when the current graph deduplicates Babel.

Validation: npm ci, browser Start fixture generation with 95 integrity-verified archives, all 45 source-check CI tests on Node 24, 32 installer/persistence tests, and eight fixture/provenance tests passed. Two unrelated WASM toolchain tests skipped because their tools are not installed. The complete SDK build is still unavailable in this clean checkout: its kernel-builtin preparation needs fixtures/workloads/node_modules/sql.js. Browser/native SDK acceptance was not run. This is a source fixture refresh, with no deployment or SDK release.

Summary by CodeRabbit

  • Updates

    • Starter templates and project setup now use newer TanStack Router and Start releases.
    • Starter templates include package aliases for TypeScript 6 and TypeScript 7.
  • Tests

    • Lockfile conflict coverage now uses a fixed npm lockfile fixture, keeping the nested dependency version checks unchanged.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: cb275d27-e88a-40d0-90f7-1b123dbacc71

📥 Commits

Reviewing files that changed from the base of the PR and between 0bda96f and 3fc0a34.

⛔ Files ignored due to path filters (9)
  • fixtures/install-start-portable/package-lock.json is excluded by !**/package-lock.json
  • fixtures/install-start-wasm/package-lock.json is excluded by !**/package-lock.json
  • fixtures/install-start/package-lock.json is excluded by !**/package-lock.json
  • fixtures/site-start-basic-portable/package-lock.json is excluded by !**/package-lock.json
  • fixtures/site-start-counter-portable/package-lock.json is excluded by !**/package-lock.json
  • fixtures/site-start-counter/package-lock.json is excluded by !**/package-lock.json
  • fixtures/site-start-streaming-data-from-server-functions-portable/package-lock.json is excluded by !**/package-lock.json
  • fixtures/start-vite8-wasm/package-lock.json is excluded by !**/package-lock.json
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (16)
  • fixtures/install-start-portable/package.json
  • fixtures/install-start-wasm/package.json
  • fixtures/install-start/package.json
  • fixtures/site-start-basic-portable/package.json
  • fixtures/site-start-basic-portable/provenance.json
  • fixtures/site-start-counter-portable/package.json
  • fixtures/site-start-counter-portable/provenance.json
  • fixtures/site-start-counter/package.json
  • fixtures/site-start-counter/provenance.json
  • fixtures/site-start-streaming-data-from-server-functions-portable/package.json
  • fixtures/site-start-streaming-data-from-server-functions-portable/provenance.json
  • fixtures/start-vite8-wasm/package.json
  • package.json
  • scripts/build-start-fixture.mjs
  • tests/fixtures/npm-lock-conflict.json
  • tests/project-install.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The repository and Start fixtures update TanStack Router and Start versions. Site-start fixtures change TypeScript aliases and provenance records. The npm lock-conflict test now reads package data from a dedicated fixture.

Changes

TanStack Start dependency updates

Layer / File(s) Summary
TanStack dependency versions
package.json, scripts/build-start-fixture.mjs, fixtures/install-start-*/package.json, fixtures/start-vite8-wasm/package.json, fixtures/site-start-*/package.json
Updates TanStack Router and Start dependency versions in the root manifest, fixture manifests, and fixture build script.
Site fixture TypeScript aliases and provenance
fixtures/site-start-basic-portable/*, fixtures/site-start-counter*/*, fixtures/site-start-streaming-data-from-server-functions-portable/*
Adds TypeScript 7 and TypeScript 6 aliases in site-start fixtures. Updates provenance hashes and, in two fixtures, records an empty devDependencies map.

npm lock-conflict test fixture

Layer / File(s) Summary
Lock-conflict fixture and test
tests/fixtures/npm-lock-conflict.json, tests/project-install.test.ts
Adds Babel package records to a lockfile fixture. The test reads that fixture instead of the repository lockfile; its nested-version assertions remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 3fc0a

The fixture refresh keeps the intended dependency versions and provenance, and the lock-conflict test retains its asserted cases. No concrete merge-blocking regression was found.

Architecture Summary

Architecture risk: 🔵 Low · up to 3fc0a

The change affects 4 systems.

Changed systems: scripts, fixtures, tests, package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — scripts (service) was modified; 1 changed file maps to changed impact.
  • observed — fixtures (service) was modified; 12 changed files map to changed impact.
  • observed — tests (service) was modified; 2 changed files map to changed impact.
  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in fixtures/install-start-portable/package.json: Updated the pinned versions of @tanstack/react-router and @tanstack/react-start to 1.170.41 and 1.168.60, respectively.
  • observed — Modified behavior in fixtures/install-start-wasm/package.json: Updated the pinned versions of @tanstack/react-router and @tanstack/react-start.
  • observed — Modified behavior in fixtures/install-start/package.json: Updates the pinned versions of @tanstack/react-router and @tanstack/react-start to 1.170.41 and 1.168.60, respectively.
  • observed — Modified behavior in fixtures/site-start-basic-portable/package.json: Updated the version ranges for @tanstack/react-router, @tanstack/react-router-devtools, and @tanstack/react-start.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: updating dependencies used by the Start fixtures.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​tanstack/​react-router@​1.170.15 ⏵ 1.170.4193 +110087 +498100
Updatednpm/​@​tanstack/​react-start@​1.168.57 ⏵ 1.168.60991008898100

View full report

@tannerlinsley
tannerlinsley merged commit 0be9a9e into main Oct 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant