Skip to content

Release: merge beta into main - #865

Open
rubenvdlinde wants to merge 20 commits into
mainfrom
beta
Open

Release: merge beta into main#865
rubenvdlinde wants to merge 20 commits into
mainfrom
beta

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

Stable promotion. Signing failures waived by explicit decision; being fixed separately.

github-actions Bot and others added 13 commits August 30, 2026 17:43
…260830174314

chore(sync): carry beta back into development
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…854)

Dependabot re-proposes these on every run, and each one takes `npm ci` or
`npm run build` from green to red with no code change in this repository that
can fix it. Closing the pull requests does nothing: without an ignore rule they
come straight back.

Each is blocked by a package we do not control, verified against the registry
rather than assumed:

- typescript 7      typescript-eslint hard-throws on TS >= 7 (a `versionMajor
                    >= 7` guard in its dist/index.js) and every published
                    version still peers `typescript: ">=4.8.4 <6.1.0"`.
- webpack-cli 7     @nextcloud/webpack-vue-config 7.0.4, the LATEST, peers
                    `webpack-cli: ^6.0.1`.
- @babel/core 8     the same package peers `@babel/core: ^7.22.9`.
- @babel/preset-env preset-env 8 requires core 8, so the pair moves together
                    or not at all. Splitting them is what broke filinq.

These are COMPATIBILITY limits, not security ones. `npm audit` reports no
advisory against any version pinned here, so holding them costs no exposure.
Lift each the moment its blocker ships support.

Deliberately NOT held: stylelint 17, vitest 4 and pinia 4. All three were
blocked earlier today and all three are now adoptable, so dependabot should
keep proposing them.
Release: merge development into beta
The 0.1.148 release bumped the version on main. Without this,
development stays behind main and the next development -> main promotion
conflicts on the version file.

Version files resolve to development's side, which is the higher line,
so this never moves a version backwards.
The 0.1.149-beta.20260830190846 release bumped the version on beta. Without this,
development stays behind beta and the next development -> beta promotion
conflicts on the version file.

Version files resolve to development's side, which is the higher line,
so this never moves a version backwards.
…91328

chore(sync): carry main back into beta
…260830191336

chore(sync): carry beta back into development
vue-router 5 peers `vite: ^7.3.0 || ^8.0.0` and expects a Vite toolchain. These
apps build with webpack, which cannot resolve it at all: the build dies on
`Can't resolve 'vue-router'` from src and from @nextcloud/vue's own chunks.
Adopting it is a Vite migration, not a version bump.

Dependabot proposed it across 8 repositories in a single run, and merging any
one of them takes that app's build from green to red with no code change that
can fix it.

versioniq already builds with Vite and is the natural pilot if the fleet does
move. Lift this when an app's toolchain can actually take it.
#869)

The comment claimed these apps "cannot resolve it at all". That is not what the
evidence shows, and a comment that overstates its case is worse than none: the
next person reads it, tries vue-router 5 somewhere it works, and stops trusting
the file.

Measured across four apps: integriq and zaakafhandelapp fail their build on
`Can't resolve 'vue-router'`, while openregister and learniq build clean on
5.3.0. The holdback still stands, for the honest reason rather than the
overstated one: a major that breaks some apps and not others cannot be merged
unattended, and the difference between them is not yet understood.

No behaviour change. The ignore rule is unchanged; only the reasoning is.
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/stackiq @ dfd26f8

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
check-vue-demi
test-l10n
format
check-schema-l10n
check-l10n-js
composer ✅ 130/130
npm ✅ 713/713
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman ⏭️
Playwright
Hydra gates

Quality workflow — 2026-08-30 23:49 UTC

Download the full PDF report from the workflow artifacts.

rubenvdlinde and others added 7 commits August 31, 2026 02:49
npm ci failed with ERESOLVE, so every frontend job failed before running
a single check.

Majors had landed WITHOUT the peers that must move with them. These
packages are a set: bumping one alone leaves another declaring a range
the new version cannot satisfy, and npm rejects the whole tree rather
than the single package. Fixing them one at a time simply walks the
list, because each correction exposes the next conflict underneath --
which is exactly what happened here before the whole set was taken
together.

Realigned: postcss-html=^1.8.1 node-polyfill-webpack-plugin=4.0.0 stylelint-config-html=^1.1.0

Verified: the lockfile resolves from a clean tree, where it previously
exited on ERESOLVE.
…876)

2.25.x makes the canonical KPI card flat and horizontal, so dashboards stop
drawing a grey box inside the white card CnWidgetWrapper already draws, and
2.25.1 fixes the narrow-tile step-down that 2.25.0 shipped inert (a source-order
bug left KPI values clipped on a three-column tile).

The caret range already allowed both; only the lockfile pinned this app back.
Lockfile only.
…1.149-beta.20260830190846

chore(release): sync beta back into development
…1.148

chore(release): sync main back into development
hydra-gates v1.10.0 -> v1.10.0
nc-vue      2.25.1 -> 2.26.0

Lock-only: both packages are already declared with caret ranges that
permit these versions, so nothing about what this app ACCEPTS changes
- only what it currently resolves to. Opened by the weekly fleet
shared-dependency bump, because a lock nobody re-resolves is a pin
nobody chose.

Merging is gated by this repository's own suite, deliberately: taking
hydra-gates v1.8.1 added patchObject() to a published interface, which
is a load-time fatal for any concrete double that implements it without
the method. CI is the only thing that can tell a safe bump from that.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Carries the two KPI-card fixes this dashboard reads: the canonical card is flat
and horizontal (no grey box inside the white card CnWidgetWrapper already
draws), and a calendar-aligned date range follows the reader's calendar rather
than UTC — "Current month" previously showed a To of 1 September in CEST on
31 August.

The caret range already allowed it; only the lockfile pinned this app back.
Lockfile only, and npm pruned nothing.
Release: merge development into beta
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/stackiq @ 09d0aff

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
check-vue-demi
test-l10n
format
check-schema-l10n
check-l10n-js
composer ✅ 130/130
npm ✅ 711/711
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman ⏭️
Playwright
Hydra gates

Quality workflow — 2026-08-31 11:03 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant