Skip to content

fix(deps): lock vite to ^6 via overrides so git-dep installs resolve on npm 9 - #500

Open
jaieds wants to merge 5 commits into
stagingfrom
fix/ci-npm9-peer-resolution
Open

jaieds wants to merge 5 commits into
stagingfrom
fix/ci-npm9-peer-resolution

Conversation

@jaieds

@jaieds jaieds commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Every SureRank CI run since 2026-09-03 fails at npm install --force with:

npm ERR! git dep preparation failed
npm ERR! Cannot read properties of null (reading 'edgesOut')

Consumers install @bsf/force-ui as a git dependency (github:brainstormforce/force-ui#1.8.1). The release tag ships package.json with full devDependencies and build/postinstall scripts but no lockfile, so npm runs a nested npm install --include=dev --include=peer inside the cloned tag and re-resolves every devDependency from the registry on each run.

Trigger

vitest@5.0.0 was published on 2026-09-03 12:24 UTC. Nothing in force-ui or SureRank changed.

Two peer-resolution chains reach vite 8, whose @vitejs/devtools peer pulls @vitejs/devtools-vitest → vitest: "*" → now vitest@5.0.0. That conflicts with our vitest 4 and trips an arborist bug (loadPeerSet dereferences a detached node) present in npm 9.x and 10.0–10.3. npm 9.5.0 ships with Node 18.15, which SureRank CI pins.

  1. @storybook/react-vite ≥ 10.3.5 depends on @joshwooding/vite-plugin-react-docgen-typescript ^0.7.0, whose peer range allows vite up to ^8. Our ^10.3.3 range floated there.
  2. vitest 4 peers vite ^6 || ^7 || ^8, but we declared vite ^5.4.21, so arborist reached for vite 8 to satisfy it.

Only vite 8 declares the @vitejs/devtools peer; vite 5/6/7 do not.

Fix

  • overrides: { "vite": "^6.4.3" } — states the invariant once: no node in the tree may resolve vite ≥ 7. Both chains above are closed regardless of which storybook or vitest version floats in, and dependabot cannot silently undo it.
  • vite ^5.4.21 → ^6.4.3 — satisfies vitest 4's peer range natively. Vite 6 supports Node 18/20/22, matching our workflows (vite 7 needs Node ≥ 20.19; publish-public-build.yml runs Node 18).
  • @vitejs/plugin-react ^4.3.2 → ^4.3.4 — first release whose peer range includes vite 6.
  • package-lock.json regenerated from scratch. Removes three stale nested vite@8.0.2 subtrees, moves the vitest family 4.1.1 → 4.1.11 (clears 4 critical advisories: audit 40 → 15 findings, 0 critical). Storybook stays at 10.3.3 in the dev tree.
  • Version bumped to 1.8.2, changelog updated.

Verification

Scenario Result
Bare manifest, npm 9.5.0 (staging) ❌ edgesOut crash
Bare manifest, npm 9.5.0 (this PR) ✅ single vite node 6.4.3
Bare manifest, npm 10.3.0 (this PR) ✅
Real consumer install via git dep, npm 9.5.0 ✅ force-ui 1.8.2, Lexical patches applied
npm run build ✅ 375 files
npm run build-storybook ✅ 266 files
dist vs staging build JS, sourcemaps identical. tailwind.css differs by minifier whitespace (esbuild 0.21 → 0.25). force-ui.d.ts imports JSX from react instead of react/jsx-runtime (same types, @types/react 18.3.28 → 18.3.31)

Follow-up

After merge and the 1.8.2 tag, SureRank bumps its @bsf/force-ui ref to that tag.

…umers

Consumers installing force-ui as a git dependency on npm 9.x (Node 18.15)
fail with "Cannot read properties of null (reading 'edgesOut')" since
vitest 5.0.0 was published (2026-09-03). The release tag ships package.json
without a lockfile, so npm re-resolves all devDependencies on every install.

Two peer chains reached vite 8, whose @vitejs/devtools peer pulls in
vitest@* (now 5.0.0), which conflicts with our vitest 4 and trips an
arborist bug in npm 9:

- @storybook/react-vite >=10.3.5 -> @joshwooding/vite-plugin-react-docgen-typescript ^0.7 (peer vite up to ^8)
- vitest 4 peer vite ^6||^7||^8 while we declared vite ^5

Pinning the storybook family to the exact 10.3.3 already in the lockfile
keeps the docgen plugin at 0.6.x (peer vite <=6), and moving vite to ^6
satisfies vitest's peer range. Neither path can reach vite 8 anymore.

Verified: npm 9.5.0 resolves the tag package.json cleanly; npm run build
succeeds on vite 6.4.3.
@socket-security

socket-security Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Comment thread package-lock.json Outdated
Comment thread package.json Outdated
Comment thread package.json Outdated
Comment thread package.json
Comment thread changelog.txt Outdated
Comment thread changelog.txt Outdated
Comment thread package.json Outdated
Comment thread package.json Outdated
Comment thread package.json Outdated
Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package.json
Comment thread package-lock.json Outdated
Comment thread package.json
Address review on #500:

- Drop the nine exact storybook pins and express the real invariant once:
  `overrides: { vite: "^6.4.3" }`. No node in the tree can resolve vite 8,
  so the @vitejs/devtools -> vitest@* peer chain is unreachable regardless
  of which storybook version floats in. Survives dependabot bumps.
- Raise @vitejs/plugin-react floor to ^4.3.4, the first release whose peer
  range includes vite 6.
- Regenerate package-lock.json from scratch instead of patching in place.
  Removes the three stale nested vite@8.0.2 subtrees, moves the vitest
  family 4.1.1 -> 4.1.11 (clears 4 critical advisories), keeps storybook
  at 10.3.3.
- Add a consumer-install-check workflow that resolves the bare manifest on
  Node 18.15 / npm 9.5.0 without a lockfile, the path consumers hit and
  the one `npm ci` never exercises.
- Changelog: describe the override mechanism; disclose the tailwind.css
  minifier delta and the d.ts JSX import change from newer @types/react.

Verified: lockless resolution passes on npm 9.5.0 and 10.3.0; npm run
build and build-storybook pass; JS/sourcemaps byte-identical to the
previous build.
@jaieds jaieds changed the title fix(deps): pin storybook to 10.3.3 and move vite to ^6 for npm 9 consumers fix(deps): lock vite to ^6 via overrides so git-dep installs resolve on npm 9 Sep 8, 2026
@socket-security

socket-security Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.json → npm/@storybook/test-runner@0.24.5 → npm/@wordpress/eslint-plugin@20.3.0 → npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Not needed; the vite override in package.json already keeps the git-dep
install path stable. Removed per maintainer decision on #500.
@jaieds
jaieds requested a review from imnavanath September 8, 2026 14:32

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants