Skip to content

chore: modernize builds, releases, and workspace dependencies - #267

Draft
KevinVandy wants to merge 1 commit into
mainfrom
feat-modernize-pacer
Draft

KevinVandy wants to merge 1 commit into
mainfrom
feat-modernize-pacer

Conversation

@KevinVandy

@KevinVandy KevinVandy commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

🎯 Changes

Bring Pacer’s build and dependency setup in line with Table v9 and Hotkeys. Packages now target ES2022, require Node >=20, and ship ESM plus declarations from dist; CommonJS, source files, and source maps are excluded. Preserve all 98 export keys (88 code entry points plus package metadata), including devtools browser/server and production conditions.

  • Update workspace dependencies with ncu -u -ws --root -x typescript, keeping TypeScript 6.0.3. Upgrade pnpm to 12.6, tsdown to 0.23, Vitest to 5, Vite to 8.3.1, Angular to 22.2, React to 19.3, and devtools UI to 0.7.1. Use Preact Store 0.13.3 with the merged selector-cache fix.
  • Align local/CI tooling on Node 24.21.0. Keep runtime and tooling requirements separate, explicit ES2022 build targets, and the existing 10 kB size budget. Correct the stale build:core project and trailing build-script commands.
  • Run strict publint and actual-tarball checks for all ten packages in PR/release validation, following explicit declaration conditions for server exports.
  • Migrate Changesets CLI 3/action 2 with the renamed inputs, official GitHub changelog generator, and private-package exclusions. Add version preview and provenance checks; update SHA-pinned actions while retaining the shared setup revision used by Table/Hotkeys.
  • Replace removed Vitest assertion aliases without changing expectations. Update contributor/install documentation and regenerate API references with the latest typedoc config; trim whitespace in generated code fences.

The broad file count primarily comes from example manifests/TypeScript configs and regenerated reference docs. This changeset requests minor releases for all ten packages, including pacer-devtools 1.4.0 → 1.5.0.

Dependency policy exceptions are exact versions: Vite 8.3.1, Preact Store 0.13.3, and six Angular 22.2 tooling packages that were still within the 24-hour release window during installation. Retain the existing semver 6.3.1 trust exception; remove obsolete age exceptions.

Related open PRs: #226 overlaps the official changelog migration; #251 overlaps Changesets 3 but proposes a broader release workflow redesign that is not included here; #263 overlaps the assertion replacements required by Vitest 5; dependency upgrades also overlap #249. These PRs remain open for maintainers to reconcile.

Validation

  • Clean frozen install and pnpm test: 330 tasks across 169 projects pass, including package tests, types, lint, all framework example builds, and ten packed-artifact checks. Core is 7.09 kB / 10 kB.
  • pnpm test:pr, root TypeScript, script lint, formatting, docs generation/link checks (346 Markdown files), and git diff --check pass.
  • Installed tarballs in an external consumer with framework/devtools dependencies: 88 code entry points pass Bundler and NodeNext type checks with skipLibCheck: false. Core/lite subpath runtime imports pass on Node 20.0.0.
  • Isolated Changesets 3 version run produces ten minor releases/changelogs, no majors, and no private-example version changes.

GitHub CI passes on commit bcf2e9d5: Test, preview publication, version preview, Zizmor, code scanning, provenance, autofix, and Socket checks.

✅ Checklist

  • I have followed the steps in the Contributing guide.
  • I have tested this code locally with pnpm run test:pr.

🚀 Release Impact

  • This change affects published code, and I have generated a changeset.
  • This change is docs/CI/dev-only (no release).

@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Changeset Version Preview

10 package(s) bumped directly, 0 bumped as dependents.

🟨 Minor bumps

Package Version Reason
@tanstack/angular-pacer 0.24.0 → 0.25.0 Changeset
@tanstack/pacer 0.22.0 → 0.23.0 Changeset
@tanstack/pacer-devtools 1.4.0 → 1.5.0 Changeset
@tanstack/pacer-lite 0.2.2 → 0.3.0 Changeset
@tanstack/preact-pacer 0.23.0 → 0.24.0 Changeset
@tanstack/preact-pacer-devtools 0.7.0 → 0.8.0 Changeset
@tanstack/react-pacer 0.23.0 → 0.24.0 Changeset
@tanstack/react-pacer-devtools 0.8.0 → 0.9.0 Changeset
@tanstack/solid-pacer 0.22.0 → 0.23.0 Changeset
@tanstack/solid-pacer-devtools 0.7.0 → 0.8.0 Changeset

@nx-cloud

nx-cloud Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit bcf2e9d

Command Status Duration Result
nx run-many --targets=build --exclude=examples/** ✅ Succeeded 11s View ↗

☁️ Nx Cloud last updated this comment at 2026-09-24 21:05:17 UTC

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​size-limit/​preset-small-lib@​13.0.3 ⏵ 14.0.0991005291100
Updated@​tanstack/​typedoc-config@​0.3.3 ⏵ 0.3.489 +81006491 +7100
Updatedhappy-dom@​20.11.1 ⏵ 20.14.5661008895 +1100
Updatednx@​23.1.1 ⏵ 23.2.168 +1010093 +1100100
Updated@​tanstack/​preact-store@​0.13.2 ⏵ 0.13.381 +61006994 +2100
Updated@​tanstack/​react-query-devtools@​5.101.4 ⏵ 5.103.21001007098 +1100
Updated@​tanstack/​devtools-utils@​0.6.0 ⏵ 0.7.0100 +11007295100
Updated@​changesets/​cli@​2.31.1 ⏵ 3.0.399 +210074 -2595100
Updated@​angular/​platform-browser@​22.1.0 ⏵ 22.2.0100 +2310074 +198 +1100
Added@​types/​react-dom@​19.3.01001007592100
Updated@​tanstack/​devtools-ui@​0.6.0 ⏵ 0.7.1100 +11007596 +1100
Updated@​tanstack/​preact-devtools@​0.10.9 ⏵ 0.10.1376 +210091 +597100
Updated@​angular/​compiler-cli@​22.1.0 ⏵ 22.2.0100 +2010076 +198 +1100
Updated@​angular/​router@​22.1.0 ⏵ 22.2.0100 +2110077 +198100
Updated@​angular/​forms@​22.1.0 ⏵ 22.2.0100 +2110077 +198 +1100
Updated@​angular/​cli@​22.1.3 ⏵ 22.2.09010077 +198100
Updated@​angular/​build@​22.1.3 ⏵ 22.2.09210078 +198 +1100
Added@​angular/​compiler@​22.2.01001007898100
Added@​types/​react@​19.3.01001007993100
Added@​angular/​core@​22.2.01001007998100
Updated@​angular/​common@​22.1.1 ⏵ 22.2.0100 +110079 +198 +1100
Updatedvitest@​4.1.11 ⏵ 5.0.198 +110079 +198100
Updated@​faker-js/​faker@​10.5.0 ⏵ 10.6.010010010090 +280
Updated@​types/​node@​12.20.55 ⏵ 26.6.210010081 +296100
Updatedpublint@​0.3.23 ⏵ 0.3.24100 +110081 +193 +2100
Updatedsize-limit@​13.0.3 ⏵ 14.0.0100 +110082 +192 +1100
Updatedvite@​8.2.0 ⏵ 8.3.19810082 +196 -1100
Addedreact@​19.3.01001008497100
Addeddayjs@​1.11.2310010010086100
Updatedtsdown@​0.22.14 ⏵ 0.23.09810088 +196100
Updated@​tanstack/​solid-devtools@​0.8.9 ⏵ 0.8.1397 +2010090 +697100
Updated@​tanstack/​react-query@​5.101.4 ⏵ 5.103.299 +110091 +498100
See 11 more rows in the dashboard

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Publisher changed: npm @solid-primitives/trigger is now published by davedbase

Author: davedbase

From: pnpm-lock.yaml → npm/@tanstack/react-query-devtools@5.103.2 → npm/@solid-primitives/trigger@1.2.4

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@solid-primitives/trigger@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm @tanstack/preact-devtools

Location: Package overview

From: examples/preact/useQueuer/package.json → npm/@tanstack/preact-devtools@0.10.13

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tanstack/preact-devtools@0.10.13. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@pkg-pr-new

pkg-pr-new Bot commented Sep 24, 2026

Copy link
Copy Markdown
More templates

@tanstack/angular-pacer

npm i https://pkg.pr.new/@tanstack/angular-pacer@267

@tanstack/pacer

npm i https://pkg.pr.new/@tanstack/pacer@267

@tanstack/pacer-devtools

npm i https://pkg.pr.new/@tanstack/pacer-devtools@267

@tanstack/pacer-lite

npm i https://pkg.pr.new/@tanstack/pacer-lite@267

@tanstack/preact-pacer

npm i https://pkg.pr.new/@tanstack/preact-pacer@267

@tanstack/preact-pacer-devtools

npm i https://pkg.pr.new/@tanstack/preact-pacer-devtools@267

@tanstack/react-pacer

npm i https://pkg.pr.new/@tanstack/react-pacer@267

@tanstack/react-pacer-devtools

npm i https://pkg.pr.new/@tanstack/react-pacer-devtools@267

@tanstack/solid-pacer

npm i https://pkg.pr.new/@tanstack/solid-pacer@267

@tanstack/solid-pacer-devtools

npm i https://pkg.pr.new/@tanstack/solid-pacer-devtools@267

commit: bcf2e9d

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant