Feat/typescript 7 - #30
Conversation
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
jfa-dev-og-img-gen | e0f0109 | Jul 12 2026, 12:21 PM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
jfa-dev-landing | e0f0109 | Jul 12 2026, 12:21 PM |
|
Warning Review limit reached
Next review available in: 55 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. WalkthroughThe changes update repository dependency catalogs and root tooling to newer versions, switch the package manager to Bun 1.4.0, and disable the Bun minimum release age setting. Function and web package scripts now use 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@bunfig.toml`:
- Around line 1-2: Re-enable the Bun install configuration by uncommenting the
[install] section and minimumReleaseAge = 604800 in bunfig.toml, preserving the
seven-day package quarantine.
In `@package.json`:
- Around line 13-23: Align the root devDependencies entry for oxfmt with the
catalog version 0.56.0. Update only the oxfmt version so root and workspace
formatting use the same pinned dependency.
In `@web/og-img-gen/package.json`:
- Around line 9-16: Update the deploy script in web/og-img-gen/package.json to
invoke the existing check script via vp run check instead of separately running
vp typecheck and vp lint, while preserving the subsequent build and wrangler
deploy steps.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 53cdf3e3-00b3-47ab-8550-d28442e4ae65
⛔ Files ignored due to path filters (1)
bun.lockis excluded by!**/*.lock
📒 Files selected for processing (7)
bunfig.tomlfunction/redirects/package.jsonfunction/router/package.jsonpackage.jsonweb/landing/package.jsonweb/landing/src/routes/__root.tsxweb/og-img-gen/package.json
💤 Files with no reviewable changes (1)
- web/landing/src/routes/__root.tsx
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: CodeRabbit
- GitHub Check: Workers Builds: jfa-dev-og-img-gen
- GitHub Check: Workers Builds: jfa-dev-landing
⚠️ CI failures not shown inline (2)
GitHub Check: Workers Builds: jfa-dev-landing: Workers Builds: jfa-dev-landing
Conclusion: failure
Build ID: [a85a9838-0a1a-48e1-899a-6e58909230c8](https://dash.cloudflare.com/cb3d0c5cb46f4e801b0b7f4cc3fc78d3/workers/services/view/jfa-dev-landing/production/builds/a85a9838-0a1a-48e1-899a-6e58909230c8)
Script: [jfa-dev-landing](https://dash.cloudflare.com/cb3d0c5cb46f4e801b0b7f4cc3fc78d3/workers/services/view/jfa-dev-landing/production)
GitHub Check: Workers Builds: jfa-dev-og-img-gen: Workers Builds: jfa-dev-og-img-gen
Conclusion: failure
Build ID: [e436e039-92ee-4a57-84ea-52fb2e89d5c9](https://dash.cloudflare.com/cb3d0c5cb46f4e801b0b7f4cc3fc78d3/workers/services/view/jfa-dev-og-img-gen/production/builds/e436e039-92ee-4a57-84ea-52fb2e89d5c9)
Script: [jfa-dev-og-img-gen](https://dash.cloudflare.com/cb3d0c5cb46f4e801b0b7f4cc3fc78d3/workers/services/view/jfa-dev-og-img-gen/production)
🔇 Additional comments (9)
function/redirects/package.json (2)
20-21: Removal of@typescript/native-previewis consistent with thetsgo→tscmigration.The
typescriptdependency atcatalog:build(resolving to 7.0.2) providestsc. No orphaned references totsgoremain in this file.
7-12: 🩺 Stability & AvailabilityDrop the lint warning.
deployalready runsvp run check, andvp checkcovers linting, formatting, and typechecking.> Likely an incorrect or invalid review comment.function/router/package.json (2)
9-15: Script changes are consistent withfunction/redirects— good.Same
check→typecheck→vp checkchain, samedeploy→check→wrangler deploychain, sametsc --noEmitswitch. Consistency across function packages is exactly what you want.Same observation as redirects: no
lintin the deploy chain.
19-23: 🩺 Stability & AvailabilityNo issue:
vp fmtis already covered by the workspace root.function/routerdoesn’t need its ownoxfmtdevDependency, and the samevp fmtscript is used in the other workspace packages too.> Likely an incorrect or invalid review comment.web/og-img-gen/package.json (2)
29-29:nanoidbump from 5.1.11 to 5.1.16 — minor patch, low risk.
42-42: Removal of@typescript/native-previewis consistent.No
tsgoreferences remain.tsc --noEmitis the replacement, backed bytypescriptatcatalog:build.web/landing/package.json (2)
3-17: Version bump and script changes are consistent withweb/og-img-gen.Version
0.3.5, samecheck/deploy/typecheckscript patterns, sametsgo→tscmigration. Good consistency across web packages.Same deploy chain observation applies:
deploydoesn't reusevp run check, running its owntypecheck → lint → buildchain instead. This is consistent withog-img-genbut diverges from the function packages' approach.
40-41: Removal of@typescript/native-previewis consistent with all other packages.package.json (1)
11-51: This comment is off-target.packageManagerisbun@1.4.0-canary.1, notbun@1.4.0, and the workspace typecheck scripts already usetsc --noEmit.> Likely an incorrect or invalid review comment.
| # [install] | ||
| # minimumReleaseAge = 604800 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Disabling minimumReleaseAge removes a supply chain safety net.
minimumReleaseAge = 604800 enforced a 7-day quarantine for newly published packages. Commenting it out means Bun will happily install packages published seconds ago — including potentially compromised or buggy ones. Given this PR bumps a massive swath of dependencies to bleeding-edge versions, disabling this guardrail right now is the worst possible timing.
If the intent was to install versions younger than 7 days, re-enable this setting after the update lands. Leaving it disabled permanently is reckless.
🔒️ Proposed fix: re-enable after updates are applied
-# [install]
-# minimumReleaseAge = 604800
+[install]
+minimumReleaseAge = 604800📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| # [install] | |
| # minimumReleaseAge = 604800 | |
| [install] | |
| minimumReleaseAge = 604800 |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@bunfig.toml` around lines 1 - 2, Re-enable the Bun install configuration by
uncommenting the [install] section and minimumReleaseAge = 604800 in
bunfig.toml, preserving the seven-day package quarantine.
| "build": { | ||
| "@typescript/native-preview": "7.0.0-dev.20260610.1", | ||
| "@vitejs/plugin-react": "6.0.2", | ||
| "oxfmt": "0.54.0", | ||
| "@vitejs/plugin-react": "6.0.3", | ||
| "oxfmt": "0.56.0", | ||
| "oxlint": "1.57.0", | ||
| "oxlint-tsgolint": "0.18.1", | ||
| "typescript": "6.0.3", | ||
| "vite": "8.0.16", | ||
| "vite-plus": "0.1.24", | ||
| "typescript": "7.0.2", | ||
| "vite": "8.1.4", | ||
| "vite-plus": "0.2.4", | ||
| "vitest": "4.1.2", | ||
| "wrangler": "4.99.0" | ||
| "wrangler": "4.110.0" | ||
| }, |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
oxfmt version mismatch between catalog and root devDependencies.
The catalog pins oxfmt at 0.56.0 (line 15), but root devDependencies use 0.58.0 (line 72). Every other root devDependency matches its catalog counterpart exactly. This isn't intentional — it's a typo or a stale pin.
This means vp fmt will use different oxfmt versions depending on whether it runs from the root or a workspace context. You'll get inconsistent formatting across the monorepo and nobody will understand why.
🔧 Proposed fix: align root devDeps with catalog
- "oxfmt": "0.56.0",
+ "oxfmt": "0.58.0",Or alternatively, update the root devDependency to match the catalog:
- "oxfmt": "0.58.0",
+ "oxfmt": "0.56.0",📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| "build": { | |
| "@typescript/native-preview": "7.0.0-dev.20260610.1", | |
| "@vitejs/plugin-react": "6.0.2", | |
| "oxfmt": "0.54.0", | |
| "@vitejs/plugin-react": "6.0.3", | |
| "oxfmt": "0.56.0", | |
| "oxlint": "1.57.0", | |
| "oxlint-tsgolint": "0.18.1", | |
| "typescript": "6.0.3", | |
| "vite": "8.0.16", | |
| "vite-plus": "0.1.24", | |
| "typescript": "7.0.2", | |
| "vite": "8.1.4", | |
| "vite-plus": "0.2.4", | |
| "vitest": "4.1.2", | |
| "wrangler": "4.99.0" | |
| "wrangler": "4.110.0" | |
| }, | |
| "build": { | |
| "`@vitejs/plugin-react`": "6.0.3", | |
| "oxfmt": "0.58.0", | |
| "oxlint": "1.57.0", | |
| "oxlint-tsgolint": "0.18.1", | |
| "typescript": "7.0.2", | |
| "vite": "8.1.4", | |
| "vite-plus": "0.2.4", | |
| "vitest": "4.1.2", | |
| "wrangler": "4.110.0" | |
| }, |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@package.json` around lines 13 - 23, Align the root devDependencies entry for
oxfmt with the catalog version 0.56.0. Update only the oxfmt version so root and
workspace formatting use the same pinned dependency.
| "check": "vp run typecheck && vp check", | ||
| "deploy": "vp run typecheck && vp lint && vp build && wrangler deploy", | ||
| "dev": "vp dev --port 3000 --host", | ||
| "format": "vp fmt", | ||
| "lint": "vp lint", | ||
| "preview": "vp preview", | ||
| "serve": "vp preview", | ||
| "typecheck": "tsgo --noEmit" | ||
| "typecheck": "tsc --noEmit" |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Compare deploy chains across all packages
rg -n '"deploy"' --type=json -g '*package.json' -A1
# Investigate what vp check does vs vp lint + vp build
rg -n 'vp check' --type=json -g '*package.json' -B2 -A2Repository: jfalava/jfa.dev
Length of output: 153
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== package.json files =="
git ls-files '*package.json'
echo
echo "== deploy/check scripts across package.json files =="
python3 - <<'PY'
import json, pathlib
for p in sorted(pathlib.Path('.').rglob('package.json')):
try:
data = json.loads(p.read_text())
except Exception:
continue
scripts = data.get('scripts', {})
if any(k in scripts for k in ('deploy','check','lint','build','typecheck')):
print(f'-- {p}')
for k in ('check','deploy','lint','build','typecheck'):
if k in scripts:
print(f' {k}: {scripts[k]}')
PY
echo
echo "== any direct vp check references =="
rg -n --glob 'package.json' 'vp check|vp run check|vp run typecheck|wrangler deploy|vp lint|vp build' .
echo
echo "== files mentioning vp check outside package.json =="
rg -n 'vp check|vp run check' .Repository: jfalava/jfa.dev
Length of output: 2739
Use vp run check in deploy. web/og-img-gen skips vp check entirely here, so this path can drift from check and miss any validation added there. The function packages already gate deploys through check.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@web/og-img-gen/package.json` around lines 9 - 16, Update the deploy script in
web/og-img-gen/package.json to invoke the existing check script via vp run check
instead of separately running vp typecheck and vp lint, while preserving the
subsequent build and wrangler deploy steps.
Summary by CodeRabbit
Updates
Maintenance