Skip to content

AP-9905 # Changed update-dependents to publish intermediate packages - #38

Merged
divporter merged 7 commits into
mainfrom
AP-9905
Aug 4, 2026
Merged

divporter merged 7 commits into
mainfrom
AP-9905

Conversation

@mymattcarroll

@mymattcarroll mymattcarroll commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

Requester Checklist

Please only check the items that you have actioned. Do not check items that are not applicable to your PR.

Implementation

  • Have you tested your implementation locally?
  • If applicable, has an appropriate changelog entry been added? Do not include if you are fixing/changing something that is only in the current release.
  • There are no warnings that have been suppressed unnecessarily
  • Have automated tests been added, or have related ones been updated to cover the change?
  • Have all OneBlink dependency updates been completed (eg apps / apps-react / types etc).
  • Have you ensured this change does not add unwanted dependencies?
  • If this PR contains a refactor, have relevant Jira testing tasks added?
  • Changes that will knowingly make the feature/bug incomplete have been commented with TODO and a description of what needs to be done to finish the feature/bug
  • Any changes made to public APIs have been reflected in the documentation
  • Have you isolated business logic where possible to allow for unit testing?

Logging and Debugging

  • Are the error messages, if any, informative?
  • Are there enough log events and are they written in a way that allows for easy debugging?
  • "Debugging" code removed
  • Front-end: No erroneous Console.WriteLines

Readability

  • All class, variable, property and method modifiers are provided with the smallest scope possible
  • New files, variables and functions are descriptive/comprehensible and named consistently.
  • There is no dead code (unreachable code)
  • There is no usage of magic numbers
  • There is no commented out code.
  • In hard-to-understand areas, comments exist and describe rationale or reasons for decisions in code

Security

  • All personal data inputs are checked (for the correct type, length/size, format, and range).
  • No sensitive information is logged or visible in a stacktrace
  • Are authorization and authentication handled correctly?
  • Is (user) input validated, sanitized, and escaped to prevent security attacks such as cross-site scripting or SQL injection?
  • Is data retrieved from external APIs or libraries checked for security issues?
  • Do API endpoints return appropriate status codes

Reviewer Guide

  • It is important that you understand the purpose of the PR.
  • You are encouraged to engage with the requestor if you do not understand any of the proposed code changes/additions/deletions.
  • Do you, the reviewer, understand what the code does? Do you think a specific expert, like a security expert or a usability expert, should look over the code before it can be accepted?
  • Is a framework, API, library, or service used that should not be used? Are there alternatives you could recommend?
  • Are there existing hooks/components/functions in the same code base that could be utilised?
  • When reviewing tests, attempt to identify missing edge cases that may be relevant to the proposed implementation
  • Ensure you check for:
    • Security
    • Scalability
    • Performance
    • Maintainability

Note

High Risk
Automates cross-repo git operations, semver releases, and npm publish waits; the breaking --force contract can surprise existing scripts.

Overview
update-dependents is reworked to walk the product dependency graph: it scans clones, finds repos that need the released package, detects intermediate NPM packages other repos depend on, and can bump, commit, release, and poll npm for those intermediates (topologically ordered) before opening downstream PRs that can include every newly published version—not only the original dependency.

CLI: oneblink-release repository gains --update-dependents (post-tag npm wait + update-dependents). New flags --force-update-dependency, --force-publish-intermediate-dependency, and --ticket. --force on update-dependents is breaking: it now skips all prompts and requires --ticket (old “force bump only” behaviour is --force-update-dependency).

Supporting pieces: updateDependentsPlanning, waitForNpmPackageVersion, topologicallySortByPackageDependencies, Vitest tests, changelog; product-cognito-hosted-login-css removed from the product repository list.

Reviewed by Cursor Bugbot for commit 107e1f1. Bugbot is set up for automated code reviews on this repo. Configure here.

@mymattcarroll
mymattcarroll marked this pull request as draft August 3, 2026 23:55
Comment thread src/bin.ts
Comment thread src/startUpdateDependents.ts
@mymattcarroll
mymattcarroll marked this pull request as ready for review August 4, 2026 00:35

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 747d313. Configure here.

Comment thread src/startUpdateDependents.ts
Comment thread src/startUpdateDependents.ts
@mymattcarroll
mymattcarroll marked this pull request as draft August 4, 2026 01:09
Comment thread src/waitForNpmPackageVersion.ts Outdated
@mymattcarroll
mymattcarroll marked this pull request as ready for review August 4, 2026 01:46
@divporter
divporter merged commit 25f041c into main Aug 4, 2026
4 checks passed
@divporter
divporter deleted the AP-9905 branch August 4, 2026 01:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants