Skip to content

chore(deps): declare lodash and @remoteoss/json-schema-form explicitly - #1454

Merged
jordividaller merged 1 commit into
mainfrom
chore/pbyr-4974-declare-phantom-dependencies
Oct 7, 2026
Merged

jordividaller merged 1 commit into
mainfrom
chore/pbyr-4974-declare-phantom-dependencies

Conversation

@jordividaller

@jordividaller jordividaller commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The SDK used three packages it never declared: lodash, @types/lodash and @remoteoss/json-schema-form. They only resolved because other dependencies happened to install them. This declares them, still on npm, with no change to the runtime code.

Why

This is step 0 of moving the SDK root to pnpm (PBYR-4975). It's kept small and mergeable on its own, still on npm, so the migration PR only has to change the package manager.

npm hides the problem, pnpm doesn't. npm hoists every installed package into a flat node_modules, so code can import a package it never declared as long as something else pulled it in. pnpm uses a strict layout: a package only sees what's in its own package.json. Anything that only works through hoisting (a "phantom dependency") stops resolving.

Three phantom dependencies exist today:

  • src/common/hooks.ts and src/lib/i18n.ts import lodash/debounce and lodash/isNil. lodash only resolves through yup, and @types/lodash through the @types/lodash.* packages.
  • The published types reference @remoteoss/json-schema-form (ValidationResult, Field) through the form kit. Only the kit depended on it.

What breaks under pnpm. The DTS build fails with TS2883 ("The inferred type of X cannot be named without a reference to ... This is likely not portable"). The type generator needs to write a reference to @remoteoss/json-schema-form, but the SDK doesn't declare it, so it can't point to it from the SDK's own node_modules. Without lodash and @types/lodash declared, the build and type-check can't resolve them either.

Why do it first, on npm. If the pnpm switch also had to add these dependencies, a failing build would be hard to tell apart from lockfile and tooling changes. Declaring them now on npm shows nothing else changes: the JS output is byte-identical to main (see below), so the migration PR can be reviewed as a pure package-manager change.

What changed

Toggle details
  • @remoteoss/json-schema-form 1.2.18 in dependencies.
    • The ticket said 1.2.19, but the lockfile resolves 1.2.18 today. 1.2.19 changes how conditional schemas get merged at runtime: it skips properties set to false. Pinning 1.2.18 keeps the runtime exactly as it is. A version bump can go through Renovate separately.
    • It has to be in dependencies, not devDependencies, because the emitted .d.ts now import its types (import("@remoteoss/json-schema-form").ValidationResult) where they used to inline a 50-line copy. Consumers already install it through the kit (^1.2.18, deduped to the same copy). Declaring it guarantees it resolves next to the SDK under any package manager.
  • lodash 4.18.1 and @types/lodash 4.17.25 in devDependencies. These are the versions already resolved.
    • tsdown inlines packages that aren't in dependencies, which is how debounce and isNil ship today. In dependencies, lodash would be externalized as import "lodash/isNil". Node's ESM resolver rejects that path because it has no extension and lodash has no exports map (I checked: ERR_MODULE_NOT_FOUND). So devDependencies keeps the current output and doesn't risk breaking server-side consumers.
    • No lodash type shows up in the emitted .d.ts, so @types/lodash stays dev-only, next to the other @types/lodash.*.
  • Build output compared with main (both built in the same worktree): every .js file is byte-identical. Only the .d.ts change, as described above. npm ls shows one copy of each package.
  • Public API: no change in shape. The exported types are the same, they now reference @remoteoss/json-schema-form directly instead of embedding its declarations. Not breaking.

Screenshots

N/A

Related Resources

  • PBYR-4974. Blocks PBYR-4975 (moving the SDK root to pnpm).

Testing

  • npm run ci is green (build, format, exports, lint, type-check, 1097 unit tests). npm run size:check passes, and example/ lint + type-check pass.

  • E2E (example/, all browsers): 21 passed, 6 failed. The 6 failures are onboard-basic-employee and onboard-germany-employee ("Preview Employment Agreement" instead of "Review"). They fail the same way on a main build with the local test company, so they don't come from this change.

  • Tested against the example/ app in a browser

  • Feature flag: N/A

🤖 Generated with Claude Code


Note

Low Risk
Dependency manifest and lockfile only; runtime JS unchanged and types remain equivalent, with json-schema-form pinned to avoid a 1.2.19 conditional-schema merge change.

Overview
Adds explicit package declarations for dependencies the SDK already used transitively, with no intended runtime behavior change.

@remoteoss/json-schema-form 1.2.18 is added to dependencies so published .d.ts can reference its types (ValidationResult, Field) under strict layouts (e.g. pnpm) instead of relying on the form kit to hoist it. lodash and @types/lodash are added to devDependencies so lodash/debounce and lodash/isNil resolve during build/type-check while keeping tsdown’s current inlining behavior (avoiding broken import "lodash/isNil" in emitted ESM).

Lockfile updates mirror these pins; JS build output is expected to stay byte-identical to main.

Reviewed by Cursor Bugbot for commit db5572a. Bugbot is set up for automated code reviews on this repo. Configure here.

src imports lodash/debounce and lodash/isNil, and the published types
reference @remoteoss/json-schema-form through the form kit, but none of
them were declared: they only resolved through yup and the kit.

- @remoteoss/json-schema-form 1.2.18 in dependencies: the version the
  lockfile already resolves, so the runtime stays the same. The emitted
  .d.ts now import its types instead of inlining a copy.
- lodash 4.18.1 and @types/lodash 4.17.25 in devDependencies: tsdown
  keeps inlining the two lodash helpers, so the JS output is unchanged
  and consumers don't get a new runtime import.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

📦 Bundle Size Report

Metric Current Previous Change Status
Total (gzip) 226.39 kB 226.39 kB 0 B (0%) 🟢
Total (raw) 632.02 kB 632.02 kB 0 B (0%) 🟢
CSS (gzip) 21.94 kB 21.94 kB 0 B (0%) 🟢
CSS (raw) 114.43 kB 114.43 kB 0 B (0%) 🟢

Size Limits

  • ✅ Total gzipped: 226.39 kB / 350 kB (64.7%)
  • ✅ Total raw: 632.02 kB / 850 kB (74.4%)
  • ✅ CSS gzipped: 21.94 kB / 25 kB (87.8%)

Largest Files (Top 5)

  1. index.esm-wIkXrqU6.js - 11.4 kB (0 B (0%))
  2. styles.css - 10.97 kB (0 B (0%))
  3. index.css - 10.97 kB (0 B (0%))
  4. internals-60vKS2gi.js - 6.14 kB (0 B (0%))
  5. hooks-AI3ANODo.js - 5.85 kB (0 B (0%))
View All Files (289 total)
File Size (gzip) Change
index.esm-wIkXrqU6.js 11.4 kB 0 B (0%)
styles.css 10.97 kB 0 B (0%)
index.css 10.97 kB 0 B (0%)
internals-60vKS2gi.js 6.14 kB 0 B (0%)
hooks-AI3ANODo.js 5.85 kB 0 B (0%)
index.js 5.52 kB 0 B (0%)
sdk.gen-hikpofx9.js 5.48 kB 0 B (0%)
flows/Onboarding/hooks.js 4.42 kB 0 B (0%)
utils-qfe-oQBs.js 4.07 kB 0 B (0%)
FieldSetField-Bds5UIuj.js 4.03 kB 0 B (0%)

✅ Bundle size check passed

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Deploy preview for adp-cost-calculator ready!

Project:adp-cost-calculator
Status: ✅  Deploy successful!
Preview URL:https://adp-cost-calculator-34hes4ujv-remotecom.vercel.app
Latest Commit:db5572a

Deployed with vercel-action

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Deploy preview for remote-flows ready!

Project:remote-flows
Status: ✅  Deploy successful!
Preview URL:https://remote-flows-am77dq8ab-remotecom.vercel.app
Latest Commit:db5572a

Deployed with vercel-action

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

📊 Coverage Report

⚪ Coverage unchanged

Metric Current Previous Change Status
Lines 86.82% 86.82% 0% ⚪
Statements 86.39% 86.39% 0% ⚪
Functions 85.42% 85.42% 0% ⚪
Branches 78.19% 78.19% 0% ⚪

Detailed Breakdown

Lines Coverage
  • Covered: 5006 / 5766
  • Coverage: 86.82%
  • Change: 0% (0 lines)
Statements Coverage
  • Covered: 5095 / 5898
  • Coverage: 86.39%
  • Change: 0% (0 statements)
Functions Coverage
  • Covered: 1330 / 1557
  • Coverage: 85.42%
  • Change: 0% (0 functions)
Branches Coverage
  • Covered: 3093 / 3956
  • Coverage: 78.19%
  • Change: 0% (0 branches)

✅ Coverage check passed

@jordividaller jordividaller self-assigned this Oct 6, 2026
@jordividaller
jordividaller merged commit 54e5329 into main Oct 7, 2026
16 checks passed
@jordividaller
jordividaller deleted the chore/pbyr-4974-declare-phantom-dependencies branch October 7, 2026 05:01
@jordividaller jordividaller mentioned this pull request Oct 7, 2026
1 of 2 tasks
@gabrielseco gabrielseco mentioned this pull request Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants