Repository navigation
chore(deps): declare lodash and @remoteoss/json-schema-form explicitly - #1454
Merged
Merged
Conversation
src imports lodash/debounce and lodash/isNil, and the published types reference @remoteoss/json-schema-form through the form kit, but none of them were declared: they only resolved through yup and the kit. - @remoteoss/json-schema-form 1.2.18 in dependencies: the version the lockfile already resolves, so the runtime stays the same. The emitted .d.ts now import its types instead of inlining a copy. - lodash 4.18.1 and @types/lodash 4.17.25 in devDependencies: tsdown keeps inlining the two lodash helpers, so the JS output is unchanged and consumers don't get a new runtime import. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
📦 Bundle Size Report
Size Limits
Largest Files (Top 5)
View All Files (289 total)
✅ Bundle size check passed |
Contributor
|
Deploy preview for adp-cost-calculator ready!
Deployed with vercel-action |
Contributor
|
Deploy preview for remote-flows ready!
Deployed with vercel-action |
Contributor
📊 Coverage Report⚪ Coverage unchanged
Detailed BreakdownLines Coverage
Statements Coverage
Functions Coverage
Branches Coverage
✅ Coverage check passed |
gabrielseco
approved these changes
Oct 6, 2026
1 of 2 tasks
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The SDK used three packages it never declared:
lodash,@types/lodashand@remoteoss/json-schema-form. They only resolved because other dependencies happened to install them. This declares them, still on npm, with no change to the runtime code.Why
This is step 0 of moving the SDK root to pnpm (PBYR-4975). It's kept small and mergeable on its own, still on npm, so the migration PR only has to change the package manager.
npm hides the problem, pnpm doesn't. npm hoists every installed package into a flat
node_modules, so code can import a package it never declared as long as something else pulled it in. pnpm uses a strict layout: a package only sees what's in its ownpackage.json. Anything that only works through hoisting (a "phantom dependency") stops resolving.Three phantom dependencies exist today:
src/common/hooks.tsandsrc/lib/i18n.tsimportlodash/debounceandlodash/isNil.lodashonly resolves throughyup, and@types/lodashthrough the@types/lodash.*packages.@remoteoss/json-schema-form(ValidationResult,Field) through the form kit. Only the kit depended on it.What breaks under pnpm. The DTS build fails with TS2883 ("The inferred type of X cannot be named without a reference to ... This is likely not portable"). The type generator needs to write a reference to
@remoteoss/json-schema-form, but the SDK doesn't declare it, so it can't point to it from the SDK's ownnode_modules. Withoutlodashand@types/lodashdeclared, the build and type-check can't resolve them either.Why do it first, on npm. If the pnpm switch also had to add these dependencies, a failing build would be hard to tell apart from lockfile and tooling changes. Declaring them now on npm shows nothing else changes: the JS output is byte-identical to
main(see below), so the migration PR can be reviewed as a pure package-manager change.What changed
Toggle details
@remoteoss/json-schema-form1.2.18independencies.false. Pinning 1.2.18 keeps the runtime exactly as it is. A version bump can go through Renovate separately.dependencies, notdevDependencies, because the emitted.d.tsnow import its types (import("@remoteoss/json-schema-form").ValidationResult) where they used to inline a 50-line copy. Consumers already install it through the kit (^1.2.18, deduped to the same copy). Declaring it guarantees it resolves next to the SDK under any package manager.lodash4.18.1and@types/lodash4.17.25indevDependencies. These are the versions already resolved.dependencies, which is howdebounceandisNilship today. Independencies,lodashwould be externalized asimport "lodash/isNil". Node's ESM resolver rejects that path because it has no extension and lodash has noexportsmap (I checked:ERR_MODULE_NOT_FOUND). SodevDependencieskeeps the current output and doesn't risk breaking server-side consumers..d.ts, so@types/lodashstays dev-only, next to the other@types/lodash.*.main(both built in the same worktree): every.jsfile is byte-identical. Only the.d.tschange, as described above.npm lsshows one copy of each package.@remoteoss/json-schema-formdirectly instead of embedding its declarations. Not breaking.Screenshots
N/A
Related Resources
Testing
npm run ciis green (build, format, exports, lint, type-check, 1097 unit tests).npm run size:checkpasses, andexample/lint + type-check pass.E2E (
example/, all browsers): 21 passed, 6 failed. The 6 failures areonboard-basic-employeeandonboard-germany-employee("Preview Employment Agreement" instead of "Review"). They fail the same way on amainbuild with the local test company, so they don't come from this change.Tested against the
example/app in a browserFeature flag: N/A
🤖 Generated with Claude Code
Note
Low Risk
Dependency manifest and lockfile only; runtime JS unchanged and types remain equivalent, with json-schema-form pinned to avoid a 1.2.19 conditional-schema merge change.
Overview
Adds explicit package declarations for dependencies the SDK already used transitively, with no intended runtime behavior change.
@remoteoss/json-schema-form1.2.18 is added to dependencies so published.d.tscan reference its types (ValidationResult,Field) under strict layouts (e.g. pnpm) instead of relying on the form kit to hoist it. lodash and @types/lodash are added to devDependencies solodash/debounceandlodash/isNilresolve during build/type-check while keeping tsdown’s current inlining behavior (avoiding brokenimport "lodash/isNil"in emitted ESM).Lockfile updates mirror these pins; JS build output is expected to stay byte-identical to
main.Reviewed by Cursor Bugbot for commit db5572a. Bugbot is set up for automated code reviews on this repo. Configure here.