chore: modernize, harden, and release the TypeScript stack - #320
Conversation
358a845 to
ff6c0c9
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
c6f8d16 to
c6b3491
Compare
c6b3491 to
4ecbcd7
Compare
|
Socket warning review (final dependency graph):
These are heuristic obfuscation warnings on current, expected build/test tools rather than vulnerability or install-script alerts. Both Socket checks pass. I am leaving the warnings visible rather than applying |
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
|



Outcome
Reconciles the public TypeScript stack onto one tested dependency, toolchain, correctness, and release baseline. Draft PR #306 remains excluded, and no Sonar organization setting is changed.
Highlights
Verification
Release and rollback
After merge, tag release/v2026-July-25 to publish only manifests ahead of npm through OIDC. Validate dist-tags, provenance, tarball imports, and then merge the generated version-sync PR. Rollback is package-specific npm deprecation/dist-tag correction; no workstation publication is used.
Closes #20
Closes #29
Closes #65
Closes #69
Closes #70
Closes #71
Closes #72
Closes #158
Closes #168
Closes #189
Closes #269
Closes #277
Closes #282
Closes #301