Skip to content

chore: prepare the first monorepo release on oclif 3 - #252

Merged
pviti merged 12 commits into
maint/oclif3from
chore/oclif3-release-prep
Oct 1, 2026
Merged

pviti merged 12 commits into
maint/oclif3from
chore/oclif3-release-prep

Conversation

@pviti

@pviti pviti commented Oct 1, 2026

Copy link
Copy Markdown
Member

Summary

Prepares the first release from the monorepo on oclif 3, on the maintenance branch maint/oclif3 = monorepo right before oclif 5 (30aff8a9, after #238). oclif 5, the Node 22.13 dependency update and SDK 8 come in a later major from monorepo.

Ported from monorepo (cherry-picked, -x)

Only on this branch

Not ported

oclif 5 (#239) and everything built on it: READMEs (#240), the @oclif/test 5 suites (#242 tests, integration #248/#249), the dependency update to Node 22.13 (#247), the provisioning fetch refactor (#243), SDK 8 (#250).

Expected release (dry run of release:version on this branch)

patch for most packages (cli 6.9.8, cli-core 5.11.5, cli-ux 1.2.5, …), minor for orders 5.7.0, provisioning 2.2.0, resources 6.19.0, triggers 4.20.0 (regenerated commands). No majors. check-manifest: no command, flag or argument removed against npm in any package.

The 589 imported stable tags and the cli-vX.Y.Z aliases of the CLI's vX.Y.Z tags are now pushed, so versions are derived from each package's last release.

After the release, maint/oclif3 is merged into monorepo, so its tags are ancestors of the oclif 5 major.

Test plan

  • pnpm build, pnpm lint, check-packages, pnpm install --frozen-lockfile, pnpm audit
  • All suites: 671 passing, the 2 failing locally need the CI credentials
  • check-manifest against npm for every oclif package
  • CI

🤖 Generated with Claude Code

pviti and others added 12 commits October 1, 2026 18:43
…ndents

A package released with unreleased changes in a workspace dependency
(cli-core, cli-ux, …) no longer needs that dependency released and
published first by hand:

- finish-version.mjs always adds the runtime workspace dependencies with
  unreleased changes to the release, even if they're skipped with
  --interactive, and orders the release dependencies first;
- publish.mjs publishes the dependencies not on npm yet before the package,
  from the same tree, provided their release tag exists (a version bumped
  outside the release flow still stops the publish). A package already on
  npm, published as someone's dependency, is skipped instead of failing;
- publish.yml tests the package with its workspace dependencies and marks
  the draft releases of the dependencies published along as published.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 56228ef)
…talized special folders

- output.cleanDate returned an empty string for ISO dates without
  milliseconds (2026-01-01T10:00:00Z)
- output.printCSV crashed on id/type columns when the flags had no
  fields (formatOutput with --csv only)
- util.specialFolder detected Desktop/Home case-insensitively but only
  replaced the lowercase name, so Desktop/file.json was left relative

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 0e2bdad)
jest and babel were only used by core and ux, with no tests. Both now
use mocha, chai and nock with tsx, as the rest of the monorepo, and the
jest and babel entries leave the catalog.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 15a67a9)
api, application, command, filter, jsonapi, output, schema, symbol,
text, token and util: 83 tests, API and auth calls mocked with nock.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit fbb77c2)
util, theme, list, styled object, tree and table (table/CSV/JSON/YAML
output, filter, sort, columns), logging and output levels, prompts and
confirmations with a fake stdin, and the oclif action: 47 tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 174f953)
… estimate

The negated check was missing, so the resource types of the model whose GETs
are not cacheable never made it into uncacheableTypes (shown by --debug and
used to pick the resource type of the uncacheable requests delay).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 9fb3ac6)
The first test of a suite loads oclif and transpiles the sources: about
1s on a CI runner, against mocha's 2s default. On a slow runner it timed
out (provisioning:create after the #243 merge), and the command left
running kept oclif's action buffering stdout, so the report and the
failing test's name were lost.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit fa65cff)
Pushes and pull requests made with the default GITHUB_TOKEN don't
trigger other workflows, so Verify never ran on the regeneration PR.
Check out and open the PR with COMMERCELAYER_CI_TOKEN.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit d67f480)
The shared generator (cf78981) replaced the resources script, but
prepack still ran 'pnpm resources': pnpm pack, and so publishing,
failed. The resource list is generated and committed (pnpm generate),
and CI checks that it is reproducible, so prepack doesn't need it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 93965ad)
A script calling a missing one only fails when it runs, and for prepack
that is at publish time. Found packing the packages for the prerelease.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 9979c1d)
… 3 line

Path-only fetch (#228) removes the resource argument, a breaking change
for check-manifest: it ships with the oclif 5 major instead. The fetch
suite, written for the path-only form, is skipped here.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… 0.28.1+

- cli-ux allowed js-yaml 3.15.1, affected by GHSA-2883-xcg3-v3hh
  (CVE-2026-84375, high), the Dependabot/Vanta alert: the range now
  starts at the fixed 3.15.2, same major, no code change.
- esbuild 0.28.1+ (GHSA-g7r4-m6w7-qqqr, low, dev only) through a pnpm
  override, as tsup pins ^0.27.

pnpm audit: no known vulnerabilities.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@pviti
pviti merged commit 111ec71 into maint/oclif3 Oct 1, 2026
4 checks passed
@pviti
pviti deleted the chore/oclif3-release-prep branch October 7, 2026 08:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant