Skip to content

Tooling modernization: Node 22, husky v9, pnpm minimumReleaseAge, drop nyc - #1408

Merged
quietbits merged 4 commits into
modernizationfrom
modern-cleanup
May 5, 2026
Merged

Tooling modernization: Node 22, husky v9, pnpm minimumReleaseAge, drop nyc#1408
quietbits merged 4 commits into
modernizationfrom
modern-cleanup

Conversation

@quietbits

Copy link
Copy Markdown
Contributor
  • Node 20 → 22 across the project — runtime bump: Bumped engines.node to >=22.0.0, added a root .nvmrc pinning v22, updated @types/node to ^22.19.17, switched the tests.yml matrix from [20, 22] to [22, 24], and pinned all single-version workflows (e2e.yml, format.yml, gh_pages.yaml, npm_publish.yml) to Node 22. Removed test/e2e/.nvmrc (consolidated into the root file).

  • Husky v4 → v9 — modern hook layout: Removed the legacy in-package.json husky.hooks block (v4 syntax) and replaced it with a tracked .husky/pre-commit script (pnpm exec lint-staged). Added && husky to the prepare script so husky v9's hook runners (.husky/_/) get installed on pnpm install.

  • Remove unused nyc coverage stack — dead-code purge: Deleted the nyc devDep, _nyc script, top-level nyc config, and config/.nycrc. Coverage is already produced by @vitest/coverage-istanbul / @vitest/coverage-v8. Updated clean / clean:bundle-size to drop .nyc_output/ and removed the matching .gitignore entry. Lockfile shrinks by ~480 lines as the transitive nyc tree falls away.

  • pnpm.minimumReleaseAge: 10080 — supply-chain hardening: Added a 7-day quarantine on newly published package versions, mitigating short-window npm supply-chain attacks (malicious packages typically caught and yanked within days).

  • .gitignore cleanup — reorganization: Grouped editor/agent dirs together (.vscode*, .idea/, .claude/, .copilot/, .codex/) and dropped the stale /.nyc_output/ entry.

  • README updates — match the new Node baseline: Root README.md "Install Node 20" section now reads "Install Node" and points at .nvmrc (currently Node 22), with nvm install 20 simplified to nvm install so it auto-reads the pin file. Removed the now-redundant Node prerequisite from test/e2e/README.md.

@github-project-automation github-project-automation Bot moved this to Backlog (Not Ready) in DevX May 4, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​node@​25.5.0 ⏵ 22.19.17100 +110081 +194100

View full report

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Modernizes project tooling by bumping the Node.js baseline to v22, migrating Git hooks to Husky v9, and removing the legacy nyc coverage stack in favor of Vitest coverage providers.

Changes:

  • Bumped Node.js baseline (engines, .nvmrc, and CI workflows) to Node 22 (with CI matrix covering 22 and 24).
  • Migrated from legacy Husky package.json hooks to a tracked .husky/pre-commit hook and updated prepare to install Husky hooks.
  • Removed nyc configuration/dependency and added pnpm.minimumReleaseAge for supply-chain hardening.

Reviewed changes

Copilot reviewed 12 out of 14 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
test/e2e/README.md Removes redundant Node prerequisite from e2e docs.
test/e2e/.nvmrc Removes local e2e Node pin in favor of root .nvmrc.
README.md Updates contributor Node instructions to follow root .nvmrc.
pnpm-lock.yaml Updates lockfile for Node/types bump and removal of nyc dependency tree.
package.json Bumps engines/types, removes nyc, adds pnpm quarantine config, and updates Husky setup.
config/.nycrc Deletes unused nyc config.
.nvmrc Pins development Node major to v22.
.husky/pre-commit Adds a pre-commit hook entry point for lint-staged (needs Husky header fix).
.gitignore Removes stale /.nyc_output/ ignore and reorganizes editor/agent ignores.
.github/workflows/tests.yml Updates CI node matrix to [22, 24] and normalizes YAML formatting.
.github/workflows/npm_publish.yml Pins publish workflow to Node 22.
.github/workflows/gh_pages.yaml Pins docs workflow to Node 22.
.github/workflows/format.yml Pins formatting workflow to Node 22.
.github/workflows/e2e.yml Pins e2e workflow to Node 22 and reformats steps/options.
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .husky/pre-commit
@quietbits
quietbits merged commit 085fe94 into modernization May 5, 2026
10 checks passed
@quietbits
quietbits deleted the modern-cleanup branch May 5, 2026 17:03
@github-project-automation github-project-automation Bot moved this from Backlog (Not Ready) to Done in DevX May 5, 2026
@Ryang-21 Ryang-21 mentioned this pull request Jun 5, 2026
Ryang-21 added a commit that referenced this pull request Jun 5, 2026
* [Modernization] Make fetch default (#1394)

* Replace __USE_AXIOS__ dynamic require with static fetch default

* Add babel and webpack aliasing to emit axios variant from shared source

* Flip package.json exports: fetch default, /axios opt-in, drop /no-axios

* Update eventsource and remove no-eventsource build (#1395)

* update eventsource to v4.1.0 and remove conditional import of eventsource

* remove the dom-monkeypatch as its now included in the tsconfig lib field

* build and export cjs and esm build varients, remove export of umd bundles

* Base Migration (#1399)

* move stellar-base src under src/base

* migrate from classic yarn to pnpm (#1400)

* remove randomBytes for universal crypto.getRandomValues

* replace sha.js with noble/hashes and update to version 2.2.0

* update BigNumber to v11.0.0

* replace noble/curves with noble/ed25519 for reduced bundle size

* replace toml with smol-toml

* replace URI for native URL (#1402)

* refactor: replace URI usage for native URL + URLSearchParam objects

* allow expandUriTemplate to handle relative templated links

* Tooling modernization: Node 22, husky v9, pnpm minimumReleaseAge, drop nyc (#1408)

* Update husky config + remove nyc

* Root .nvmrc + bump Node to v22

* pnpm minimumReleaseAge config

* Use pnpm workspace (#1417)

* New docs (#1413)

* TypeDoc setup

* P27 updates (#1429)

* Update XDR base URLs and improve Makefile for TypeScript definitions

* pull and regenerate xdr definitions for p27

* handle signing the new SorobanCredential varients

* add CAP-71 delegate-credential signing helpers

  - buildAuthorizationEntryPreimage: expose the signature payload (authorizeEntry
    now builds its preimage through it)
  - buildWithDelegatesEntry: wrap ADDRESS/ADDRESS_V2 into ADDRESS_WITH_DELEGATES,
    sorting + de-duping delegates; top-level signature defaults to Void
  - authorizeEntry: optional forAddress to fill a specific node (top-level or a
    delegate) instead of always the top-level
  - export the new helpers + DelegateSignature/BuildWithDelegatesParams from base

* Update readme + pre-push check for docs (#1430)

* Pre-push hook + updated docs

* Update pre-push hook

* Add @stellar/stellar-base migration guide to the installation docs

* Map xdr.HashIdPreimage in typedoc to fix docs:reference build

---------

Co-authored-by: oceans404 <[email protected]>

* Tx builder type regression (#1438)

* Implement TransactionSource interface for Account and MuxedAccount classes; update TransactionBuilder to use TransactionSource

* TSDoc: Replace @internal with @ignore tag (#1436)

* TSDoc: Replace @internal with @ignore tag

* Add friendbot call builder items

* Dependency updates (#1433)

* Minor: axios + bignumber.js

* Patch: vitest + @vitest

* Minor astro + patch @astro

* Minor: esbuild to v0.27.7 (not latest v0.28.0)

* Some patch + minor

* Major: @rollup/plugin-commonjs

* Major: cross-env + dotenv

* Major: jsdom

* Updated pnpm-lock

* Auth flag namespace (#1441)

* add back AuthFlag namespace

* fix: update build types script for axios to ensure generated types are copied correctly

* P27 guide (#1440)

* add p27 guide

* docs: add task-oriented guides (connect-and-fund, send-a-payment) + internal-link tooling (#1434)

* docs: add internal-link tooling (base-prefix rewriting + dead-link validation)

* docs: add connect-and-fund and send-a-payment guides

* docs: add issue-an-asset guide

* docs: refine issue-an-asset guide (token framing, typed helper, review fixes)

* docs: add query-and-stream guide

* docs: add handle-errors guide

* docs: link guides 02-04 to the handle-errors guide

Add error-handling pointers now that guide 05 exists (sibling-link upgrade):
a primary pointer in guide 02's submit section and lighter pointers in 03/04.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: add invoke-a-contract guide (06)

Teaches invoking a deployed Soroban contract from JS with contract.Client and
AssembledTransaction: connect over RPC, preview a call by simulation, then sign
and send a state change. Uses the increment contract; deployment is linked out
to the Stellar CLI tutorial. Regenerate llms bundles.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: add contract-auth guide (07)

Covers signing Soroban contract authorization for an account other than the
transaction source, framed for AddressV2 (CAP-0071-02) readiness: the same code
is correct on the legacy ADDRESS credential today and on AddressV2 after the
Protocol 28 flip. Distinguishes envelope signing from authorization-entry
signing, and gives a before/after migration for hand-rolled signers
(buildAuthorizationEntryPreimage / authorizeEntry).

Also upgrades the Invoke a Contract guide's closing link to point at this guide,
replaces numbered guide references with named links, and regenerates the llms
bundles.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: fold versioning into the home page, drop it as a guide

Versioning and compatibility is reference material, not a task how-to, so it
moves out of the guides nav into a 'Versioning and compatibility' section on the
home page (README -> index). Repoints the agents.md reference to the new
home-page anchor and regenerates index.md + llms bundles.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: add migration guide (00)

A versioned breaking-changes guide for upgrading to the v16 modernization release (base fold-in, native fetch, ESM, Node 22) and Protocol 27 / 28 Soroban auth (AddressV2). Modeled on viem's migration guide: one section per version, one entry per change, with before/after diffs. Sorts first in the guides nav and opens with a pointer to the home-page versioning section.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: link API references in migration guide (00)

Link the first mention of each documented symbol (Keypair, the auth helpers, contract.Client/basicNodeSigner/signAuthEntries, rpc.Server/Horizon.Server, getLatestLedger, BalanceResponse, SigningCallback) to its reference page, base-agnostic, matching guide 07. Anchors verified against the rendered reference pages; internal link check passes.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Co-authored-by: Ryan Yang <[email protected]>
Co-authored-by: Iveta <[email protected]>

* update package version to 16.0.0-rc.1

* fix: improve token formatting logic

---------

Co-authored-by: Iveta <[email protected]>
Co-authored-by: oceans404 <[email protected]>
Co-authored-by: Steph <[email protected]>
Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Co-authored-by: Iveta <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants