Tooling modernization: Node 22, husky v9, pnpm minimumReleaseAge, drop nyc - #1408
Merged
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Pull request overview
Modernizes project tooling by bumping the Node.js baseline to v22, migrating Git hooks to Husky v9, and removing the legacy nyc coverage stack in favor of Vitest coverage providers.
Changes:
- Bumped Node.js baseline (engines,
.nvmrc, and CI workflows) to Node 22 (with CI matrix covering 22 and 24). - Migrated from legacy Husky
package.jsonhooks to a tracked.husky/pre-commithook and updatedprepareto install Husky hooks. - Removed
nycconfiguration/dependency and addedpnpm.minimumReleaseAgefor supply-chain hardening.
Reviewed changes
Copilot reviewed 12 out of 14 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
test/e2e/README.md |
Removes redundant Node prerequisite from e2e docs. |
test/e2e/.nvmrc |
Removes local e2e Node pin in favor of root .nvmrc. |
README.md |
Updates contributor Node instructions to follow root .nvmrc. |
pnpm-lock.yaml |
Updates lockfile for Node/types bump and removal of nyc dependency tree. |
package.json |
Bumps engines/types, removes nyc, adds pnpm quarantine config, and updates Husky setup. |
config/.nycrc |
Deletes unused nyc config. |
.nvmrc |
Pins development Node major to v22. |
.husky/pre-commit |
Adds a pre-commit hook entry point for lint-staged (needs Husky header fix). |
.gitignore |
Removes stale /.nyc_output/ ignore and reorganizes editor/agent ignores. |
.github/workflows/tests.yml |
Updates CI node matrix to [22, 24] and normalizes YAML formatting. |
.github/workflows/npm_publish.yml |
Pins publish workflow to Node 22. |
.github/workflows/gh_pages.yaml |
Pins docs workflow to Node 22. |
.github/workflows/format.yml |
Pins formatting workflow to Node 22. |
.github/workflows/e2e.yml |
Pins e2e workflow to Node 22 and reformats steps/options. |
Files not reviewed (1)
- pnpm-lock.yaml: Language not supported
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Ryang-21
approved these changes
May 5, 2026
Merged
Ryang-21
added a commit
that referenced
this pull request
Jun 5, 2026
* [Modernization] Make fetch default (#1394) * Replace __USE_AXIOS__ dynamic require with static fetch default * Add babel and webpack aliasing to emit axios variant from shared source * Flip package.json exports: fetch default, /axios opt-in, drop /no-axios * Update eventsource and remove no-eventsource build (#1395) * update eventsource to v4.1.0 and remove conditional import of eventsource * remove the dom-monkeypatch as its now included in the tsconfig lib field * build and export cjs and esm build varients, remove export of umd bundles * Base Migration (#1399) * move stellar-base src under src/base * migrate from classic yarn to pnpm (#1400) * remove randomBytes for universal crypto.getRandomValues * replace sha.js with noble/hashes and update to version 2.2.0 * update BigNumber to v11.0.0 * replace noble/curves with noble/ed25519 for reduced bundle size * replace toml with smol-toml * replace URI for native URL (#1402) * refactor: replace URI usage for native URL + URLSearchParam objects * allow expandUriTemplate to handle relative templated links * Tooling modernization: Node 22, husky v9, pnpm minimumReleaseAge, drop nyc (#1408) * Update husky config + remove nyc * Root .nvmrc + bump Node to v22 * pnpm minimumReleaseAge config * Use pnpm workspace (#1417) * New docs (#1413) * TypeDoc setup * P27 updates (#1429) * Update XDR base URLs and improve Makefile for TypeScript definitions * pull and regenerate xdr definitions for p27 * handle signing the new SorobanCredential varients * add CAP-71 delegate-credential signing helpers - buildAuthorizationEntryPreimage: expose the signature payload (authorizeEntry now builds its preimage through it) - buildWithDelegatesEntry: wrap ADDRESS/ADDRESS_V2 into ADDRESS_WITH_DELEGATES, sorting + de-duping delegates; top-level signature defaults to Void - authorizeEntry: optional forAddress to fill a specific node (top-level or a delegate) instead of always the top-level - export the new helpers + DelegateSignature/BuildWithDelegatesParams from base * Update readme + pre-push check for docs (#1430) * Pre-push hook + updated docs * Update pre-push hook * Add @stellar/stellar-base migration guide to the installation docs * Map xdr.HashIdPreimage in typedoc to fix docs:reference build --------- Co-authored-by: oceans404 <[email protected]> * Tx builder type regression (#1438) * Implement TransactionSource interface for Account and MuxedAccount classes; update TransactionBuilder to use TransactionSource * TSDoc: Replace @internal with @ignore tag (#1436) * TSDoc: Replace @internal with @ignore tag * Add friendbot call builder items * Dependency updates (#1433) * Minor: axios + bignumber.js * Patch: vitest + @vitest * Minor astro + patch @astro * Minor: esbuild to v0.27.7 (not latest v0.28.0) * Some patch + minor * Major: @rollup/plugin-commonjs * Major: cross-env + dotenv * Major: jsdom * Updated pnpm-lock * Auth flag namespace (#1441) * add back AuthFlag namespace * fix: update build types script for axios to ensure generated types are copied correctly * P27 guide (#1440) * add p27 guide * docs: add task-oriented guides (connect-and-fund, send-a-payment) + internal-link tooling (#1434) * docs: add internal-link tooling (base-prefix rewriting + dead-link validation) * docs: add connect-and-fund and send-a-payment guides * docs: add issue-an-asset guide * docs: refine issue-an-asset guide (token framing, typed helper, review fixes) * docs: add query-and-stream guide * docs: add handle-errors guide * docs: link guides 02-04 to the handle-errors guide Add error-handling pointers now that guide 05 exists (sibling-link upgrade): a primary pointer in guide 02's submit section and lighter pointers in 03/04. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: add invoke-a-contract guide (06) Teaches invoking a deployed Soroban contract from JS with contract.Client and AssembledTransaction: connect over RPC, preview a call by simulation, then sign and send a state change. Uses the increment contract; deployment is linked out to the Stellar CLI tutorial. Regenerate llms bundles. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: add contract-auth guide (07) Covers signing Soroban contract authorization for an account other than the transaction source, framed for AddressV2 (CAP-0071-02) readiness: the same code is correct on the legacy ADDRESS credential today and on AddressV2 after the Protocol 28 flip. Distinguishes envelope signing from authorization-entry signing, and gives a before/after migration for hand-rolled signers (buildAuthorizationEntryPreimage / authorizeEntry). Also upgrades the Invoke a Contract guide's closing link to point at this guide, replaces numbered guide references with named links, and regenerates the llms bundles. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: fold versioning into the home page, drop it as a guide Versioning and compatibility is reference material, not a task how-to, so it moves out of the guides nav into a 'Versioning and compatibility' section on the home page (README -> index). Repoints the agents.md reference to the new home-page anchor and regenerates index.md + llms bundles. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: add migration guide (00) A versioned breaking-changes guide for upgrading to the v16 modernization release (base fold-in, native fetch, ESM, Node 22) and Protocol 27 / 28 Soroban auth (AddressV2). Modeled on viem's migration guide: one section per version, one entry per change, with before/after diffs. Sorts first in the guides nav and opens with a pointer to the home-page versioning section. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: link API references in migration guide (00) Link the first mention of each documented symbol (Keypair, the auth helpers, contract.Client/basicNodeSigner/signAuthEntries, rpc.Server/Horizon.Server, getLatestLedger, BalanceResponse, SigningCallback) to its reference page, base-agnostic, matching guide 07. Anchors verified against the rendered reference pages; internal link check passes. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> Co-authored-by: Ryan Yang <[email protected]> Co-authored-by: Iveta <[email protected]> * update package version to 16.0.0-rc.1 * fix: improve token formatting logic --------- Co-authored-by: Iveta <[email protected]> Co-authored-by: oceans404 <[email protected]> Co-authored-by: Steph <[email protected]> Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> Co-authored-by: Iveta <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Node 20 → 22 across the project — runtime bump: Bumped
engines.nodeto>=22.0.0, added a root.nvmrcpinningv22, updated@types/nodeto^22.19.17, switched thetests.ymlmatrix from[20, 22]to[22, 24], and pinned all single-version workflows (e2e.yml,format.yml,gh_pages.yaml,npm_publish.yml) to Node 22. Removedtest/e2e/.nvmrc(consolidated into the root file).Husky v4 → v9 — modern hook layout: Removed the legacy in-
package.jsonhusky.hooksblock (v4 syntax) and replaced it with a tracked.husky/pre-commitscript (pnpm exec lint-staged). Added&& huskyto thepreparescript sohuskyv9's hook runners (.husky/_/) get installed onpnpm install.Remove unused
nyccoverage stack — dead-code purge: Deleted thenycdevDep,_nycscript, top-levelnycconfig, andconfig/.nycrc. Coverage is already produced by@vitest/coverage-istanbul/@vitest/coverage-v8. Updatedclean/clean:bundle-sizeto drop.nyc_output/and removed the matching.gitignoreentry. Lockfile shrinks by ~480 lines as the transitivenyctree falls away.pnpm.minimumReleaseAge: 10080— supply-chain hardening: Added a 7-day quarantine on newly published package versions, mitigating short-window npm supply-chain attacks (malicious packages typically caught and yanked within days)..gitignorecleanup — reorganization: Grouped editor/agent dirs together (.vscode*,.idea/,.claude/,.copilot/,.codex/) and dropped the stale/.nyc_output/entry.README updates — match the new Node baseline: Root
README.md"Install Node 20" section now reads "Install Node" and points at.nvmrc(currently Node 22), withnvm install 20simplified tonvm installso it auto-reads the pin file. Removed the now-redundant Node prerequisite fromtest/e2e/README.md.