Skip to content

Update project dependencies and CI tooling - #204

Merged
Dedac merged 3 commits into
mainfrom
dedac-update-project-packages
Sep 30, 2026
Merged

Dedac merged 3 commits into
mainfrom
dedac-update-project-packages

Conversation

@Dedac

@Dedac Dedac commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • Update direct and transitive npm dependencies and regenerate package-lock.json.
  • Migrate ESLint 9 to flat config via eslint.config.mjs.
  • Update Azure DevOps packages and switch Work Item Tracking imports to the supported exported path.
  • Upgrade GitHub Actions to actions/checkout@v7, actions/setup-node@v5, and CodeQL init/analyze @v4; retain Node 22.x.
  • Fix the unused catch binding exposed by the dependency/tooling updates.

Compatibility pins

  • React/ReactDOM and types remain on 16 for azure-devops-ui compatibility.
  • azure-devops-extension-sdk remains on 4 because extension-api v5 supports SDK 2–4.
  • ESLint remains on 9 because the current React plugin peer range does not support ESLint 10.
  • TypeScript remains on 5.9.3 because TypeScript 6.0.3 caused Azure DevOps UI declaration/CSS and stricter source errors; TypeScript 7 is outside the TypeScript-ESLint peer range.
  • TypeScript-ESLint remains on the latest stable 8.x release; 8.70.2 is prerelease-only.

Validation

  • npm ci — passed.
  • npm audit — passed; 0 vulnerabilities.
  • npx tsc --noEmit — passed.
  • npm run build — passed; production bundle and VSIX generated.
  • npm run build-dev — passed.
  • git diff --check — passed.
  • No test script exists in the repository.
  • Remaining lint findings are non-blocking and not regressed: clean HEAD produced 381 errors/23 warnings; the updated tree produces 293 errors/15 warnings.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 336317db-0945-4820-ae6a-7c2a231f1fc0

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The refreshed dependency tree omits rimraf, causing npm run clean to fail after a clean installation.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Modernizes dependencies, lint configuration, Azure DevOps imports, and CI tooling.

Changes:

  • Upgrades npm dependencies and regenerates the lockfile.
  • Migrates ESLint to flat configuration.
  • Updates Azure DevOps imports and GitHub Actions.
File Description
package.json Updates dependency versions.
package-lock.json Locks the refreshed dependency tree.
eslint.config.mjs Introduces ESLint 9 flat configuration.
src/​SelectorEvents.tsx Uses the supported Work Item Tracking export.
src/​RestServiceData.ts Updates imports and removes an unused catch binding.
src/​parameter-replacement.ts Updates the Work Item Tracking import.
src/​index.tsx Updates Work Item Tracking type imports.
.github/​workflows/​node.js.yml Upgrades CI actions and Node.js.
.github/​workflows/​codeql-analysis.yml Upgrades CodeQL and build tooling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 336317db-0945-4820-ae6a-7c2a231f1fc0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 336317db-0945-4820-ae6a-7c2a231f1fc0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants