Modernize dependency toolchain and prune vulnerable packages - #182
Open
mswilkison wants to merge 2 commits into
Open
Modernize dependency toolchain and prune vulnerable packages#182mswilkison wants to merge 2 commits into
mswilkison wants to merge 2 commits into
Conversation
- drop consumer-facing engines block; published tarball no longer hard-fails installs for Yarn-1 downstream consumers on Node 20/24 (P1) - unify tsconfig lib across tsconfig.json/tsconfig.export.json so the typecheck CI gate is no more permissive than the ES5 publish compile (P2) - add tsconfig.json/tsconfig.export.json to npm.yml's publish-trigger paths filter, since prepack now depends on them (P2) - correct NODE_AUTH_TOKEN comment: it also covers npm-version-bump's registry read, not just the publish step (P2) - gate hardhat-gas-reporter v2 behind an opt-in env var to avoid pulling its network-capable client stack into every default test run (P2) - keep artifacts/ out of stale local publish state via the clean script (P3) - correct Tenderly shim comment's inaccurate extender count (P3)
piotr-roslaniec
approved these changes
Aug 12, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
yarn formatcheck disabled in7dc7cb0, and add a newtypecheckgate (TS had no prior type coverage)Security impact
The direct OpenZeppelin Solidity versions intentionally remain unchanged here. Updating them is not mechanical: newer Governor semantics require a separate design and test pass for
StakerGovernorauthorization behavior.Validation
yarn install --frozen-lockfileyarn formatyarn prepacknpm publish --dry-run --network=hardhatgit diff --check