Repository navigation
Build: Deduplicate npm dependencies - #82698
Conversation
🤖 PR meta 🤖📦 Bundle sizeSize Change: +2.11 kB (+0.03%) Total Size: 8.1 MB 📦 View Changed
⚡ PerformanceShow the resultsClient side metrics exclude the server response time. front-end-block-theme
front-end-classic-theme
media-processing
media-upload
post-editor
site-editor
🏁 Flaky testsShow the failuresSome tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information. Navigates the items list via UP/DOWN arrow keys in
|
There was a problem hiding this comment.
Made this test more robust to reduce flakiness while testing deduped deps
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
18e9ddc to
f6d9eb3
Compare
f6d9eb3 to
ce3616e
Compare
|
For making deduplication an enforceable, automated task, would it be as simple as adding the dedupe commands somewhere in the static checks steps and trusting the "Check local changes" step to flag the drift? |
Deduping often results in version drifts which is difficult to handle when those drifts are more engaging - require test updates, type fixes etc. |
But the situations where deduplication would flag something would be one where someone is adding / updating a dependency and may be in the best position to address it at that point? |
Not always. Sometimes a totally unrelated transitive dependency gets drifted, and fixing its effects may be beyond the scope of the current PR. |
|
A better solution might be to run dedupe on a schedule and then create a PR from it, and the CI should catch any problematic drifts. |
ce3616e to
9737096
Compare
9737096 to
559f2d3
Compare
|
@manzoorwanijk @aduth I updated / rebased the PR to include the latest webpack release, which includes the bugfix we were waiting for. This PR is now ready for another round of review. |
manzoorwanijk
left a comment
There was a problem hiding this comment.
This looks good now.
Thank you for waiting for the release.
What?
Follow-up to #81017.
Deduplicates the full workspace dependency tree, removing 34 package entries and refreshing compatible transitive versions. Updates webpack to
^5.111.0and removes the temporary exact pin.Why?
This keeps the full-tree cleanup separate from narrower dependency PRs. Webpack 5.111.0 includes the fix for the production-bundle regression that required the pin.
How?
Regenerates the lockfile from current trunk with
npm dedupe. The three direct webpack declarations require the fixed release, including the published@wordpress/scriptsdependency. Its changelog records the update.Also refreshes webpack asset-hash snapshots, removes an obsolete Stylelint suppression, and makes the ConfirmDialog Enter-activation test independent of a brittle Tab sequence.
Testing Instructions
npm ci, thennpm run buildandnpm run storybook:build.npm run test:unit:vitestto exercise the deduped dependencies and webpack fixtures. Asset dependencies should remain unchanged; only generated hashes differ.@wordpress/scripts, runwp-scripts build --experimental-moduleswith botheditorScriptandviewScriptModuleentries. Both builds should succeed and emit the expected.asset.phpdependencies.Release-age guard
The dedupe command used temporary
--min-release-age-exclude=webpack --min-release-age-exclude=schema-utilsflags for the newly released packages. The repository's one-day guard is unchanged. Neither exception is needed after September 15 at 06:18:28 UTC.Testing Instructions for Keyboard
No UI changes. ConfirmDialog tests still verify Enter activation for both actions.
Use of AI Tools
Codex assisted with dependency auditing, implementation, verification, independent self-review, and PR text.