Upgrade to TypeScript ~6.0.3 #19

Merged
amoussa1229 merged 8 commits from feature/typescript-6-upgrade into main 2026-05-06 23:56:58 +00:00
amoussa1229 commented 2026-05-06 22:39:06 +00:00 (Migrated from github.com)

Summary

  • Bumps typescript from ~5.7.2 to ~6.0.3
  • Adds "types": ["node"] to tsconfig.json — required by TS 6 to resolve Node globals (path, __dirname)
  • Uses tilde pin since TS doesn't follow semver
  • @types/node stays at ^22.0.0 to match the Lambda NODEJS_22_X runtime
  • Lockfile regenerated with npm 11.14.0 to fix peer:true corruption (npm/cli#8690)

Supersedes Dependabot PRs #13 and #17.

Test plan

  • tsc --noEmit passes cleanly
  • cdk synth succeeds
## Summary - Bumps `typescript` from ~5.7.2 to ~6.0.3 - Adds `"types": ["node"]` to `tsconfig.json` — required by TS 6 to resolve Node globals (`path`, `__dirname`) - Uses tilde pin since TS doesn't follow semver - `@types/node` stays at `^22.0.0` to match the Lambda NODEJS_22_X runtime - Lockfile regenerated with npm 11.14.0 to fix peer:true corruption (npm/cli#8690) Supersedes Dependabot PRs #13 and #17. ## Test plan - [x] `tsc --noEmit` passes cleanly - [x] `cdk synth` succeeds
cursor[bot] commented 2026-05-06 22:39:12 +00:00 (Migrated from github.com)

PR Summary

Medium Risk
Upgrading to TypeScript 6 can surface new type-checking/build issues across the repo, and the workflow permission change (id-token: write) expands GitHub Actions token capabilities.

Overview
Upgrades the toolchain to TypeScript ~6.0.3 (with updated @types/node) and refreshes package-lock.json to match.

Updates tsconfig.json to explicitly include Node types via "types": ["node"] to ensure Node globals/modules resolve under TS6.

Extends the claude-review GitHub Actions workflow permissions by adding id-token: write.

Reviewed by Cursor Bugbot for commit 4d492f6b3e. Bugbot is set up for automated code reviews on this repo. Configure here.

## PR Summary <!-- CURSOR_SUMMARY --> **Medium Risk** Upgrading to TypeScript 6 can surface new type-checking/build issues across the repo, and the workflow permission change (`id-token: write`) expands GitHub Actions token capabilities. **Overview** Upgrades the toolchain to **TypeScript `~6.0.3`** (with updated `@types/node`) and refreshes `package-lock.json` to match. Updates `tsconfig.json` to explicitly include **Node types** via `"types": ["node"]` to ensure Node globals/modules resolve under TS6. Extends the `claude-review` GitHub Actions workflow permissions by adding `id-token: write`. <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 4d492f6b3ea63b2cfdabafc401a4b820f780bdcb. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
cursor[bot] (Migrated from github.com) reviewed 2026-05-06 22:45:54 +00:00
@ -14,11 +14,11 @@
"@aws-sdk/client-dynamodb": "^3.1030.0",
cursor[bot] (Migrated from github.com) commented 2026-05-06 22:45:54 +00:00

TypeScript version range changed from tilde to caret

Medium Severity

The typescript version specifier changed from ~5.7.2 (patch-only updates) to ^6.0.3 (minor + patch updates). TypeScript explicitly does not follow semantic versioning — minor releases like 6.1 or 6.2 can introduce breaking type-checking changes. The previous ~ prefix was the safer, intentional choice. Using ^ risks future npm install runs pulling in a TypeScript minor release that breaks the build with new type errors.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 6d9b874250. Configure here.

### TypeScript version range changed from tilde to caret **Medium Severity** <!-- DESCRIPTION START --> The `typescript` version specifier changed from `~5.7.2` (patch-only updates) to `^6.0.3` (minor + patch updates). TypeScript explicitly does not follow semantic versioning — minor releases like 6.1 or 6.2 can introduce breaking type-checking changes. The previous `~` prefix was the safer, intentional choice. Using `^` risks future `npm install` runs pulling in a TypeScript minor release that breaks the build with new type errors. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: 3aab6f02-d545-4dc0-9c30-6920bf1f93bc --> <!-- LOCATIONS START package.json#L20-L21 LOCATIONS END --> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OjJhNDU2OTMwLTMwZDktNGYxMC1hNjg5LWVkNTBhMTg1OGI1YiIsImVuY3J5cHRpb25LZXkiOiIzb3AtcnJJMnI5NDgzZm9TZDUzYmVtY2JQdTdzbGdsbGtNaWpQWTFodG5NIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QifSwiaWF0IjoxNzc4MTA3NTU0LCJleHAiOjE3ODA2OTk1NTR9.KEwZ-ODjZCs153GpuO_vZaYT_0kz2GUHJgTiE3-aZLSs3oAbI-rpbOrGykkj26O5ALr4U8SSqFEBUkw5p5T1Re5s34GqN2ONfJjfhHaS-Fkh4ILAYC8wfUyM8FRq7Ui2Eltn0xzwNVBG_jOwN7bK_OMw9tSabx7KEbsBnrAC5TIuyJddTvq4f_Fi6Zg-0erysqMA6yhhdwJ6kVfuIvbVvmONpJOwYKG9uZqCF3lnHlPgF3WZGVE1Tm_c7O2mPDECCKeT25tUd_uhjTzNqYWPdoTmdJOla1uFP7Ip21CmbPVrnycNJ3hY0wOs3xplogGLChbiD6JTjl6j1HtK5jnKLg" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OjJhNDU2OTMwLTMwZDktNGYxMC1hNjg5LWVkNTBhMTg1OGI1YiIsImVuY3J5cHRpb25LZXkiOiIzb3AtcnJJMnI5NDgzZm9TZDUzYmVtY2JQdTdzbGdsbGtNaWpQWTFodG5NIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QiLCJwck51bWJlciI6MTksImNvbW1pdFNoYSI6IjZkOWI4NzQyNTBhNTI4OTc5NmYwNTc4ODQ2YTU5YmUxN2E2NDUwOWMiLCJwcm92aWRlciI6ImdpdGh1YiJ9LCJpYXQiOjE3NzgxMDc1NTQsImV4cCI6MTc4MDY5OTU1NH0.MpTjg72CjqAN27Rb3vhENT2mE9NonmQau9J7adUxNbpjarGBAV9pJN1Ic0jMZ4eu9ovw4pvlmlMcfp2_ZOnrPaeZahcr9Ny2jcGziaLlocfhzZtMzW7rhoqkt7UuBmpKBkamF0S6nRtAfLBJ3w_I95kGcY0RQ00nVm2hrd7mj2iehrJSdQufzjGKm0YMsEw-5qTyLNcuyMfY7Cl_Lj4blJq7RoIKCshuqK2Qk1ilswCSfI2x0QdyhTHa4qwytcKV-BjoWRYCALbYDTOxTmJYjT7OIYmhP2i9lHPp4ByGD6qVjBKvWIQgQiOVAT-bB0tzqd0v4lRcxJP4Rg07kBGR1A" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 6d9b874250a5289796f0578846a59be17a64509c. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
cursor[bot] (Migrated from github.com) commented 2026-05-06 22:45:54 +00:00

Node type definitions don't match Node.js 22 runtime

Low Severity

@types/node was bumped from ^22.0.0 to ^25.6.0, but every Lambda function in the project uses NODEJS_22_X runtime and the Docker service uses node:22-slim. Previously the type definitions matched the runtime; now they describe Node.js 25 APIs that may not exist on the Node.js 22 runtime, creating a false sense of type safety and risking runtime errors if Node 25–only APIs are used.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 6d9b874250. Configure here.

### Node type definitions don't match Node.js 22 runtime **Low Severity** <!-- DESCRIPTION START --> `@types/node` was bumped from `^22.0.0` to `^25.6.0`, but every Lambda function in the project uses `NODEJS_22_X` runtime and the Docker service uses `node:22-slim`. Previously the type definitions matched the runtime; now they describe Node.js 25 APIs that may not exist on the Node.js 22 runtime, creating a false sense of type safety and risking runtime errors if Node 25–only APIs are used. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: ref1_e3eb794b-f9bf-4aca-b017-bd6b1b07d701 --> <!-- LOCATIONS START package.json#L16-L17 LOCATIONS END --> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90Ojg1ZjZkNDdmLWUzYWYtNDBhZS05ODA3LTM3NjIyNmNmMWZlNyIsImVuY3J5cHRpb25LZXkiOiJBMmpQMi00SllfUmx1dE5SdGRiZkRwZzQ1MGlkaWhNbTlNU3paRk0wOUNJIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QifSwiaWF0IjoxNzc4MTA3NTU0LCJleHAiOjE3ODA2OTk1NTR9.MLaN6UV0PbzdkwqclHy7jLI2YUzI3nIwP4rYfVruD6iNz7zP_0YSXYSG7qCf_PbifASR_dwJqmqjViBv6R1xk8fnffjHlw6kFLMAWQZTVzxOJO7vNV9y4cYlmHXWbRS2YdCIEdXD_yv3ZMQ_dVyk6BboY-DbdLlmcI1bI_VpjUO5Xy4twg4H1AHDn5zuGVxu4J_lAfMJlgBChkX5bOqEPrSQ025A7A-k74WcAdDDZTMjgTpFbbKYKp6ANQfaVt_BA-3u_fyyu_lZbBveIXLrsU8BjsXoDkIJlbvPt54gDsVEvup8j5gWVqPJTgI2UGPJ5Y6z4spW-JjG2CtaWsudyQ" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90Ojg1ZjZkNDdmLWUzYWYtNDBhZS05ODA3LTM3NjIyNmNmMWZlNyIsImVuY3J5cHRpb25LZXkiOiJBMmpQMi00SllfUmx1dE5SdGRiZkRwZzQ1MGlkaWhNbTlNU3paRk0wOUNJIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QiLCJwck51bWJlciI6MTksImNvbW1pdFNoYSI6IjZkOWI4NzQyNTBhNTI4OTc5NmYwNTc4ODQ2YTU5YmUxN2E2NDUwOWMiLCJwcm92aWRlciI6ImdpdGh1YiJ9LCJpYXQiOjE3NzgxMDc1NTQsImV4cCI6MTc4MDY5OTU1NH0.uSSji2DE3DbQTbQl2sxtzVotzp2iKTXRaPZj-GLuHGBjumEn5AKE7OaR8WPmslPpSA6ZSbNHSwOji879EupciJ9RZ39VL18UlierDuwFxVs89mWRMfsEgCMBqMK2ofYuyeEwrfjhRMs1u4hEc-27AFni3OH-9glKPkqB_xYSukUxoxG5Tr525PA39wTYiHpFXxFQGH4DeBsYrLyqUMzP0-O27GSYSlSdFBP1l5LwN18hcRLwxAvVS2AzppSOjdwX0SBTxj2G33-I-H3QLWApI272LGsZEG6Q_zRxLvX1fyS3niRMz2fJBdnRCGwN8CCSNqC9HEn6rAgszfqzSz7Ofg" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 6d9b874250a5289796f0578846a59be17a64509c. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
cursor[bot] (Migrated from github.com) reviewed 2026-05-06 23:10:49 +00:00
cursor[bot] (Migrated from github.com) commented 2026-05-06 23:10:49 +00:00

Lockfile corrupted: direct dependencies marked as peer-only

High Severity

Several direct dependencies now have "peer": true in the lockfile due to a known npm bug (npm/cli#8690). Notably, constructs and aws-cdk-lib are production dependencies in package.json but are marked peer-only in the lockfile — running npm ci --omit=peer would skip them entirely, breaking cdk synth and cdk deploy. The same issue affects typescript, @types/node, and @aws-sdk/client-dynamodb (devDeps gaining an extra peer: true flag). Regenerating the lockfile with npm ≥11.6.3 fixes this.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 3b84455692. Configure here.

### Lockfile corrupted: direct dependencies marked as peer-only **High Severity** <!-- DESCRIPTION START --> Several direct dependencies now have `"peer": true` in the lockfile due to a known npm bug (npm/cli#8690). Notably, `constructs` and `aws-cdk-lib` are production `dependencies` in `package.json` but are marked peer-only in the lockfile — running `npm ci --omit=peer` would skip them entirely, breaking `cdk synth` and `cdk deploy`. The same issue affects `typescript`, `@types/node`, and `@aws-sdk/client-dynamodb` (devDeps gaining an extra `peer: true` flag). Regenerating the lockfile with npm ≥11.6.3 fixes this. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: 9983e6d0-accf-47ed-ba0a-f5934827e016 --> <!-- LOCATIONS START package-lock.json#L2521-L2523 package-lock.json#L2144-L2145 package-lock.json#L2792-L2793 LOCATIONS END --> <details> <summary>Additional Locations (2)</summary> - [`package-lock.json#L2144-L2145`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/blob/3b84455692ef887eb1b48162635b7860fae95ec6/package-lock.json#L2144-L2145) - [`package-lock.json#L2792-L2793`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/blob/3b84455692ef887eb1b48162635b7860fae95ec6/package-lock.json#L2792-L2793) </details> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OjAzYTc0ZTVjLThiMDktNDhlMi1hOWY4LTY5YzBhNDZhZmY1NiIsImVuY3J5cHRpb25LZXkiOiI3cmhlZHo1SWdXZ21YZm5RdThjYWtNTmdoMHh2V3ZaYWkxaWxJMkpkZmRRIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QifSwiaWF0IjoxNzc4MTA5MDQ4LCJleHAiOjE3ODA3MDEwNDh9.LC1V332_UxFTTiQVmxY4rEXAY9m9KtKDCGXIPqDl8grOXCu77Eo0JCRIBZlI2LXg9X-7buaBvOWDkQxxfZBVaLrbHu6XG80bWbvWGUGr36ooJyvlGUdSRiB6vpLIiMg_rekLX6nCrpOxh9gZGrVXG0DDMJv-6C7eGK8EFPZT8PsdJpyaT5isRDo7t4JW9EvQ6bzhsnbGFLuRzW1lGd0qwfmlnrEXz8vFZ2A2qLE7YUvNafFVNpUU6878Wt5hE7ErlVad1J9eeGOxrFz8XYbH9UbIld44ZZqgR_ZpgWMFtaX22yMUyI24oqy1ZfQ-jAa7H4MpUnjrfEb6lqj1RwlAJQ" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OjAzYTc0ZTVjLThiMDktNDhlMi1hOWY4LTY5YzBhNDZhZmY1NiIsImVuY3J5cHRpb25LZXkiOiI3cmhlZHo1SWdXZ21YZm5RdThjYWtNTmdoMHh2V3ZaYWkxaWxJMkpkZmRRIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QiLCJwck51bWJlciI6MTksImNvbW1pdFNoYSI6IjNiODQ0NTU2OTJlZjg4N2ViMWI0ODE2MjYzNWI3ODYwZmFlOTVlYzYiLCJwcm92aWRlciI6ImdpdGh1YiJ9LCJpYXQiOjE3NzgxMDkwNDgsImV4cCI6MTc4MDcwMTA0OH0.lD8m-zLscRawHE00PUQCyseE4RMqKIVH_Ac3WccWs4zAvXQS6P_JB_LM5n6EwfOQWuiO5VH5V8mEzzVeMak4IaKNgDNDQvO8f7MAnRfV_XKTXugrQjTCxOdRxPVfGKZH_e5-PbuZ1xh9fId1ykEEBAkpI_KB1jvryFAMYF6VOPfldeVQsMCdHxbD0KmkXbZMKwfcQL__j-STM-PkfM-rDwmjjKhVjAPcek_ZejumkSYY3Rw6t05MBteq4eMWKfk9ZG2iJrB7O3z8KlEzEN7faXQLrNopzO5H_ErrFX8HBFNga5K8QJ5VMyYhS9Dh9gjqKQ9efLcsuVekW6Nqu32ATw" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 3b84455692ef887eb1b48162635b7860fae95ec6. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
@ -16,3 +16,3 @@
"@types/aws-lambda": "^8.10.149",
"@types/node": "^22.0.0",
"@types/node": "^22.19.17",
"aws-cdk": "^2.1120.0",
cursor[bot] (Migrated from github.com) commented 2026-05-06 23:10:49 +00:00

@types/node version specifier doesn't match intended upgrade

Low Severity

The PR title and description both state that @types/node is being bumped to 25.6.0, but the actual version specifier ^22.19.17 can only resolve within the 22.x range due to semver caret semantics. The lockfile confirms the resolved version is 22.19.17, not 25.6.0. If the intent was to upgrade to 25.x, the specifier needs to be ^25.6.0.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 3b84455692. Configure here.

### @types/node version specifier doesn't match intended upgrade **Low Severity** <!-- DESCRIPTION START --> The PR title and description both state that `@types/node` is being bumped to 25.6.0, but the actual version specifier `^22.19.17` can only resolve within the 22.x range due to semver caret semantics. The lockfile confirms the resolved version is 22.19.17, not 25.6.0. If the intent was to upgrade to 25.x, the specifier needs to be `^25.6.0`. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: ref1_52237570-441a-4c9d-bf37-deea0e519dc0 --> <!-- LOCATIONS START package.json#L16-L17 package-lock.json#L2069-L2070 LOCATIONS END --> <details> <summary>Additional Locations (1)</summary> - [`package-lock.json#L2069-L2070`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/blob/3b84455692ef887eb1b48162635b7860fae95ec6/package-lock.json#L2069-L2070) </details> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OmRjZjU0NDM5LWJjZDEtNGFlZi1iYmEyLWE4MjI0NGM0Y2U0YyIsImVuY3J5cHRpb25LZXkiOiJFYU1DY3ZmalVUbFhfaHZ1dnQxbWRnc01OQzlZTnMxQjZyOXctTGttUFAwIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QifSwiaWF0IjoxNzc4MTA5MDQ4LCJleHAiOjE3ODA3MDEwNDh9.mCGXUwz9Ma4YGy2NUY3q5VmcU4e6M_ugt4vILsSiXcJxxiNeRnYhnkAw0ba4Yf6ZTIybmIL2JpD-e8RStacXavkodr5McXEe_1BoWXKrIJrNi2SSCcID4rvJIdxpHL13eOAl0bjmtzpjOkv28jIM2C3aeU38rrOjcQVW1G0npf8SF0-mCsdNGdFB8bgxtHv4gaJ6z28RHAuzvI7HXbiomk6-4h7Le8yAzQUmDglPGgwjugtbiAO5jeNYqg5IBYvN-t9fHeNn7ffASUttnVnWTRPJeLXQpdCM4z3M7dmjWiB8-3XR3J1e8GFQoRHU3INsbxy9F8MVBWyNFD_Qste7Cg" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OmRjZjU0NDM5LWJjZDEtNGFlZi1iYmEyLWE4MjI0NGM0Y2U0YyIsImVuY3J5cHRpb25LZXkiOiJFYU1DY3ZmalVUbFhfaHZ1dnQxbWRnc01OQzlZTnMxQjZyOXctTGttUFAwIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QiLCJwck51bWJlciI6MTksImNvbW1pdFNoYSI6IjNiODQ0NTU2OTJlZjg4N2ViMWI0ODE2MjYzNWI3ODYwZmFlOTVlYzYiLCJwcm92aWRlciI6ImdpdGh1YiJ9LCJpYXQiOjE3NzgxMDkwNDgsImV4cCI6MTc4MDcwMTA0OH0.X_7vxHMGTjsH8pJeTHwgiI7NczPWpxMOuLpW6wu15tqfR-m6OzYCYxzkpbHwSXT57t65rrHkC35pYLpkrY6A2L6oI82YYXYCAzKmn7kxW7hHeumO-kO5zCBwZbENe3WjGbU6gRShrpygchBY_ol-AgnbLl2GFEGJRDKJ4YG7_BF2iA2EeViArq1kM2EN3IN1VoySxva2joUvvbP3utqTmFTqQSUEgw41P266ARnQqS5cmlAg9znXIKdUQAnvM8drVoYwJDrFQfGx29uWmn9WQu6iMOOVPfyGMUNdiXUyVromU5XOUJjOykrNu1wdNOpQJhkIQcwVW6-FzBkfedgoRA" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 3b84455692ef887eb1b48162635b7860fae95ec6. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
amoussa1229 commented 2026-05-06 23:26:31 +00:00 (Migrated from github.com)

@cursor review

@cursor review
cursor[bot] (Migrated from github.com) reviewed 2026-05-06 23:28:02 +00:00
cursor[bot] (Migrated from github.com) left a comment

✅ Bugbot reviewed your changes and found no new issues!

1 issue from previous review remains unresolved.

Fix All in Cursor

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 9d7182b3bc. Configure here.

<!-- BUGBOT_REVIEW --> ✅ Bugbot reviewed your changes and found no new issues! 1 issue from previous review remains unresolved. <!-- BUGBOT_FIX_ALL --> <a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9BTExfSU5fQ1VSU09SIiwiZGF0YSI6eyJyZWRpc0tleSI6ImJ1Z2JvdC1tdWx0aTo5YTYxMzU2YS1hYTE3LTQ5YWMtOTcyMy0yNzE0MTIyMzQ5OTEiLCJlbmNyeXB0aW9uS2V5IjoiV3lVWFMwcEQ3b2w1YzZSV3dIN2loMnRUXzF2d1EyeC1DcnJ2aVN2TFJpbyIsImJyYW5jaCI6ImZlYXR1cmUvdHlwZXNjcmlwdC02LXVwZ3JhZGUiLCJyZXBvT3duZXIiOiJTZWEtSGF2ZW4tSW5kdXN0cmllcyIsInJlcG9OYW1lIjoic2VhaGF2ZW4tc2xhY2stYm90In0sImlhdCI6MTc3ODExMDA4MiwiZXhwIjoxNzgwNzAyMDgyfQ.Ib9CdX_HscYosQyIlj56umC9v-ebNA--Yl5eAQg65hcYgUgLx3Z1neQrZ2uIpg8iWLIAXqbw_hauVuzOhBuGNckB4u_mnXa0VGNQxIjfBYr9h9691PIk-6CbGQfWhm0ndjSToHOf8mkATFMgeuCE0dHaNfjWxsTKCA85R_bvQeqWWdBfnetKnYo2IZ8koB1M7KSLEwquOFiU1UllObxcbGeMsNRfQPwHobLShXsEr3evD6jTI3bgQfMIjFuHh57n_HAijCytFfjG_swAhtMcpAZa6G2iiYmS1hppT9-iey-WNKYYZvfXof3S5WhFfuuL296P9d12U3bSvjoQbIg0lw" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix All in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a> <!-- /BUGBOT_FIX_ALL --> _Comment `@cursor review` or `bugbot run` to trigger another review on this PR_ <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 9d7182b3bca2abae95272124893844e81f9e62c6. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
cursor[bot] (Migrated from github.com) reviewed 2026-05-06 23:50:17 +00:00
cursor[bot] (Migrated from github.com) left a comment

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 4d492f6b3e. Configure here.

<!-- BUGBOT_REVIEW --> Cursor Bugbot has reviewed your changes and found 1 potential issue. There are 2 total unresolved issues (including 1 from previous review). <!-- BUGBOT_FIX_ALL --> <a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9BTExfSU5fQ1VSU09SIiwiZGF0YSI6eyJyZWRpc0tleSI6ImJ1Z2JvdC1tdWx0aTo4NDYzMDRhYS05NjIzLTQ4ZGUtOTdlNS1jZTYyNjUyN2ZhYjYiLCJlbmNyeXB0aW9uS2V5IjoiekFiSDMyV0Q2eHNhS2NSZlZQVXZ5NVVBUm44OFliSFdNdEgxQ09vOXBVVSIsImJyYW5jaCI6ImZlYXR1cmUvdHlwZXNjcmlwdC02LXVwZ3JhZGUiLCJyZXBvT3duZXIiOiJTZWEtSGF2ZW4tSW5kdXN0cmllcyIsInJlcG9OYW1lIjoic2VhaGF2ZW4tc2xhY2stYm90In0sImlhdCI6MTc3ODExMTQxNywiZXhwIjoxNzgwNzAzNDE3fQ.U5sb7IU229SKarVOH1a-i5EFZyx8oGjVXgnhYybL5DO9Rq7LCUGu8I_QFTJge8u8OFy_0tQrMpHap0LPcHWK6Unw0VhGGCEHFY1qEwu0XCdWnaTPgjhlZCaSOWCbJThsdzWgMP1AveB4koah3qqvA4eHcC6ARi-H_a6hiNunVuK1CdwX6BiHhGD2K24fBq8tnrdzmvMJMkh2UUfeSLuoS1yaNtnRCB3moMBRJFdUoLxiwTB_n7ea1tN0ZrktZqZNOu7c1jWmeY-d1e8iFWD3D5x_JBqBvR7D2YOPIpdZvzaF2So-tjDX-MIZsSuDIcCn8msJGerrYfzfXn6AiOzUGw" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix All in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a> <!-- /BUGBOT_FIX_ALL --> <!-- BUGBOT_AUTOFIX_REVIEW_FOOTNOTE_BEGIN --> <sup>❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the [Cursor dashboard](https://www.cursor.com/dashboard/bugbot).</sup> <!-- BUGBOT_AUTOFIX_REVIEW_FOOTNOTE_END --> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 4d492f6b3ea63b2cfdabafc401a4b820f780bdcb. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
@ -7,6 +7,7 @@ on:
permissions:
contents: read
pull-requests: write
id-token: write
cursor[bot] (Migrated from github.com) commented 2026-05-06 23:50:17 +00:00

Unrelated id-token: write permission added to workflow

Medium Severity

The id-token: write permission was added to the workflow but is not mentioned in the PR description and is unrelated to the TypeScript upgrade. This permission allows the workflow to mint OIDC tokens, which can be used to authenticate with cloud providers. Bundling a security-relevant permission escalation into an unrelated dependency-upgrade PR risks it going unreviewed.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 4d492f6b3e. Configure here.

### Unrelated `id-token: write` permission added to workflow **Medium Severity** <!-- DESCRIPTION START --> The `id-token: write` permission was added to the workflow but is not mentioned in the PR description and is unrelated to the TypeScript upgrade. This permission allows the workflow to mint OIDC tokens, which can be used to authenticate with cloud providers. Bundling a security-relevant permission escalation into an unrelated dependency-upgrade PR risks it going unreviewed. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: dda31b5f-f743-464b-ba5b-954c9febb1f8 --> <!-- LOCATIONS START .github/workflows/claude-review.yaml#L9-L10 LOCATIONS END --> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90Ojc4NGE1NjdjLTA3MTYtNDRhMi1iZjc2LTczMWI1MjRlMDkxMyIsImVuY3J5cHRpb25LZXkiOiJUMHFBd0RzTjJmakx1VWo1WlZzbVVLRmNReDZmTTF3U3lRalA1VGlSOWZJIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QifSwiaWF0IjoxNzc4MTExNDE3LCJleHAiOjE3ODA3MDM0MTd9.Aj7EE1Utr9eVP3ojRdTqmj-qimRNrj1qMu7ZPrVucLTqgU4uMrxXldpN6LYwWsWNCO0yL4N01wveWj7M8nUIgmft0rYd59p48JRygb417SfCkmkjiR847kBy0XVMA5U-Si-YQfxE0lHJ2ws7SD2TsWK7QuTDut6G-jFWNoI2kaf4f_bOuabqEg2V3I0OvDYZhIYB5j0x3o59xpwEthD1q153ijFkIrP8gcqhv64v1FOoHxlk8U_9CeNQcB72_zNt4asC10fus8VyLxfs3rdnZ-kPU2emJKkRRdzZ5O8M4BSyIq9v4ezkZ9dHvVdiYKj1mo9ZWeJpeVi8yNwArKtUXQ" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90Ojc4NGE1NjdjLTA3MTYtNDRhMi1iZjc2LTczMWI1MjRlMDkxMyIsImVuY3J5cHRpb25LZXkiOiJUMHFBd0RzTjJmakx1VWo1WlZzbVVLRmNReDZmTTF3U3lRalA1VGlSOWZJIiwiYnJhbmNoIjoiZmVhdHVyZS90eXBlc2NyaXB0LTYtdXBncmFkZSIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QiLCJwck51bWJlciI6MTksImNvbW1pdFNoYSI6IjRkNDkyZjZiM2VhNjNiMmNmZGFiYWZjNDAxYTRiODIwZjc4MGJkY2IiLCJwcm92aWRlciI6ImdpdGh1YiJ9LCJpYXQiOjE3NzgxMTE0MTcsImV4cCI6MTc4MDcwMzQxN30.yvYTWc2B6UazpPOBRau0HQrGwNxkQtJKpbXfDz5h4mXRFyztsoIk5VtSmlYCHB7sTouyY8kxGEzs7zkAyOOFIGjhEjQJiUCN3yOMcE-Ask1kkarT9HTZ2KMsEdNtylgSD76MHTb5BoTpcvvXtyymzYq7M9yrteUqN8GZPVoGyGKKqF84YqjeSwbYmAbw7DDSPwWR0cw4kBzcHyPxY6kryFc5DjDpKjnBWxmULIrAsRS3IukaZ9kREmgsM23y_AfcanJWuuB00ENwu_fA7WpWU1P6I7ejSMNUmqZdj6lI4ZjLu4cX4N93kBMqAuTPlq8jO0VEKhXq3F5KE_vqxmlyRg" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 4d492f6b3ea63b2cfdabafc401a4b820f780bdcb. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
This repo is archived. You cannot comment on pull requests.
No description provided.