Upgrade to TypeScript ~6.0.3 #19
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#19
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/typescript-6-upgrade"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
typescriptfrom ~5.7.2 to ~6.0.3"types": ["node"]totsconfig.json— required by TS 6 to resolve Node globals (path,__dirname)@types/nodestays at^22.0.0to match the Lambda NODEJS_22_X runtimeSupersedes Dependabot PRs #13 and #17.
Test plan
tsc --noEmitpasses cleanlycdk synthsucceedsPR Summary
Medium Risk
Upgrading to TypeScript 6 can surface new type-checking/build issues across the repo, and the workflow permission change (
id-token: write) expands GitHub Actions token capabilities.Overview
Upgrades the toolchain to TypeScript
~6.0.3(with updated@types/node) and refreshespackage-lock.jsonto match.Updates
tsconfig.jsonto explicitly include Node types via"types": ["node"]to ensure Node globals/modules resolve under TS6.Extends the
claude-reviewGitHub Actions workflow permissions by addingid-token: write.Reviewed by Cursor Bugbot for commit
4d492f6b3e. Bugbot is set up for automated code reviews on this repo. Configure here.@ -14,11 +14,11 @@"@aws-sdk/client-dynamodb": "^3.1030.0",TypeScript version range changed from tilde to caret
Medium Severity
The
typescriptversion specifier changed from~5.7.2(patch-only updates) to^6.0.3(minor + patch updates). TypeScript explicitly does not follow semantic versioning — minor releases like 6.1 or 6.2 can introduce breaking type-checking changes. The previous~prefix was the safer, intentional choice. Using^risks futurenpm installruns pulling in a TypeScript minor release that breaks the build with new type errors.Reviewed by Cursor Bugbot for commit
6d9b874250. Configure here.Node type definitions don't match Node.js 22 runtime
Low Severity
@types/nodewas bumped from^22.0.0to^25.6.0, but every Lambda function in the project usesNODEJS_22_Xruntime and the Docker service usesnode:22-slim. Previously the type definitions matched the runtime; now they describe Node.js 25 APIs that may not exist on the Node.js 22 runtime, creating a false sense of type safety and risking runtime errors if Node 25–only APIs are used.Reviewed by Cursor Bugbot for commit
6d9b874250. Configure here.Lockfile corrupted: direct dependencies marked as peer-only
High Severity
Several direct dependencies now have
"peer": truein the lockfile due to a known npm bug (npm/cli#8690). Notably,constructsandaws-cdk-libare productiondependenciesinpackage.jsonbut are marked peer-only in the lockfile — runningnpm ci --omit=peerwould skip them entirely, breakingcdk synthandcdk deploy. The same issue affectstypescript,@types/node, and@aws-sdk/client-dynamodb(devDeps gaining an extrapeer: trueflag). Regenerating the lockfile with npm ≥11.6.3 fixes this.Additional Locations (2)
package-lock.json#L2144-L2145package-lock.json#L2792-L2793Reviewed by Cursor Bugbot for commit
3b84455692. Configure here.@ -16,3 +16,3 @@"@types/aws-lambda": "^8.10.149","@types/node": "^22.0.0","@types/node": "^22.19.17","aws-cdk": "^2.1120.0",@types/node version specifier doesn't match intended upgrade
Low Severity
The PR title and description both state that
@types/nodeis being bumped to 25.6.0, but the actual version specifier^22.19.17can only resolve within the 22.x range due to semver caret semantics. The lockfile confirms the resolved version is 22.19.17, not 25.6.0. If the intent was to upgrade to 25.x, the specifier needs to be^25.6.0.Additional Locations (1)
package-lock.json#L2069-L2070Reviewed by Cursor Bugbot for commit
3b84455692. Configure here.@cursor review
✅ Bugbot reviewed your changes and found no new issues!
1 issue from previous review remains unresolved.
Comment
@cursor revieworbugbot runto trigger another review on this PRReviewed by Cursor Bugbot for commit
9d7182b3bc. Configure here.Cursor Bugbot has reviewed your changes and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit
4d492f6b3e. Configure here.@ -7,6 +7,7 @@ on:permissions:contents: readpull-requests: writeid-token: writeUnrelated
id-token: writepermission added to workflowMedium Severity
The
id-token: writepermission was added to the workflow but is not mentioned in the PR description and is unrelated to the TypeScript upgrade. This permission allows the workflow to mint OIDC tokens, which can be used to authenticate with cloud providers. Bundling a security-relevant permission escalation into an unrelated dependency-upgrade PR risks it going unreviewed.Reviewed by Cursor Bugbot for commit
4d492f6b3e. Configure here.