Skip to content

chore(deps): upgrade Zod while preserving protocol diagnostics - #341

Merged
Maneek21 merged 3 commits into
masterfrom
dependabot/npm_and_yarn/zod-4.6.5
Sep 23, 2026
Merged

Maneek21 merged 3 commits into
masterfrom
dependabot/npm_and_yarn/zod-4.6.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Upgrades Zod to 4.6.5 while preserving the published App v0/v1/v2 and Module v1/v2 rejection diagnostics. Zod now continues refinements after unknown-key errors; the original bump changed both semantic-error output and union branch diagnostics.

Adds one shared helper at existing refinement boundaries to retain every issue and restore the old unknown-key abort behavior. The portable App Kit ships the same authoritative helper as the host. Removes the workspace Zod 4.4.3 override and regenerates the lockfile, including the packed-consumer dependency. Zod remains outside the routine Dependabot group.

Validation:

  • 1,609 before/after App and Module corpus cases: 241 differences before the fix, zero afterward.
  • 63 App Kit tests pass, including 16 new diagnostic regressions, unchanged protocol/package-byte tests, and clean external packed consumers.
  • The core 15 new App/Module regressions also pass against the former 4.4.3 baseline.
  • All 66 shared contract tests pass. Workspace typecheck/build, full web lint, frozen install and dependency audit pass; the dependency graph contains only Zod 4.6.5. Combined validation includes the merged ESLint 10 compatibility fix.
  • All required CI passed at 625088e: https://github.com/Maneek21/Deft/actions/runs/35898814944 (API, production image/browser smoke, versioned upgrade, typecheck, lint, build; security workflow also passed).

Decision, trust boundaries, alternatives and rollback: docs/superpowers/plans/2026-09-23-zod-contract-compatibility.md. No data migration or authority changes.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 23, 2026
@Maneek21
Maneek21 marked this pull request as draft September 23, 2026 14:53
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/zod-4.6.5 branch from ca491a2 to 17ebce1 Compare September 23, 2026 15:00
Bumps [zod](https://github.com/colinhacks/zod) from 4.4.3 to 4.6.5.
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

---
updated-dependencies:
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/zod-4.6.5 branch from 17ebce1 to ded0296 Compare September 23, 2026 17:28
@Maneek21 Maneek21 changed the title chore(deps): bump zod from 4.4.3 to 4.6.5 chore(deps): upgrade Zod while preserving protocol diagnostics Sep 23, 2026
@Maneek21
Maneek21 marked this pull request as ready for review September 23, 2026 17:54
@Maneek21
Maneek21 merged commit 1427f66 into master Sep 23, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/zod-4.6.5 branch September 23, 2026 18:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant