Skip to content

chore(deps-dev): bump @koa/router from 14.0.0 to 15.0.0 - #145

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/koa/router-15.0.0
Open

chore(deps-dev): bump @koa/router from 14.0.0 to 15.0.0#145
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/koa/router-15.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Contributor

Bumps @koa/router from 14.0.0 to 15.0.0.

Release notes

Sourced from @​koa/router's releases.

v15.0.0

  • chore: add full migration guide to v15 91a0ce2
  • feat: re-writing in TS + fix all reported bugs + add all effective enhancments + rock to v15 d53e17f
  • Revert "Fix: Ensure .use() middleware works when path or prefix contains para…" (#204) e64b164
  • Fix: Ensure .use() middleware works when path or prefix contains parameters (#203) 3ca5aa6

Check the full docs here, and the full migration here!


koajs/router@v14.0.0...v15.0.0

Commits
  • b65d6ae v15.0.0
  • 91a0ce2 chore: add full migration guide to v15
  • d53e17f feat: re-writing in TS + fix all reported bugs + add all effective enhancment...
  • e64b164 Revert "Fix: Ensure .use() middleware works when path or prefix contains para...
  • 3ca5aa6 Fix: Ensure .use() middleware works when path or prefix contains parameters (...
  • See full diff in compare view
Maintainer changes

This version was pushed to npm by 3imed-jaberi, a new releaser for @​koa/router since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [@koa/router](https://github.com/koajs/router) from 14.0.0 to 15.0.0.
- [Release notes](https://github.com/koajs/router/releases)
- [Commits](koajs/router@v14.0.0...v15.0.0)

---
updated-dependencies:
- dependency-name: "@koa/router"
  dependency-version: 15.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 1, 2026
Comment thread package.json
},
"devDependencies": {
"@koa/router": "^14.0.0",
"@koa/router": "^15.0.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: @koa/router v15 is a breaking major release (TypeScript rewrite). Bumping only this devDependency line breaks the build and 45 tests locally: import Router = require('@koa/router') no longer yields a constructable default export (TypeError: Router is not a constructor), and Router.Middleware is no longer a valid namespace type (src/koa-utils.ts, src/router.ts). Land the v15 migration in application/test source (see FULL_MIGRATION_TO_V15+) alongside this version bump, or stay on v14 until ready.

This review was generated by review-bot.

@lifeomic-review-bot lifeomic-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scope

Dependabot bumps @koa/router from ^14.0.0 to ^15.0.0 in package.json with a matching yarn.lock refresh (changedFiles: package.json, yarn.lock only). @koa/router is a peer dependency used throughout Koa routing helpers and tests; v15 is a major TypeScript rewrite with export and type-surface changes.

Upstream: koajs/router v15.0.0 (compare v14.0.0…v15.0.0; migration guide linked in PR body).

CI

ciStatus is pending with no recorded check results. Local verification after yarn install --frozen-lockfile shows yarn build and yarn test both fail — expect CI to fail until migration land.

Regression risk

High for a lockfile-only diff. v15 changes the CommonJS export shape (require('@koa/router') is now { Router, default }, not a direct constructor) and removes Router.Middleware as a namespace type in favor of exported RouterMiddleware. Without accompanying source changes, 45/78 tests fail (TypeError: Router is not a constructor) and tsc reports errors in src/koa-utils.ts, src/router.ts, and all three test files that use import Router = require('@koa/router').

[blocking] This PR cannot merge as-is: bumping the devDependency alone breaks compile and the Koa integration test suite. Required follow-up (not in changedFiles):

  • Update test imports — e.g. import { Router } from '@koa/router' or import Router from '@koa/router' instead of import Router = require('@koa/router').
  • Replace Router.Middleware with RouterMiddleware from @koa/router in src/koa-utils.ts and src/router.ts.
  • Consider dropping @types/koa__router (v15 ships its own types) and revisiting peerDependencies (>=14.0.0 still allows v14 consumers while CI tests v15).
  • Confirm Node >= 20 (v15 engines requirement) is acceptable for this repo's CI matrix.

[suggestion] After code migration, run the full yarn checks pipeline and confirm no runtime regressions in router.routes() / allowedMethods() middleware composition.

Note: Review generated using Cursor model composer-2.5.

This review was generated by review-bot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants