chore(deps-dev): bump @koa/router from 14.0.0 to 15.0.0 - #145
chore(deps-dev): bump @koa/router from 14.0.0 to 15.0.0#145dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@koa/router](https://github.com/koajs/router) from 14.0.0 to 15.0.0. - [Release notes](https://github.com/koajs/router/releases) - [Commits](koajs/router@v14.0.0...v15.0.0) --- updated-dependencies: - dependency-name: "@koa/router" dependency-version: 15.0.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
| }, | ||
| "devDependencies": { | ||
| "@koa/router": "^14.0.0", | ||
| "@koa/router": "^15.0.0", |
There was a problem hiding this comment.
Blocking: @koa/router v15 is a breaking major release (TypeScript rewrite). Bumping only this devDependency line breaks the build and 45 tests locally: import Router = require('@koa/router') no longer yields a constructable default export (TypeError: Router is not a constructor), and Router.Middleware is no longer a valid namespace type (src/koa-utils.ts, src/router.ts). Land the v15 migration in application/test source (see FULL_MIGRATION_TO_V15+) alongside this version bump, or stay on v14 until ready.
This review was generated by review-bot.
There was a problem hiding this comment.
Scope
Dependabot bumps @koa/router from ^14.0.0 to ^15.0.0 in package.json with a matching yarn.lock refresh (changedFiles: package.json, yarn.lock only). @koa/router is a peer dependency used throughout Koa routing helpers and tests; v15 is a major TypeScript rewrite with export and type-surface changes.
Upstream: koajs/router v15.0.0 (compare v14.0.0…v15.0.0; migration guide linked in PR body).
CI
ciStatus is pending with no recorded check results. Local verification after yarn install --frozen-lockfile shows yarn build and yarn test both fail — expect CI to fail until migration land.
Regression risk
High for a lockfile-only diff. v15 changes the CommonJS export shape (require('@koa/router') is now { Router, default }, not a direct constructor) and removes Router.Middleware as a namespace type in favor of exported RouterMiddleware. Without accompanying source changes, 45/78 tests fail (TypeError: Router is not a constructor) and tsc reports errors in src/koa-utils.ts, src/router.ts, and all three test files that use import Router = require('@koa/router').
[blocking] This PR cannot merge as-is: bumping the devDependency alone breaks compile and the Koa integration test suite. Required follow-up (not in changedFiles):
- Update test imports — e.g.
import { Router } from '@koa/router'orimport Router from '@koa/router'instead ofimport Router = require('@koa/router'). - Replace
Router.MiddlewarewithRouterMiddlewarefrom@koa/routerinsrc/koa-utils.tsandsrc/router.ts. - Consider dropping
@types/koa__router(v15 ships its own types) and revisitingpeerDependencies(>=14.0.0still allows v14 consumers while CI tests v15). - Confirm Node
>= 20(v15enginesrequirement) is acceptable for this repo's CI matrix.
[suggestion] After code migration, run the full yarn checks pipeline and confirm no runtime regressions in router.routes() / allowedMethods() middleware composition.
Note: Review generated using Cursor model
composer-2.5.
This review was generated by review-bot.
Bumps @koa/router from 14.0.0 to 15.0.0.
Release notes
Sourced from @koa/router's releases.
Commits
b65d6aev15.0.091a0ce2chore: add full migration guide to v15d53e17ffeat: re-writing in TS + fix all reported bugs + add all effective enhancment...e64b164Revert "Fix: Ensure .use() middleware works when path or prefix contains para...3ca5aa6Fix: Ensure .use() middleware works when path or prefix contains parameters (...Maintainer changes
This version was pushed to npm by 3imed-jaberi, a new releaser for
@koa/routersince your current version.Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.