chore(tooling): simplify development dependencies - #235
Merged
vanilla-wave merged 3 commits intoSep 10, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reduce the development dependency graph from 635 to 328 lockfile entries (48.3%). Replace Jest/ts-jest with Vitest 5, jsdom 30 and V8 coverage; remove unused jest-dom, the size-limit visualizer, commitlint and the ESLint Prettier plugin. Runtime dependencies and React peer versions stay unchanged. Vitest/Vite also bundle internal dependencies, so these counts describe the npm graph.
Tests retain DOM cleanup, mock state, hook ordering and the localhost URL. Standalone TypeScript checks all tests/helpers and compile-time assertions; watch mode also checks types. CI runs V8 coverage with text, JSON, LCOV/HTML and Clover reports. Coverage and published output exclude test helpers, and builds clear stale dist files. Controller diagnostics use the configured logger without detecting a test runner; a regression test covers additional instances. One previously unawaited rejection assertion is corrected.
Commit hooks and CI PR-title validation now use a dependency-free Node CLI: one Conventional Commit header, a supported lowercase type, optional scope/!, nonempty subject and a 100-code-unit limit. Git editor comments, whitespace and verbose diff blocks are cleaned before checking and writing back the accepted message. Bodies, footers and extended commitlint exemptions are outside this intentionally smaller contract. PR titles are passed as literal arguments and edits rerun CI.
Prettier runs separately in lint and staged-file hooks; eslint-config-prettier retains conflicting-rule suppression. Source-file formatting scope is preserved. Standard size-limit checks remain, without the optional --why visualizer.
Dependabot is restricted to security fixes. Ordinary npm and GitHub Actions version-update PRs are disabled with open-pull-requests-limit: 0; security updates remain enabled. Only development patch/minor updates in the security group qualify for automatic merging. Major security fixes and runtime updates remain manual. A regression test rejects ordinary development updates.
Validation: 546 tests in 37 files; native tests of real Git commits, the checker CLI and Dependabot policy; lint/format, library/test typechecks, watch typecheck smoke test, build and size-limit pass. Statement coverage is 94.62%; npm audit reports zero vulnerabilities. npm pack contains no tests, helpers or tooling scripts. Independent review covered workflow input handling, formatter scope and Git editor compatibility.