Skip to content

fix(engines): require Node 20.13.0, the floor clack's code actually needs - #219

Merged
PrzemekGalarowicz merged 1 commit into
mainfrom
claude/optimistic-heisenberg-8rw8ke
Sep 25, 2026
Merged

PrzemekGalarowicz merged 1 commit into
mainfrom
claude/optimistic-heisenberg-8rw8ke

Conversation

@PrzemekGalarowicz

Copy link
Copy Markdown
Contributor

What this changes

Plan A of the second batch from the PHARN-01..18 review (finding F6), shipped through /pharn-dev-ship.

@clack/prompts 1.8.1 declares >= 20.12.0, but it passes an array of formats to util.styleText. Node accepts that only from 20.13.0. On Node 20.12.x, cancelling a confirmation (or a picker after selecting something) crashed with ERR_INVALID_ARG_VALUE and exit 1. It should print "Cancelled" and exit 0.

Measured here in a pty against the packed CLI (pharn remove), on the official binaries:

keys Node 20.12.0 Node 20.13.0
Ctrl-C at the picker 0, "Cancelled" 0, "Cancelled"
Space, Ctrl-C 1, ERR_INVALID_ARG_VALUE 0, "Cancelled"
Space, Enter, Ctrl-C (at the confirm) 1, ERR_INVALID_ARG_VALUE 0, "Cancelled"
  • engines.node is now >=20.13.0, in package.json and the lockfile's root entry. The lockfile was regenerated with npm 11.20.0, so nothing else in it changes.
  • tests/engines.test.ts no longer trusts only the dependencies' declared floors:
    • It scans their shipped code against a measured table of known API floors.
    • Planted-text cases prove the scanner both fires and stays quiet.
    • A non-vacuity case pins that @clack/prompts was actually read.
    • The smoke workflow's FLOOR is pinned to package.json.
  • node-floor.yml now uses FLOOR: 20.13.0. The job is renamed to the version-free Smoke (node floor), so future floor bumps never rename it. It is not a required check.
  • The version is corrected in README, SECURITY.md, CLAUDE.md, contributing, getting-started and troubleshooting (with the new symptom). CHANGELOG has a ### Changed entry.

Type of change

  • feat — new stack option, wizard step, or command capability
  • fix — bug fix
  • docs — docs-only change
  • chore / refactor — tooling or internal restructure, no behavior change

Area(s) touched

package metadata · tests/engines.test.ts · repo tooling (node-floor.yml, a ci.yml comment) · docs · .dev/features/engines-styletext-floor/ (pipeline artifacts)

Checklist

  • Read the existing file(s) before editing; followed the ESM .js-extension import convention.
  • Updated the matching tests/*.test.ts — the code-floor case fails on the base (>=20.12.0).
  • Updated the relevant docs/ pages.
  • Preserved the security invariants — no remote-input handling touched.

Quality gates

  • npm run check passes locally (format:check + lint + typecheck + test) — 1513 tests.
  • npm run build succeeds.
  • npm run test:coverage passes (coverage thresholds met).

Notes for the reviewer

  • Pipeline results: validate exit 0, regress no-regressions, verify PASS, review GREEN with 2 minor advisory findings (.dev/features/engines-styletext-floor/REVIEW.md).
  • Cancelling with nothing selected does not crash even on 20.12.0. The crash is in clack's cancelled-state rendering of a value, and it is not reachable before the first write.

🤖 Generated with Claude Code

https://claude.ai/code/session_0199owRmYfskqYQVQrVP679o


Generated by Claude Code

…eeds

@clack/prompts 1.8.1 declares ">= 20.12.0" but passes an ARRAY of formats
to util.styleText, which Node accepts only from 20.13.0. On 20.12.x,
cancelling a confirm prompt (or a picker after selecting something)
crashed with ERR_INVALID_ARG_VALUE and exit 1 instead of "Cancelled"
and exit 0 — measured in a pty against the packed CLI on the official
20.12.0 / 20.13.0 binaries.

- engines.node -> ">=20.13.0" (package.json + the lockfile root entry,
  regenerated with npm 11.20.0 so nothing else moves).
- tests/engines.test.ts also scans the runtime dependencies' shipped
  code against a measured known-API table, instead of trusting their
  declared floors; planted-text cases prove the scanner fires and stays
  quiet; the smoke workflow's FLOOR is pinned to package.json.
- node-floor.yml: FLOOR 20.13.0, job renamed to the version-free
  `Smoke (node floor)` (not a required check).
- README, SECURITY.md, CLAUDE.md, contributing, getting-started,
  troubleshooting and CHANGELOG updated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0199owRmYfskqYQVQrVP679o
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: da0c3770-6bb1-4dcd-9171-2f19a4f66031


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@PrzemekGalarowicz
PrzemekGalarowicz merged commit cf6582e into main Sep 25, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants