Skip to content

chore(deps): take Bun 1.4.3 from the shared toolchain - #243

Merged
jan-kubica merged 3 commits into
mainfrom
chore/bun-1.4.3
Oct 10, 2026
Merged

jan-kubica merged 3 commits into
mainfrom
chore/bun-1.4.3

Conversation

@jan-kubica

@jan-kubica jan-kubica commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Align Bun and bun-types with the shared Bun 1.4.3 toolchain in @stll/oxlint-config 0.8.0. Use package.json for workflow version selection, add the CI toolchain check, and record the temporary bun-types quarantine exception.

Summary by CodeRabbit

  • Chores
    • Automated checks now use the Bun version specified for the project, and linting includes an additional toolchain check.
    • Updated the project’s development tooling and Bun version.
  • Documentation
    • Standardised the formatting of the licence column in the tracked libraries table; the listed libraries and licence values are unchanged.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T10:23:10.999016Z 461278e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 51 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: stella/stdnum/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ffd00c38-b2f2-4007-bec7-4e2464c03bc8

📥 Commits

Reviewing files that changed from the base of the PR and between 461278e and bece54e.


📒 Files selected for processing (1)
  • bunfig.toml

📝 Walkthrough
📝 Walkthrough

Walkthrough

The pull request updates Bun version configuration and CI setup, adds a toolchain check, and changes the formatting of the coverage table’s License column.

Changes

Bun toolchain configuration

Layer / File(s) Summary
Toolchain declarations
package.json, bunfig.toml
package.json adds the check:toolchain script, updates Bun to 1.4.3, and updates @stll/oxlint-config and bun-types. bunfig.toml adds bun-types to minimumReleaseAgeExcludes with an expiry timestamp.
CI toolchain setup
.github/workflows/ci.yml
The lint, test, oracle, rust, build, and pack jobs configure Bun from package.json. The lint job runs check:toolchain after dependency installation.

Coverage table formatting

Layer / File(s) Summary
Coverage table alignment
COVERAGE.md
The License column formatting is widened for consistent alignment. The listed libraries and license values are unchanged.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other



Merge Risk: ⚪ Minimal · up to 46127

The toolchain changes and table formatting present no established merge risk; the spelling preference is not required by the project.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly identifies the main change: updating the project to use Bun 1.4.3 from the shared toolchain. It also matches the related dependency and CI workflow updates.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.



✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR


🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR



  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@stll/oxlint-config 0.8.0 UnknownUnknown
npm/bun-types 1.4.3 UnknownUnknown

Scanned Files

  • package.json

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔇 Additional comments (4)
package.json (1)

10-10: LGTM!

Also applies to: 59-59, 62-62, 80-80

.github/workflows/ci.yml (1)

94-95: LGTM!

Also applies to: 97-97, 131-132, 150-151, 188-189, 282-283, 335-336

bunfig.toml (1)

6-6: 🔒 Security & Privacy

The concern is refuted. The local scheduled workflow delegates to a pinned reusable workflow that detects expired quarantine exceptions and prepares their removal. The quarantine-expires comment is therefore processed by repository automation, even though Bun itself does not interpret the comment and the workflow does not reject dependency resolution directly.

COVERAGE.md-5-5 (1)

5-5: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

⚠️ Unverified finding
Verification ran but could not confirm this finding. It is shown for review, not as a verified issue.

Use the British spelling Licence.

License is a noun in this heading. Change it to Licence to match the British English locale.

Suggested correction
-| Key   | Library                | Language   | License    | Countries   | Modules | Oracle                  |
+| Key   | Library                | Language   | Licence    | Countries   | Modules | Oracle                  |

Source: Linters/SAST tools


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Repository: stella/stdnum/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b2368db0-d94d-41a7-99dd-0a38b35f7edf
📥 Commits

Reviewing files that changed from the base of the PR and between aa1c502 and 461278e.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (4)
  • .github/workflows/ci.yml
  • COVERAGE.md
  • bunfig.toml
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Review details
⏰ Context from checks skipped due to timeout. (12)
  • GitHub Check: Test
  • GitHub Check: Bindings and packages
  • GitHub Check: Changeset
  • GitHub Check: Pack
  • GitHub Check: Oracle
  • GitHub Check: Version sync
  • GitHub Check: Lint
  • GitHub Check: Rust
  • GitHub Check: cla / cla
  • GitHub Check: Enforce package quarantine / Enforce package quarantine
  • GitHub Check: dependency-review
  • GitHub Check: Check generated AI instructions
🧰 Additional context used
🪛 GitHub Actions: Package quarantine policy / 0_Enforce package quarantine _ Enforce package quarantine.txt
bunfig.toml

[error] 1-1: Quarantine policy check failed: the quarantine exclude entry for "bun-types" has an invalid UTC timestamp. Failed command: bun .quarantine-policy/.github/actions/quarantine-policy/check.ts "636b7841096c8f0cc5a1572077b78768ef8fea42" "stella/stdnum".

🪛 GitHub Actions: Package quarantine policy / Enforce package quarantine _ Enforce package quarantine
bunfig.toml

[error] 1-1: Quarantine policy check failed: the bun-types exclusion has an invalid UTC timestamp.

🪛 LanguageTool
COVERAGE.md

[locale-violation] ~5-~5: License must be spelled with a “c” when used as a noun in British English. Use “licence”.
Context: ...| Library | Language | License | Countries | Modules | Oracle ...

(LICENCE_LICENSE_NOUN_SINGULAR)

@jan-kubica
jan-kubica merged commit 8babc0f into main Oct 10, 2026
15 checks passed
@jan-kubica
jan-kubica deleted the chore/bun-1.4.3 branch October 10, 2026 10:43
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 10, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant