Repository navigation
TypeScript: Modernize CI and dependency maintenance #1732
Description
Activity
I'm not too familiar with the (p)npm CI stack, but I agree that version pinning via a package manager is generally a good idea,
But just quickly on this:
After the existing dependency backlog has been reviewed and updated manually, we should enable Dependabot for both JavaScript dependencies and GitHub Actions so that future updates arrive incrementally rather than accumulating for years.
I noticed that a few dependabot PRs were stale/outdated and so I have been closing this morning. The one that's been giving me pause is #1652 b/c of the eslint component (the other parts of that PR are stale). But I think we should close regardless b/c your "Toolchain modernization" proposal above offers a more principled resolution.
I believe the PRs that were open so far were triggered by Dependabot Alerts.
I thought that setting up Dependabot would automatically update these, but I think it's fine to close them manually (there are a lot of issues and PRs that should be triaged, not just those opened by Dependabot).
- changed the title
[-]Modernize CI and dependency maintenance[/-][+]TypeScript: Modernize CI and dependency maintenance[/+]on Sep 20, 2026 Progress on this tracker:
- build: migrate JavaScript tooling to pnpm 11 #1792: pinned pnpm and frozen-lockfile installs.
- ci: gate releases on shared verification #1814: stable/development releases depend on shared verification.
- build: modernize TypeScript linting with Oxlint and TypeScript 7 #1818: Oxlint with type-aware checks and TypeScript 7.
- ci: update github actions and set dependabot for github actions #1771: scheduled GitHub Actions dependency updates.
Remaining work includes Oxfmt / the formatting CI gate (#1825, still open), scheduled JavaScript dependency updates (still TODO in
.github/dependabot.yml), and an automated minimum/current VS Code compatibility matrix.Keeping this tracker open for those items; the merged toolchain PRs complete only part of its scope.
Now that the immediate CI breakage is addressed in #1731, I think we should modernize the remaining development and release infrastructure so that vscode-R does not accumulate another large dependency backlog.
This does not need to be implemented in a single PR. The goal of this issue is to agree on the direction and track a series of smaller changes.
Package management and dependency updates
I would like to migrate the repository from npm to pnpm and pin the package manager version through
packageManagerinpackage.json.After the existing dependency backlog has been reviewed and updated manually, we should enable Dependabot for both JavaScript dependencies and GitHub Actions so that future updates arrive incrementally rather than accumulating for years.
The exact pnpm version can be chosen at implementation time, taking current Dependabot support into account.
Reproducible CI and release builds
CI and release workflows should always install exactly the dependencies recorded in the lockfile.
Build and release tools such as
@vscode/vsceandovsxshould also be project dependencies rather than being fetched implicitly throughnpxduring a release.The
main, pre-release, and release workflows should use the same supported Node and Actions versions where practical.Release gating
At present, the release workflow can package and publish the extension independently of the main test workflow.
Before future releases, we should make sure that publication can only happen from a revision that has passed the required build, lint, and test checks. This could be implemented with reusable workflows or another simple mechanism that avoids duplicating CI logic.
Test coverage and compatibility matrix
The integration test suite has improved substantially recently, so we now have a reasonable basis for routine dependency updates.
We should continue strengthening it around areas where dependency or platform changes are most likely to cause regressions, especially extension activation, R session startup/IPC, terminal integration, language-server startup, and packaging of bundled resources such as
sess.It would also be useful to explicitly test both:
engines.vscode@types/vscodeshould be kept consistent with our minimum supported VS Code API rather than drifting independently.Toolchain modernization
Some of the JavaScript/TypeScript development stack is significantly behind current releases, including TypeScript, ESLint, and typescript-eslint.
Rather than assuming that we should simply upgrade the existing ESLint stack, I think this is also a good opportunity to reevaluate the linting and formatting toolchain itself. Modern alternatives such as Oxlint/Oxfmt and Biome may provide a simpler and faster maintenance model.
We should compare them against the checks we currently rely on, especially type-aware linting, and choose based on rule coverage, TypeScript compatibility, editor/CI integration, and maintenance cost rather than preserving ESLint by default.
Possible implementation order
This work should remain separate from the proposed vscode-R 4.0 extension restructuring. A reliable and routinely maintained CI baseline should make that larger refactoring considerably safer.