Skip to content

TypeScript: Modernize CI and dependency maintenance #1732

Description

@eitsupi

Now that the immediate CI breakage is addressed in #1731, I think we should modernize the remaining development and release infrastructure so that vscode-R does not accumulate another large dependency backlog.

This does not need to be implemented in a single PR. The goal of this issue is to agree on the direction and track a series of smaller changes.

Package management and dependency updates

I would like to migrate the repository from npm to pnpm and pin the package manager version through packageManager in package.json.

After the existing dependency backlog has been reviewed and updated manually, we should enable Dependabot for both JavaScript dependencies and GitHub Actions so that future updates arrive incrementally rather than accumulating for years.

The exact pnpm version can be chosen at implementation time, taking current Dependabot support into account.

Reproducible CI and release builds

CI and release workflows should always install exactly the dependencies recorded in the lockfile.

Build and release tools such as @vscode/vsce and ovsx should also be project dependencies rather than being fetched implicitly through npx during a release.

The main, pre-release, and release workflows should use the same supported Node and Actions versions where practical.

Release gating

At present, the release workflow can package and publish the extension independently of the main test workflow.

Before future releases, we should make sure that publication can only happen from a revision that has passed the required build, lint, and test checks. This could be implemented with reusable workflows or another simple mechanism that avoids duplicating CI logic.

Test coverage and compatibility matrix

The integration test suite has improved substantially recently, so we now have a reasonable basis for routine dependency updates.

We should continue strengthening it around areas where dependency or platform changes are most likely to cause regressions, especially extension activation, R session startup/IPC, terminal integration, language-server startup, and packaging of bundled resources such as sess.

It would also be useful to explicitly test both:

  • the minimum VS Code version declared in engines.vscode
  • the current stable VS Code version

@types/vscode should be kept consistent with our minimum supported VS Code API rather than drifting independently.

Toolchain modernization

Some of the JavaScript/TypeScript development stack is significantly behind current releases, including TypeScript, ESLint, and typescript-eslint.

Rather than assuming that we should simply upgrade the existing ESLint stack, I think this is also a good opportunity to reevaluate the linting and formatting toolchain itself. Modern alternatives such as Oxlint/Oxfmt and Biome may provide a simpler and faster maintenance model.

We should compare them against the checks we currently rely on, especially type-aware linting, and choose based on rule coverage, TypeScript compatibility, editor/CI integration, and maintenance cost rather than preserving ESLint by default.

Possible implementation order

This work should remain separate from the proposed vscode-R 4.0 extension restructuring. A reliable and routinely maintained CI baseline should make that larger refactoring considerably safer.

Activity

  1. grantmcdermott commented on Sep 19, 2026

    @grantmcdermott
    Contributor

    I'm not too familiar with the (p)npm CI stack, but I agree that version pinning via a package manager is generally a good idea,

    But just quickly on this:

    After the existing dependency backlog has been reviewed and updated manually, we should enable Dependabot for both JavaScript dependencies and GitHub Actions so that future updates arrive incrementally rather than accumulating for years.

    I noticed that a few dependabot PRs were stale/outdated and so I have been closing this morning. The one that's been giving me pause is #1652 b/c of the eslint component (the other parts of that PR are stale). But I think we should close regardless b/c your "Toolchain modernization" proposal above offers a more principled resolution.

  2. eitsupi commented on Sep 19, 2026

    @eitsupi
    MemberAuthor

    I believe the PRs that were open so far were triggered by Dependabot Alerts.

    I thought that setting up Dependabot would automatically update these, but I think it's fine to close them manually (there are a lot of issues and PRs that should be triaged, not just those opened by Dependabot).

  3. added this to the 3.x milestone on Sep 19, 2026
  4. changed the title [-]Modernize CI and dependency maintenance[/-] [+]TypeScript: Modernize CI and dependency maintenance[/+] on Sep 20, 2026
  5. self-assigned this
    on Sep 26, 2026
  6. renkun-ken commented on Oct 6, 2026

    @renkun-ken
    Member

    Progress on this tracker:

    Remaining work includes Oxfmt / the formatting CI gate (#1825, still open), scheduled JavaScript dependency updates (still TODO in .github/dependabot.yml), and an automated minimum/current VS Code compatibility matrix.

    Keeping this tracker open for those items; the merged toolchain PRs complete only part of its scope.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions