Repository navigation
chore: upgrade standardserver to 0.8.1 - #1956
Conversation
Bumps all seven @standardserver packages from ^0.8.0 to ^0.8.1 across the workspace. Only @standardserver/node changed between the two releases; the other six tarballs are byte-identical. That release adds a cancel-safe `toWebReadableStream`, which the static file handler now uses in place of `Readable.toWeb`. It returns the exact stream type, so the accompanying cast is gone, and `node:stream` is no longer needed there. `@orpc/node` gains `@standardserver/node` as a dependency to import it. Also prunes `minimumReleaseAgeExclude` down to the entries still inside the release-age window. The 0.7.1 and 0.8.0 pins had long since aged out, and the blume and @TanStack entries pinned versions the workspace no longer resolves.
More templates
@orpc/ai-sdk
@orpc/arktype
@orpc/bun
@orpc/client
@orpc/cloudflare
@orpc/contract
@orpc/experimental-effect
@orpc/evlog
@orpc/hibernation
@orpc/json-schema
@orpc/experimental-msw
@orpc/nest
@orpc/next
@orpc/node
@orpc/openapi
@orpc/opentelemetry
@orpc/pinia-colada
@orpc/pino
@orpc/publisher
@orpc/ratelimit
@orpc/server
@orpc/shared
@orpc/swr
@orpc/tanstack-query
@orpc/trpc
@orpc/valibot
@orpc/zod
commit: |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Dependency bump — Upgrades all seven
@standardserver/*packages from^0.8.0to^0.8.1across the root and workspacepackage.jsons, with matchingpnpm-lock.yamlupdates (specifier, integrity, and snapshot graphs all consistent;@standardserver/node@^0.8.1added to@orpc/node). - Static file handler —
packages/node/src/static-file-handler-plugin.tsnow serves file bodies viatoWebReadableStream(...)from@standardserver/nodeinstead ofReadable.toWeb(...) as ReadableStream<Uint8Array<ArrayBuffer>>. This drops the cast, the now-unusednode:streamimport, and picks up upstream's cancel-safe enqueue (guards a post-cancelenqueueon a closed controller — nodejs/node#54205). - Release-age exclusions —
pnpm-workspace.yaml::minimumReleaseAgeExcludeis pruned of entries whose pinned versions aged out (0.7.1/0.8.0, staleblume/@tanstackpins), replaced with the new0.8.1entries and a policy comment.
I verified at head that @standardserver/[email protected] exports toWebReadableStream(stream: Readable): ReadableStream<Uint8Array<ArrayBuffer>> — the return type matches exactly what body is declared as, so the cast removal is type-sound and type:check's passing claim is consistent. The implementation iterates Symbol.asyncIterator only from inside pull(), checks a canceled flag before enqueue, and destroys the stream on cancel (skipping IncomingMessage), which is precisely the cancel-safety hardening described. The compressed (sse) path's Duplex.toWeb in batch-response-compression-handler-plugin.ts is a separate write-side concern and is correctly left untouched; blast radius is static-file body serving only. Scope, lockfile, and cleanup are all consistent and well-scoped.
Minor, non-blocking observation: there's no dedicated regression test for the cancel race itself (it reproduces only on Node 22, which makes it genuinely hard to pin reliably), so future coverage bears watching if the helper behavior ever changes upstream.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏

Upgrades all seven
@standardserver/*packages from^0.8.0to^0.8.1. Only@standardserver/nodeactually changed between the two releases (the other six tarballs are byte-identical), and the change it brings is a cancel-safetoWebReadableStreamthat the static file handler now uses.Changes
StaticFileHandlerPluginserves file bodies throughtoWebReadableStreaminstead ofReadable.toWeb. The helper enqueues only from insidepullrather than from'data'events, so a chunk arriving after the consumer cancels can no longer hit a closed controller and take down the process with an uncaughtERR_INVALID_STATE(nodejs/node#54205). It returnsReadableStream<Uint8Array<ArrayBuffer>>directly, so the cast at the call site is gone along with the now-unusednode:streamimport.@orpc/nodepicks up@standardserver/nodeas a dependency to import it, matching how@orpc/serverand@orpc/nestalready declare it.minimumReleaseAgeExcludeis pruned to only the entries still inside the release-age window. The0.7.1and0.8.0pins aged out weeks ago, and theblume/@tanstackentries pinned versions the workspace no longer resolves (it is on[email protected],@tanstack/[email protected],@tanstack/[email protected]).Scope of the fix
On Node 24 the two stream helpers behave identically: a control-vs-fixed harness that cancels mid-read across three topologies (bare, through a
TransformStream, through aCompressionStream) produced no uncaught exception either way, since Node has fixed the underlying bug on its side. This is hardening for the older Node versions in the supported range (22+) where it still bites, plus the cast removal. It is not a fix for a crash reachable on current Node.Testing
Full suite passes: 3270 root, 26 cloudflare, 97 bun, including the 77 static file handler tests.
type:checkand eslint are clean. Fifty read-then-cancel cycles leak no file descriptors, matching the previous behavior.