Skip to content

build(ui): upgrade to TypeScript 7 and align the Node 26 toolchain - #3379

Merged
SamMorrowDrums merged 1 commit into
mainfrom
sammorrowdrums-typescript-node-runtime-alignment
Oct 2, 2026
Merged

SamMorrowDrums merged 1 commit into
mainfrom
sammorrowdrums-typescript-node-runtime-alignment

Conversation

@SamMorrowDrums

Copy link
Copy Markdown
Collaborator

Summary

Upgrade the UI to native TypeScript 7.0.2 and @types/node 26.6.4. Align CI and local UI requirements with the existing Node 26 Docker build stage.

Why

Follow-up to #3370 for the two deferred UI toolchain upgrades. CI previously selected Node 22 for UI builds and Node 20 for JavaScript CodeQL, while Docker already used Node 26 and the UI types targeted Node 25.

Node 26 is a supported Current release, newer than the LTS line; it enters LTS on October 28, 2026. It only builds the embedded UI, rather than running the production server. Keeping Docker's major avoids changing its pinned image. Vite 8.3.2 and @vitejs/plugin-react 6.1.1 accept Node 26 through their >=22.12.0 engine ranges; actions/setup-node supports reading the engine range from package.json.

What changed

  • Upgrade TypeScript 5.9.3 to the latest stable 7.0.2 and @types/node 25.9.9 to 26.6.4. Update the lockfile, including platform-specific native compiler binaries and matching undici-types.
  • Set UI engines to ^26.0.0; both setup-node consumers read ui/package.json. The Docker UI stage stays on the existing digest-pinned node:26-alpine image.
  • Document Node 26 and native compiler commands in CONTRIBUTING.md.
  • TypeScript 7 ships the native Go-based compiler through the existing tsc command. Vite handles transpilation and bundling independently; there is no TypeScript compiler API integration, typescript-eslint, or ts-node dependency blocking TS 7. No TS 6 fallback is needed. Source types and all existing tsconfig options pass unchanged, so no deprecated-option workaround or source edits are required.
  • React, React DOM, @primer/react, @modelcontextprotocol/ext-apps, and all unrelated locked dependencies remain unchanged.

MCP impact

  • No tool or API changes
  • Tool schema or behavior changed
  • New tool added

Only the UI build/type-check toolchain and runtime configuration change; MCP schemas and behavior are unchanged.

Prompts tested (tool changes only)

  • N/A — no tool changes.

Security / limits

  • No security or limits impact
  • Auth / permissions considered
  • Data exposure, filtering, or token/size limits considered

No runtime auth, permissions, data exposure, or limits changes. npm audit reports zero vulnerabilities.

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR

No tools are renamed.

Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.

Lint & tests

  • Linted locally with ./script/lint
  • Tested locally with ./script/test

Commands and results:

  • cd ui && npm ci && npm run typecheck && npm run build && npm audit — passed in the Dockerfile's exact digest-pinned Node image (Node 26.5.0 / npm 11.17.0), because the host has Node 22. All four bundles built; audit found zero vulnerabilities.
  • GOTOOLCHAIN=go1.26.8 script/lint — passed, zero issues. Used the documented toolchain override for the repository-pinned linter's Go export-data compatibility.
  • script/test — passed, full Go race-test suite.
  • docker build --target ui-build -t github-mcp-server-ui-toolchain-check . — passed.
  • tar -cf - Dockerfile .dockerignore ui/package.json ui/package-lock.json ui/tsconfig.json ui/vite.config.ts ui/src ui/scripts | docker build --target ui-build -t github-mcp-server-ui-toolchain-check - — passed again with a clean context excluding local node_modules.
  • docker run --rm -w /app/ui github-mcp-server-ui-toolchain-check sh -c 'node --version && npm exec tsc -- --version && npm run typecheck && npm ls typescript @types/node react @primer/react @modelcontextprotocol/ext-apps --depth=0' — passed, confirming compiler 7.0.2 and type checking inside the freshly built Alpine stage.
  • git diff --check — passed. A structured lockfile comparison confirmed that only TypeScript/native binaries, Node types, undici-types, and root metadata changed.

Vite emits an existing advisory about future native config loading and __dirname; current builds succeed. That unrelated future migration is not changed here. Live GitHub E2E tests and the complete Docker server image were not run; the requested UI stage was built.

Docs

  • Not needed
  • Updated (README / docs / examples)

CONTRIBUTING.md now documents the Node 26 and TypeScript 7 UI workflow.

Read the CI Node version from UI engines and match Docker and Node types.\nDocument the native compiler workflow without changing UI dependencies.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@SamMorrowDrums
SamMorrowDrums marked this pull request as ready for review October 2, 2026 09:51
@SamMorrowDrums
SamMorrowDrums requested a review from a team as a code owner October 2, 2026 09:51
Copilot AI balanced review requested due to automatic review settings October 2, 2026 09:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency, lockfile, CI, Docker, and documentation changes are consistent and internally aligned.

Review effort: Balanced
Findings: None

What changed in this PR

Upgrades the UI to TypeScript 7 and Node.js 26 while aligning CI, Docker, and contributor documentation.

Changes:

  • Upgrades TypeScript, Node typings, and associated lockfile dependencies.
  • Configures UI and CodeQL workflows to derive Node 26 from package.json.
  • Documents the updated UI development workflow.
File Description
ui/​package.json Updates Node requirements and TypeScript dependencies.
ui/​package-lock.json Locks compiler binaries and updated typings.
CONTRIBUTING.md Documents Node 26 and TypeScript 7 usage.
.github/​workflows/​code-scanning.yml Aligns JavaScript CodeQL with the UI Node version.
.github/​actions/​build-ui/​action.yml Aligns UI builds with the declared Node version.
Files not reviewed (1)
  • ui/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@SamMorrowDrums
SamMorrowDrums merged commit f89f884 into main Oct 2, 2026
20 checks passed
@SamMorrowDrums
SamMorrowDrums deleted the sammorrowdrums-typescript-node-runtime-alignment branch October 2, 2026 10:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants