Skip to content

Sync: dev to main - #417

Merged
aamoghS merged 11 commits into
mainfrom
dev
Sep 24, 2026
Merged

aamoghS merged 11 commits into
mainfrom
dev

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Automated PR tracking changes from dev into main.


Note

Medium Risk
Wide dependency upgrades (Zod 4, Stripe SDK majors, Vitest 5) and behavioral refactors on payments, judging prep, and form sync could surface subtle regressions despite mostly mechanical React changes.

Overview
This sync bumps the monorepo to Node 22 in CI and refreshes the stack: TypeScript 7, Next/React 19.3, Vitest 5, Zod 4, and aligned tRPC, Stripe, Drizzle, and ESLint versions across packages and sites.

API / auth: createPaymentIntent switches Zod’s optional input default to .prefault({}) (Zod 4). Router tests use RFC-style UUIDs for hackathon IDs. Nodemailer send handling treats pending as optional.

Frontend (React Compiler / hydration): New useIsClient and useWindowWidth (useSyncExternalStore) replace mount/resize useEffect patterns across the portal and marketing pages. Many screens now sync form and selection state during render (settings, submit, resumes admin, interest/membership forms, hackathon edit) instead of useEffect, to avoid stale UI and satisfy compiler lint. Admin judging routes hackathon changes through selectHackathon, bumping a generation ref so in-flight “prepare judging” work cannot apply to the wrong edition. Smaller fixes: judge queue seeding without effect races, Stripe loadStripe in useMemo, resume preview remount per src, verify redirect via location.assign.

Hacklytics 2027: Countdown uses useSyncExternalStore for client-only display; LazySection drops the no-IntersectionObserver fallback.

Reviewed by Cursor Bugbot for commit 6bc46b9. Bugbot is set up for automated code reviews on this repo. Configure here.

aamoghS and others added 10 commits September 24, 2026 14:33
Move every workspace package to TypeScript 7.0.2, including
sites/hacklytics2027 (was 5.8.3). No tsconfig or source changes were
needed; tsc --noEmit and next build type checking both pass on 7.

tooling/eslint stays on TypeScript 6.0.2 on purpose: TS 7 no longer
ships the classic JS API, and typescript-eslint (latest 8.70.1) still
requires typescript <6.1.0. Every lint config resolves typescript-eslint
through @query/eslint-config, so pinning it there keeps lint working
while the rest of the repo compiles with TS 7.
Brings every dependency with a same-major update to its latest release,
including Next.js 16.3.6 (latest stable), tRPC 11.19, TanStack Query
5.103, drizzle, Tailwind 4.3, React 19.3, eslint 10.11 and
typescript-eslint 8.70.1. No source changes needed.
- zod 3 -> 4. `.default({})` on the createPaymentIntent input now uses
  `.prefault({})`, which keeps zod 3's behaviour of running the inner
  field defaults. zod 4's `.uuid()` is RFC-strict; the database only
  generates v4 ids (defaultRandom), so the stricter check stays and the
  router test fixtures now use valid UUIDs instead of 0000...0001.
- nodemailer 9 -> 10: `SentMessageInfo.pending` is optional; guard it.
- vitest 4 -> 5: vite is now a peer dependency, so it is installed
  explicitly at the root and in @query/api.
- @stripe/stripe-js 5 -> 9, @stripe/react-stripe-js 3 -> 6, dotenv 16 -> 18,
  qrcode.react 3 -> 4, cross-env 7 -> 10: no code changes needed.
- Drop @types/minimatch and @types/qrcode.react (deprecated; both
  packages ship their own types).
- @types/node stays on 22.x to match engines (node <24).
Bump dependencies to latest minor/patch (Next.js 16.3.6)
- vitest 5 requires Node ^22.12. test.yml ran on Node 20; move it to 22,
  matching pnpm-ci.yml. vitest is dev-only, so the App Hosting runtime
  (nodejs20) and the engines range are unaffected.
- package.json asked for vite ^7.3.6 while the pnpm override pins ^7.3.5,
  so the lockfile recorded a different specifier than the manifest. Both
  now say ^7.3.5; pnpm install --frozen-lockfile passes.
Upgrade major dependencies and migrate (zod 4, vitest 5, nodemailer 10, Stripe)
Upgrades @eslint/js 10, @eslint/compat 2, eslint-config-prettier 10,
eslint-plugin-react-hooks 7 and globals 17, and drops the deprecated
@types/eslint__js.

react-hooks 7's recommended set adds the React Compiler rules. Both
sites build with reactCompiler: true, so these are real findings, not
style. Fixes for the 31 new errors:

- Mounted flags (`useEffect(() => setMounted(true), [])`) become
  `useIsClient()`, a useSyncExternalStore hook in lib/use-is-client.ts.
- Resize listeners that mirror window.innerWidth into state become
  `useWindowWidth()` in lib/use-window-width.ts. Hero reads its prop
  directly instead of copying it into state.
- Forms seeded from query data, and state reset when an input changes,
  use the "adjust state during render" pattern guarded by the previous
  value, so the stale value never paints.
- AdminLayout derives `loading` instead of storing it; the Stripe modal
  memoizes loadStripe; EventFormModal seeds the date in its initial
  state; verify uses window.location.assign; the judging page updates
  its ref in an effect instead of during render.
- LazySection drops the IntersectionObserver-missing fallback (every
  supported browser has it) and the hacklytics countdown seeds its
  first tick from the initial state.
- AttendeesTab: drop a useless initial assignment (no-useless-assignment).
- Admin judging: move the selection ref and prep generation in the click
  handler instead of a post-render effect. Between render and that effect,
  a prep run for the previous edition still passed stillThisRun and could
  land its result on the newly selected edition's panel. Re-selecting the
  current edition is now a no-op so it cannot orphan its own run.
- ResumePreview: remount per src via key instead of keying state by src.
  Going A -> B -> A before B loaded matched A's retained blob URL, which
  the A -> B cleanup had already revoked, and showed a broken PDF.
Upgrade eslint stack and fix React Compiler lint errors
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Sep 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor Author

Dependency Review

The following issues were found:

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
  • ⚠️ 2 packages with OpenSSF Scorecard issues.

View full job summary

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor Author

Visit the preview URL for this PR (updated for commit 7cb6994):

https://hacklytics2027--pr-417-jdjpmh26.web.app

(expires Thu, 01 Oct 2026 20:31:55 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: c48ba34db61581e25fe2978355160b5eefe0e83f

@aamoghS
aamoghS merged commit 162a87e into main Sep 24, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⤵️ pull dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant