REditorSupport / REditorSupport/vscode-R

Modernize CI and dependency maintenance

Open
#1,732 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
1.2k
Forks
139
Avg merge
2h 46m
Merged PRs (30d)
5

Description

Now that the immediate CI breakage is addressed in #1731, I think we should modernize the remaining development and release infrastructure so that vscode-R does not accumulate another large dependency backlog.

This does not need to be implemented in a single PR. The goal of this issue is to agree on the direction and track a series of smaller changes.

Package management and dependency updates

I would like to migrate the repository from npm to pnpm and pin the package manager version through packageManager in package.json.

After the existing dependency backlog has been reviewed and updated manually, we should enable Dependabot for both JavaScript dependencies and GitHub Actions so that future updates arrive incrementally rather than accumulating for years.

The exact pnpm version can be chosen at implementation time, taking current Dependabot support into account.

Reproducible CI and release builds

CI and release workflows should always install exactly the dependencies recorded in the lockfile.

Build and release tools such as @vscode/vsce and ovsx should also be project dependencies rather than being fetched implicitly through npx during a release.

The main, pre-release, and release workflows should use the same supported Node and Actions versions where practical.

Release gating

At present, the release workflow can package and publish the extension independently of the main test workflow.

Before future releases, we should make sure that publication can only happen from a revision that has passed the required build, lint, and test checks. This could be implemented with reusable workflows or another simple mechanism that avoids duplicating CI logic.

Test coverage and compatibility matrix

The integration test suite has improved substantially recently, so we now have a reasonable basis for routine dependency updates.

We should continue strengthening it around areas where dependency or platform changes are most likely to cause regressions, especially extension activation, R session startup/IPC, terminal integration, language-server startup, and packaging of bundled resources such as sess.

It would also be useful to explicitly test both:

  • the minimum VS Code version declared in engines.vscode
  • the current stable VS Code version

@types/vscode should be kept consistent with our minimum supported VS Code API rather than drifting independently.

Toolchain modernization

Some of the JavaScript/TypeScript development stack is significantly behind current releases, including TypeScript, ESLint, and typescript-eslint.

Rather than assuming that we should simply upgrade the existing ESLint stack, I think this is also a good opportunity to reevaluate the linting and formatting toolchain itself. Modern alternatives such as Oxlint/Oxfmt and Biome may provide a simpler and faster maintenance model.

We should compare them against the checks we currently rely on, especially type-aware linting, and choose based on rule coverage, TypeScript compatibility, editor/CI integration, and maintenance cost rather than preserving ESLint by default.

Possible implementation order

  1. Migrate npm to pnpm with frozen lockfile installs in CI.
  2. Align main, pre-release, and release workflows and make releases depend on successful verification.
  3. Review and modernize the JavaScript/TypeScript toolchain and existing dependency backlog.
  4. Add Dependabot for JavaScript dependencies and GitHub Actions.
  5. Expand the compatibility/test matrix where useful.

This work should remain separate from the proposed vscode-R 4.0 extension restructuring. A reliable and routinely maintained CI baseline should make that larger refactoring considerably safer.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing package.json, the main, pre-release, and release workflows, and the integration test suite to map the current CI and release behavior. Compare the proposed package management, dependency update, linting, compatibility, and release-gating directions against the existing checks. Done means agreeing on a maintainable direction and splitting this broad effort into focused follow-up changes with explicit validation.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, nodejs, typescript, vscode
Domain
build-system, ci-cd, release, tooling
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.