Skip to content

fix: require solid-js 1.9.13 or later - #543

Open
AlemTuzlak wants to merge 2 commits into
mainfrom
fix/511-solid-js-floor
Open

AlemTuzlak wants to merge 2 commits into
mainfrom
fix/511-solid-js-floor

Conversation

@AlemTuzlak

@AlemTuzlak AlemTuzlak commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

SSR apps with solid-js 1.9.12 or earlier in their lockfile cannot start the dev server: "use" is not exported by solid-js/web/dist/server.js. This PR raises the solid-js minimum to 1.9.13, the first version whose server build exports use.

🎯 Changes

  • The Solid compiler emits use from solid-js/web for every ref. Since devtools-ui 0.7.0, ThemeContextProvider has a ref, and devtools and devtools-utils have refs too.
  • solid-js added use to its server build (as a notSup stub) in 1.9.13. Our ranges were >=1.9.7 and ^1.9.9, so lockfiles with 1.9.12 stayed valid and then failed.
  • The dependency and peer ranges in devtools, devtools-ui, devtools-utils, devtools-a11y, and solid-devtools now start at 1.9.13.
  • The Solid examples and the Solid e2e app also move to ^1.9.13, because sherif requires one range per dependency in the workspace.
  • The lockfile moves from solid-js 1.9.12 to 1.9.15 everywhere, so the workspace keeps one copy of Solid. No other package changes.
  • 1.9.11 and later also include the seroval security fix that bump solid-js to avoid security vulnerability #410 asks for.

✅ Checklist

  • I have followed the steps in the Contributing guide.
  • I have tested code changes locally with pnpm test:pr, or these tests do not apply to this pull request.
  • I fully understand the code in this pull request, including any code generated with AI assistance.

🚀 Release Impact

  • This change affects published code, and I have generated a changeset.
  • This change is docs/CI/dev-only (no release).

Testing

Commands run

  • vitest run for devtools-ui (64), devtools (370), devtools-utils (18), and devtools-a11y (31): all pass on solid-js 1.9.15.
  • pnpm install --frozen-lockfile: the lockfile is consistent.
  • pnpm run test:sherif: no errors.
  • From packages/devtools-ui, solid-js/web resolves to the server build under Node, and typeof use is function.
  • I did not run the full pnpm test:pr.

Manual test

  1. Use a TanStack Start app with solid-js@1.9.12 in its lockfile and @tanstack/devtools@0.14.x.
  2. Before this fix: vite dev fails with MISSING_EXPORT "use".
  3. After this fix: installing a build from this branch pulls solid-js 1.9.13 or later, and vite dev starts.

How this PR makes testing easy

No new tests. The existing Solid package suites now run on solid-js 1.9.15.

Linked issues

Fixes #511
Fixes #410

Risk / rollback

Low. Apps that pin solid-js below 1.9.13 get a peer warning and must update solid-js. To undo, revert this PR.

Public API change

Before

"peerDependencies": { "solid-js": ">=1.9.7" }

After

"peerDependencies": { "solid-js": ">=1.9.13" }

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Compatibility
    • SolidJS DevTools packages and examples now require SolidJS 1.9.13 or later. Earlier versions may not support server builds correctly.
  • Releases
    • Patch releases are planned for the affected DevTools packages.

The Solid compiler emits `use` from solid-js/web for every `ref`, and
devtools-ui 0.7.0 added a ref to ThemeContextProvider. The server build of
solid-js exported `use` only from 1.9.13, so SSR apps with solid-js 1.9.12
or earlier in their lockfile failed with `"use" is not exported`.

The dependency and peer ranges were ">=1.9.7" and "^1.9.9", so resolvers kept
the old versions. They now start at 1.9.13. The lockfile moves to solid-js
1.9.15 and no other package changes.

1.9.11+ also has the seroval security fix from #410.

Fixes #511
Fixes #410
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: TanStack/devtools/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 0cd7e95a-d377-402e-87de-0ebc4873063c

📥 Commits

Reviewing files that changed from the base of the PR and between afa01fe and d2c6102.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (11)
  • .changeset/solid-js-1-9-13-floor.md
  • e2e/apps/solid/package.json
  • examples/solid/a11y-devtools/package.json
  • examples/solid/basic/package.json
  • examples/solid/devtools-ui/package.json
  • examples/solid/start/package.json
  • packages/devtools-a11y/package.json
  • packages/devtools-ui/package.json
  • packages/devtools-utils/package.json
  • packages/devtools/package.json
  • packages/solid-devtools/package.json

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The pull request raises SolidJS dependency and peer dependency minimums to 1.9.13 across devtools packages and Solid examples. It adds a changeset marking five packages for patch releases.

Changes

SolidJS version requirement

Layer / File(s) Summary
Update SolidJS requirements
.changeset/solid-js-1-9-13-floor.md, packages/*/package.json, e2e/apps/solid/package.json, examples/solid/*/package.json
Devtools package requirements and Solid example dependencies now specify SolidJS 1.9.13 or later. The changeset records patch releases for five packages and states that older versions lack the solid-js/web server export required by compiled output.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to d2c61

The change raises the SolidJS minimum to address the reported SSR startup failure. No specific blocking regression is evident in the reviewed changes.

Architecture Summary

Architecture risk: 🔵 Low · up to d2c61

The change affects 7 systems.

Changed systems: examples, e2e, packages/devtools, packages/devtools-a11y, packages/devtools-ui, packages/devtools-utils, packages/solid-devtools

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — examples (service) was modified; 4 changed files map to changed impact.
  • observed — e2e (service) was modified; 1 changed file maps to changed impact.
  • observed — packages/devtools (library) was modified; 1 changed file maps to changed impact.
  • observed — packages/devtools-a11y (library) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in e2e/apps/solid/package.json: The solid-js dependency range changed from ^1.9.9 to ^1.9.13.
  • observed — Modified behavior in examples/solid/a11y-devtools/package.json: The solid-js dependency range changed from ^1.9.9 to ^1.9.13.
  • observed — Modified behavior in examples/solid/basic/package.json: The solid-js dependency range changed from ^1.9.9 to ^1.9.13.
  • observed — Modified behavior in examples/solid/devtools-ui/package.json: The solid-js dependency range changed from ^1.9.9 to ^1.9.13.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The PR raises the solid-js dependency and peer-dependency minimum to ^1.9.13 or >=1.9.13 in packages/devtools and packages/devtools-ui, which addresses the SSR use export failure in [#511]…
Out of Scope Changes check ✅ Passed The changeset and the Solid version updates in the Solid examples and e2e app support the dependency-floor change. The additional package manifest updates keep related workspace packages consistent wi…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Title check ✅ Passed The title clearly and concisely identifies the main change: requiring SolidJS 1.9.13 or later.
Description check ✅ Passed The description is complete and relevant. It explains the SSR failure, dependency changes, release impact, testing performed, linked issues, risks, rollback, and public API impact. It also records tha…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nx-cloud

nx-cloud Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit d2c6102

Command Status Duration Result
nx run-many --target=test:e2e --parallel=1 --pr... ✅ Succeeded 1m 15s View ↗
nx affected --targets=test:eslint,test:sherif,t... ✅ Succeeded 25s View ↗
nx run-many --targets=build --exclude=examples/... ✅ Succeeded 2s View ↗

☁️ Nx Cloud last updated this comment at 2026-10-02 15:28:13 UTC

@nx-cloud

nx-cloud Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🤖 Nx Cloud AI Fix Eligible

An automatically generated fix could have helped fix failing tasks for this run, but Self-healing CI is disabled for this workspace. Visit workspace settings to enable it and get automatic fixes in future runs.

To disable these notifications, a workspace admin can disable them in workspace settings.


View your CI Pipeline Execution ↗ for commit 76ea7ee

Command Status Duration Result
nx affected --targets=test:eslint,test:sherif,t... ❌ Failed 4m 54s View ↗
nx run-many --target=test:e2e --parallel=1 --pr... ✅ Succeeded 1m 16s View ↗
nx run-many --targets=build --exclude=examples/... ✅ Succeeded 48s View ↗

☁️ Nx Cloud last updated this comment at 2026-10-02 13:33:48 UTC

@pkg-pr-new

pkg-pr-new Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
More templates

@tanstack/angular-devtools

npm i https://pkg.pr.new/@tanstack/angular-devtools@543

@tanstack/devtools

npm i https://pkg.pr.new/@tanstack/devtools@543

@tanstack/devtools-a11y

npm i https://pkg.pr.new/@tanstack/devtools-a11y@543

@tanstack/devtools-bundler-core

npm i https://pkg.pr.new/@tanstack/devtools-bundler-core@543

@tanstack/devtools-client

npm i https://pkg.pr.new/@tanstack/devtools-client@543

@tanstack/devtools-rspack

npm i https://pkg.pr.new/@tanstack/devtools-rspack@543

@tanstack/devtools-ui

npm i https://pkg.pr.new/@tanstack/devtools-ui@543

@tanstack/devtools-utils

npm i https://pkg.pr.new/@tanstack/devtools-utils@543

@tanstack/devtools-vite

npm i https://pkg.pr.new/@tanstack/devtools-vite@543

@tanstack/devtools-webmcp

npm i https://pkg.pr.new/@tanstack/devtools-webmcp@543

@tanstack/devtools-event-bus

npm i https://pkg.pr.new/@tanstack/devtools-event-bus@543

@tanstack/devtools-event-client

npm i https://pkg.pr.new/@tanstack/devtools-event-client@543

@tanstack/preact-devtools

npm i https://pkg.pr.new/@tanstack/preact-devtools@543

@tanstack/react-devtools

npm i https://pkg.pr.new/@tanstack/react-devtools@543

@tanstack/solid-devtools

npm i https://pkg.pr.new/@tanstack/solid-devtools@543

@tanstack/svelte-devtools

npm i https://pkg.pr.new/@tanstack/svelte-devtools@543

@tanstack/vue-devtools

npm i https://pkg.pr.new/@tanstack/vue-devtools@543

commit: d2c6102

sherif requires one range per dependency across the workspace. The
examples and the Solid e2e app still asked for ^1.9.9. The lockfile already
resolved them to 1.9.15, so only the specifiers change.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant