The root package.json catalog is the single version source; workspaces
write "catalog:". Most entries are caret ranges because bun.lock already
makes installs reproducible. An entry is exact only when a patch release would
change behaviour. Upgrade any of them as one reviewed change, together with
the items named beside it.
The current inventory lives in package.json: catalog, overrides, and
patchedDependencies. The tables below explain the main compatibility rules;
read those fields for the complete package list and current versions.
Exact pins
| Package | Pinned to | Why | Upstream |
|---|---|---|---|
@orpc/* |
a 2.0 beta | Prerelease: a beta bump can break the API with no semver signal. All @orpc/* packages move together. |
middleapi/orpc |
drizzle-orm |
a 1.0 release candidate | Prerelease, as above. The D1 rules in packages/db/AGENTS.md are written against this version. |
drizzle-team/drizzle-orm |
@cloudflare/sandbox |
1.0.0 |
Runtime-coupled: Workstation, CMS and Docs extend app-owned Durable Objects, use native ctx.container RPC, and copy the matching v1 sandbox-shim into each image. Upgrade the SDK and donor image together. |
cloudflare/sandbox-sdk |
vite-plus, vitest, vite |
exact; vite is an alias of @voidzero-dev/vite-plus-core |
vp fmt bundles a specific formatter, so this version decides the bytes the format check compares. vite is aliased to the Vite+ core, as Vite+ documents, and vitest must equal the version vite-plus depends on (vp toolchain vitest). Keep the core version equal to vite-plus. |
voidzero-dev/vite-plus |
wrangler, agents |
exact | Deploy and runtime behaviour at the edge. | cloudflare/workers-sdk, cloudflare/agents |
emdash, @emdash-cms/cloudflare |
exact, matching release line | CMS runtime compatibility and version-specific local patches. Update the starter manifests, embedded snapshot, patches, and lockfiles together. | emdash-cms/emdash |
Overrides
| Override | Why | Upstream |
|---|---|---|
zod |
Forces one zod copy. The AI SDK and @orpc/zod check schemas by identity, and several transitive packages still request zod 3; without the override the lockfile resolves several zod versions and schemas fail at runtime. |
colinhacks/zod |
chat |
Uses the catalog version for transitive requests as well as direct dependencies. The lockfile resolves chat and its Telegram/shared adapters to 4.41.1, satisfying the agents peer range. Review upgrades with agents and the adapters. |
vercel/chat |
vite, vitest |
Apply the catalog versions above to transitive requests too, including vite-plus’s own. |
— |
Patches
The root patchedDependencies currently names agents, EmDash and its
Cloudflare adapter; bun.lock records the same patch paths:
patches/emdash@1.1.0.patchhandles the Worker Loader transaction path, guarded collection deletion, registry bundle validation and required plugin lifecycle hooks, external-auth roles, import/seed fencing, locale-aware taxonomy archives, and atomic menu replacement.patches/@emdash-cms/cloudflare@1.1.0.patchimplements the collection-deletion registry guard using D1 batches or Durable ObjecttransactionSync, and relaxes the Kumo peer dependency to a compatible range.patches/agents@0.26.0.patchroutes facet Lifecycle alarms through registered parent-owned native jobs, preserves facet class and path identity, and adds a policy hook before facet initialization and alarm dispatch.
The CMS starters carry matching copies under apps/cms/templates/*/patches/.
Their manifests also apply @emdash-cms/plugin-forms@0.2.9.patch, which excludes
raw visitor IPs from stored submissions and defaults new forms to 30-day
retention. Each patched dependency has an entry in THIRD_PARTY_NOTICES.md,
and bun run oss:check fails on a patch without one.
Review the actual hunks on every upgrade and remove fixes supplied upstream.