Skip to content

elements-react pins @ory/client-fetch to an exact version, forcing duplicate installs #605

Description

@maxbeatty

@ory/elements-react declares "@ory/client-fetch": "1.22.22" in 1.2.1 (1.22.65 on master, not yet released).

Apps that also depend on @ory/client-fetch directly (to call Kratos outside Elements) end up with two copies whenever they update it, and TypeScript then rejects passing a LoginFlow/SettingsFlow fetched with one copy into <Login>/<Settings> from the other:

error TS2322: Type 'import(".../@ory+client-fetch@1.22.66/.../models/LoginFlow").LoginFlow' is not assignable to type 'import(".../@ory+client-fetch@1.22.22/.../models/LoginFlow").LoginFlow'.

Could the dependency be a caret range (^1.22.0) or a peerDependency, so a single copy can be shared? Alternatively, a release cadence that tracks @ory/client-fetch would shrink the window. For now we pin our direct dependency to whatever elements-react pins and exclude it from Dependabot.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions