Clean up unused and misplaced dependencies flagged by knip - #4394
Merged
Conversation
Remove genuinely-unused dependency declarations and relocate deps that were declared in a workspace that never imported them. Also fix two knip config gaps that were producing false positives. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Collaborator
📊 Performance Test ResultsComparing d6fce3e vs trunk app-size
site-editor
site-startup
Results are median values from multiple test runs. Legend: 🟢 Improvement (faster) | 🔴 Regression (slower) | ⚪ No change (<50ms diff) |
bcotrim
approved these changes
Jul 30, 2026
bcotrim
left a comment
Contributor
There was a problem hiding this comment.
LGTM 👍
CI is green and I couldn't find any regressions
1 task
wojtekn
added a commit
that referenced
this pull request
Aug 4, 2026
…4416) ## Related issues - Related to `npx knip` cleanup (follow-up to #4394, which deferred the phantom-dependency findings) ## How AI was used in this PR Claude Code ran `npx knip`, then traced every finding to its root cause: for each phantom ("unlisted") package it checked where the import actually resolves in the lockfile and which workspace owns it; for each "unused" dependency it verified with `grep` across `src`/`e2e` and `git log` whether the consumer still exists. Each conclusion was confirmed with `npm run typecheck` (all workspaces), `npm run cli:build`, the affected Vitest suites, and a re-run of knip. I worked iteratively on multiple improvements like deduping pi packages, removing remaining unused packages, then I reviewed all changes before opening this PR. ## Proposed Changes Dev-tooling / manifest change only — no runtime or user-visible behavior changes. The goal is that each workspace's `package.json` accurately declares what it imports, and that a knip run is signal-only going forward. - **Declared ~22 phantom dependencies** in the workspace that imports them, instead of relying on npm hoisting. This removes a real fragility: packages like `typebox`/`chalk` in `apps/cli` and `@earendil-works/pi-agent-core`/`pi-ai` in `packages/common` were only resolving because a sibling dependency happened to hoist them — a transitive version change could have broken resolution. Each is pinned to the version already in the lockfile, so `npm install` is a no-op dedup. - **Silenced knip's confirmed false positives** (`@sentry/react` referenced only as a string in a Vite `manualChunks`, `@wp-playground/cli` spawned as a binary, `@automattic/wp-babel-makepot` invoked via `npx` in a Fastfile, and the `promptfoo` config path) via top-level `ignoreDependencies`/`ignoreBinaries`, and dropped now-redundant knip config lines. - **Removed genuinely-dead dependencies** and their orphaned test mocks: `hpagent` (never imported since it was added), `rehype-raw` (its only consumer, the legacy WPCOM assistant, was removed in #3683), and `@types/shell-quote` (redundant — `shell-quote` now ships its own types; the runtime package stays). - **Pruned stale `dependabot.yml` entries** for packages that no `package.json` declares anymore (`hpagent`, `compression`, `compressible`, `strip-ansi`, `ora`, `cross-port-killer`, `pm2`, `@rive-app/*`), including an empty group. - **Unified all `@earendil-works/pi-*` pins at `0.82.1`**, the version `pi-coding-agent@0.82.1` expects for its siblings. This collapses the duplicate 0.81.0/0.82.1 copies that were sitting in the lockfile. ## Testing Instructions - `npm install` — completes cleanly, no peer-dependency conflicts, lockfile shrinks (duplicate copies removed). - `npm run typecheck` — passes across all workspaces, confirming no declared/removed/bumped dependency broke resolution. - `npm run cli:build` — succeeds, confirming the newly-declared bare imports (`typebox`, `chalk`) still bundle. - `npx knip` — no remaining unlisted, binary, unresolved, unused-dependency, or configuration-hint findings. ## Pre-merge Checklist - [x] Have you checked for TypeScript, React or other console errors? Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related issues
npx knipcleanupHow AI was used in this PR
Claude Code ran
npx knip, then cross-referenced every finding against actual imports across the whole monorepo to distinguish three cases: genuinely-unused deps, deps declared in the wrong workspace, and knip false positives. Each conclusion was verified withnpm why, a fullnpm run typecheck, and a re-run of knip. All findings and edits were reviewed by a human before opening this PR.Proposed Changes
npx knipreported ~38 unused dependencies, but most were not actually dead — they were declared in a workspace that never imports them (knip reports per-workspace, so a dep used only from a sibling package reads as "unused" where it's declared). This PR sorts every finding into the correct bucket:compression,compressible,strip-ansi,@wp-playground/common,@wordpress/html-entities,@wordpress/rich-text).http-proxy/tar/yauzl/fast-deep-equalinapps/studiothat belong toapps/cli/packages/common; theexpresstrio inapps/clialready present inapps/local/apps/hosted;patch-packageduplicated from root). These packages stay installed — they're still required elsewhere — so nothing changes at runtime.electron2appx→ root, used byscripts/;@types/yauzl→apps/cli).apps/studionow listselectron.vite.config.tsas an entry, andpackages/data-liberation-agentnow has anentryplus.tsxin its project glob.The result is that each workspace's
package.jsonaccurately declares what it imports, instead of relying on npm hoisting. The lockfile shrinks accordingly (onlycompression/compressibleand their private subtree are physically removed; everything else is dedup bookkeeping).Dev-tooling/manifest change only — no runtime or user-visible behavior changes.
A separate, pre-existing issue (knip's ~22 "unlisted" phantom dependencies — imported but declared nowhere, resolving via hoisting) is intentionally out of scope and will be handled in a follow-up.
Testing Instructions
npm install— completes cleanly, no peer-dependency conflicts (removes the now-unreferencedcompressionsubtree).npm run typecheck— passes across all six workspaces, confirming no removed/moved dep broke resolution.npx knip— the only remaining "unused" findings are the deliberately-kept ones (@sentry/reactvia VitemanualChunks,@wp-playground/clispawned as a binary,@automattic/wp-babel-makepotvianpxin a Fastfile, andhpagent/rehype-raw/@types/shell-quotewhich sit behind orphaned files being removed in Remove remaining unused files flagged by Knip #4393).Pre-merge Checklist