You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Repository hygiene: minify the CDN bundle, remove stale config, fix contributor docs and templates #421
Tracking ticket for the hygiene items found in the September 2026 project health audit (AUDIT.md). None of these change detection behaviour; together they are a few hours of work and can ship as one PR.
Build
Minify the <script> build.dist/index.global.js is shipped unminified: 10.98 KB (2.72 KB gzip) where a minified build is 5.9 KB (2.06 KB gzip). The 0.10.2 CDN file was a 5.7 KB .min.js. Every <script src="https://unpkg.com/current-device"> user pays for it. Set minify: true on the IIFE entry in tsup.config.ts (or emit index.global.min.js and point the unpkg/jsdelivr fields at it). Keep the source map. check:es2015 and test:dist must still pass. (Done in build: minify the <script> build #426.)
Stale configuration
Delete codecov.yml and revoke the Codecov upload token it contains. Codecov is not referenced anywhere else (no CI step, no badge); the file dates from test: add codecov #364 (2023). (File deleted in chore: repository hygiene from the audit #427; revoking the token is still to do.)
Bump jsdom 25 → 30 (and @types/jsdom). pnpm audit reports 13 advisories, all reachable only through jsdom's dependency tree; none ship to consumers. (Done in chore: bump jsdom to 30 #430.)
Optional: pin GitHub Actions to commit SHAs and let Dependabot update them; cache ~/.cache/ms-playwright in the browsers job.
Release pipeline
The Changesets "version packages" PR is created with GITHUB_TOKEN, so no CI runs on it, and release.yml publishes in parallel with ci.yml rather than after it. prepublishOnly runs the build, check:es2015 and test:dist but not typecheck or the source suite. Add pnpm run typecheck && pnpm run test as a step in release.yml before the Changesets action (or create the version PR with a token that triggers CI). (Done in ci: run the type check and tests before publishing a release #425, ci: repair the release workflow for changesets/action v2 #433.)
Contributor-facing files
Rewrite .github/CONTRIBUTING.md. It still says Node >= 4, npm install, npm test and npm run clean (no such script). Base it on the commands and gotchas in CLAUDE.md (pnpm, test:dist, test:browser, check:es2015, check:package, corpus, changesets). (Done in chore: repository hygiene from the audit #427.)
Move the issue templatesBUG_REPORT.md, FEATURE_REQUEST.md, QUESTION.md from .github/ into .github/ISSUE_TEMPLATE/; GitHub only offers templates from that folder. Fix "Describe the Nug" while there. (Done in chore: repository hygiene from the audit #427.)
Move docs/plans/*.md out of docs/, which is the GitHub Pages root (they are published on the demo site's origin, and one references a parent plan that is not in the repo). (Done in chore: repository hygiene from the audit #427, deleted.)
Lint / format
There is no linter or formatter since ESLint and Prettier were removed in 2.0.0; src/ and tests/ already differ on trailing commas. A single Biome config (biome.json, one dev dependency, pnpm biome check in CI) covers both with near-zero maintenance. (Done in chore: add Biome for formatting and linting #437.)
src/index.ts stale comments: line 86 ("more efficient indexOf(), instead of Regex" — three regexes are used now), line 191 ("Check if element exists" on a substring test), line 466 ("Run device.js in noConflict mode").
CHANGELOG.md: note that the "1.0.0" section describes a version that was never published (npm went 0.10.2 → 2.0.0), and that the 0.x /umd/current-device.min.js CDN path is gone in 2.x (Broken URL #385).
Tracking ticket for the hygiene items found in the September 2026 project health audit (
AUDIT.md). None of these change detection behaviour; together they are a few hours of work and can ship as one PR.Build
<script>build.dist/index.global.jsis shipped unminified: 10.98 KB (2.72 KB gzip) where a minified build is 5.9 KB (2.06 KB gzip). The 0.10.2 CDN file was a 5.7 KB.min.js. Every<script src="https://unpkg.com/current-device">user pays for it. Setminify: trueon the IIFE entry intsup.config.ts(or emitindex.global.min.jsand point theunpkg/jsdelivrfields at it). Keep the source map.check:es2015andtest:distmust still pass. (Done in build: minify the <script> build #426.)Stale configuration
codecov.ymland revoke the Codecov upload token it contains. Codecov is not referenced anywhere else (no CI step, no badge); the file dates from test: add codecov #364 (2023). (File deleted in chore: repository hygiene from the audit #427; revoking the token is still to do.)renovate.json(2019) extends the deprecatedconfig:basepreset and Renovate has not opened a PR since January 2023; the 2026 bumps (build(deps): bump postcss from 8.5.6 to 8.5.14 #395, build(deps): bump vite from 7.3.1 to 7.3.3 #396, build(deps-dev): bump vitest from 3.2.4 to 3.2.6 #398, build(deps-dev): bump vitest from 3.2.6 to 4.1.11 #401) were Dependabot security PRs, which need no config. Either deleterenovate.jsonand add.github/dependabot.yml(npm + github-actions, monthly), or re-enable Renovate withconfig:recommended. (Done in chore: repository hygiene from the audit #427.)jsdom25 → 30 (and@types/jsdom).pnpm auditreports 13 advisories, all reachable only through jsdom's dependency tree; none ship to consumers. (Done in chore: bump jsdom to 30 #430.)~/.cache/ms-playwrightin thebrowsersjob.Release pipeline
GITHUB_TOKEN, so no CI runs on it, andrelease.ymlpublishes in parallel withci.ymlrather than after it.prepublishOnlyruns the build,check:es2015andtest:distbut nottypecheckor the source suite. Addpnpm run typecheck && pnpm run testas a step inrelease.ymlbefore the Changesets action (or create the version PR with a token that triggers CI). (Done in ci: run the type check and tests before publishing a release #425, ci: repair the release workflow for changesets/action v2 #433.)Contributor-facing files
.github/CONTRIBUTING.md. It still says Node >= 4,npm install,npm testandnpm run clean(no such script). Base it on the commands and gotchas inCLAUDE.md(pnpm,test:dist,test:browser,check:es2015,check:package,corpus, changesets). (Done in chore: repository hygiene from the audit #427.)BUG_REPORT.md,FEATURE_REQUEST.md,QUESTION.mdfrom.github/into.github/ISSUE_TEMPLATE/; GitHub only offers templates from that folder. Fix "Describe the Nug" while there. (Done in chore: repository hygiene from the audit #427.)SECURITY.md(report privately via GitHub security advisories; supported versions 2.x). (Done in chore: repository hygiene from the audit #427.)AUTHORSwas last touched in 2018 (lists greenkeeper and "The Gitter Badger"); regenerate fromgit shortlog -seor drop it in favour of.all-contributorsrc. (Done in docs: bring AUTHORS, .all-contributorsrc and the README contributors up to date #435.)docs/plans/*.mdout ofdocs/, which is the GitHub Pages root (they are published on the demo site's origin, and one references a parent plan that is not in the repo). (Done in chore: repository hygiene from the audit #427, deleted.)Lint / format
src/andtests/already differ on trailing commas. A single Biome config (biome.json, one dev dependency,pnpm biome checkin CI) covers both with near-zero maintenance. (Done in chore: add Biome for formatting and linting #437.)Docs nits (small enough to ride along)
chromeos,linuxandharmonyosto the OS badge list and the CSS that lights badges (docs/index.html~lines 226-241 and 434-446); pin the script tohttps://unpkg.com/current-device@2. (Done in docs: rework the README around what UA sniffing can and cannot do #424.)src/index.tsstale comments: line 86 ("more efficient indexOf(), instead of Regex" — three regexes are used now), line 191 ("Check if element exists" on a substring test), line 466 ("Run device.js in noConflict mode").CHANGELOG.md: note that the "1.0.0" section describes a version that was never published (npm went 0.10.2 → 2.0.0), and that the 0.x/umd/current-device.min.jsCDN path is gone in 2.x (Broken URL #385).