Skip to content

Update all examples to workflow 5.0.1 - #52

Merged
VaguelySerious merged 7 commits into
mainfrom
peter/workflow-5.0.0
Oct 1, 2026
Merged

VaguelySerious merged 7 commits into
mainfrom
peter/workflow-5.0.0

Conversation

@VaguelySerious

@VaguelySerious VaguelySerious commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Updates all 17 examples from workflow 4.3.1 to 5.0.1, including the v5 code changes validated in #51.

  • workflow, @workflow/ai, @workflow/world-local, @workflow/world-postgres → 5.0.1. @workflow/swc-plugin stays at 5.0.0 (no 5.0.1 was published).
  • v5 code changes (cherry-picked from [DO NOT MERGE] Test all examples against workflow 5.0.0-beta.40 pre-release tarballs #51): await getWorld() in instrumentation, custom-adapter on the v5 standalone bundle layout, ffmpeg-processing requires rollup >= 4.62.4
  • Lockfiles regenerated (pnpm 10, matching Vercel builds)

5.0.1 includes the SDK fixes found while running these examples: the 5.x @workflow/ai publish (vercel/workflow#4548), errors with a read-only stack (vercel/workflow#4549), and nuxt dev (vercel/workflow#4551).

Fixes found by running every example on 5.0:

  • hono, ffmpeg-processing: nitro 3.0.1-alpha.1 → 3.0.260903-beta. On alpha.1, nitro dev tree-shakes the world registration and every start() throws "world runtime was not initialized".
  • tanstack-start: lockfile re-resolved. The previously pinned nitro-nightly build 404s the flow route, so runs stay pending.
  • postgres, flight-booking-app: workflow-postgres-setup was replaced by bootstrap in 5.0
  • birthday-card-generator, kitchen-sink: model IDs the AI Gateway no longer serves
  • hono: start script pointed at a nonexistent file

Verification

Each example was started locally, a workflow triggered, and the run checked to reach its expected terminal state (workflow inspect runs, or the Postgres table).

On 5.0.1:

  • All 17 install from the committed lockfiles (--frozen-lockfile) and build
  • Dev: nextjs, nuxt, hono, nitro, astro, sveltekit, tanstack-start, vite ✅ (nuxt dev was broken on 5.0.0)
  • Prod: nextjs, nuxt, hono, nitro, vite, tanstack-start ✅

On 5.0.0, with the same example code (not re-run on 5.0.1):

  • actors (two hook events, state count = 10), custom-adapter (bun, completes after webhook resume), postgres (world-postgres), ffmpeg-processing (dev + prod, m4a via Vercel Sandbox)
  • flight-booking-app (two chat turns via hook), ai-sdk-workflow-patterns (all 5 patterns), rag-agent (store + retrieve via pgvector), birthday-card-generator (through RSVP webhook, sleep, final step), kitchen-sink (in a scratch Next app; withCreateHook not run, needs a real OpenAI key)

astro and sveltekit build with Vercel adapters and have no local prod server.

Known issues (not fixed here)

  • rag-agent: db:migrate never creates the embeddings table (pre-existing; drizzle-kit push works around it).

Supersedes #51.

🤖 Generated with Claude Code

VaguelySerious and others added 4 commits September 30, 2026 16:00
`getWorld()` returns a Promise<World> as of v5, so `getWorld().start?.()`
no longer type-checks (and silently no-ops at runtime).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The example has no build script, so the earlier sweep never exercised it.
Running it surfaced four v5 changes:

- `flow.js` / `webhook.js` are now `flow.mjs` / `webhook.mjs`, ESM with
  named exports only, so the default imports resolved to undefined.
- `step.js` became `__step_registrations.mjs`, an internal module that
  `flow.mjs` imports. The `POST /.well-known/workflow/v1/step` route is
  deleted rather than repointed.
- The SWC plugin's `client` mode was removed and merged into `step`.
- `@swc/core` and `@workflow/swc-plugin` were never declared. They
  resolved through bun's flat node_modules; under pnpm they do not.

Verified end to end: the run starts, all steps execute, and the webhook
link is issued.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The nitro build failed with "replacement content must be a string" from
rollup's ImportExpression.render. It is a rollup 4.53.3 bug, reproducible
only when @vercel/oidc 3.0.5 and 3.8.2 are both in the tree: rollup
renders the dynamic imports in oidc 3.0.5's get-vercel-oidc-token.js while
their target modules are assigned to no chunk, so a Module object reaches
MagicString.overwrite instead of a string.

The stale lockfile was holding rollup at 4.53.3 and @vercel/sandbox at
1.0.4 (whose ^3.0.5 oidc range was pinned to literally 3.0.5). Raising the
rollup floor to ^4.62.4 encodes the actual constraint; the regenerated
lockfile also floats sandbox to 1.10.2, which drops the 3.0.5 copy.

The lockfile was regenerated against a scratch pnpm store so its tarball
entries carry integrity hashes, which makes it installable again.

No Workflow SDK change is involved: the example needs no source changes
for v5, and relaxing world-vercel's @vercel/oidc pin does not fix it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Bumps workflow, @workflow/world-local, @workflow/world-postgres and
@workflow/swc-plugin to 5.0.0 and refreshes lockfiles. @workflow/ai is
pinned to 5.0.0-beta.16: the 5.0.0 version on npm is a stale publish that
peers on workflow ^4.3.0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
birthday-card-generator Ready Ready Preview, v0 Oct 1, 2026 11:08pm UTC
flight-booking-app Ready Ready Preview, v0 Oct 1, 2026 11:08pm UTC

pnpm 11 ignores the package.json pnpm field and dropped the overrides
block, breaking frozen installs on Vercel (pnpm 10).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@vercel vercel Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additional Suggestion:

README instrumentation.ts example calls getWorld().start?.() without awaiting getWorld(), so under workflow v5 the world is never started

Fix on Vercel

Comment thread flight-booking-app/pnpm-lock.yaml
@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

- hono, ffmpeg-processing: bump nitro to 3.0.260903-beta. With
  3.0.1-alpha.1, nitro dev tree-shakes workflow's world registration and
  every start() fails with "world runtime was not initialized".
- tanstack-start: re-resolve the lockfile. The pinned nitro-nightly build
  404s the workflow flow route, so runs stay pending.
- postgres, flight-booking-app: workflow-postgres-setup moved to bootstrap.
- birthday-card-generator, kitchen-sink: replace model IDs the AI Gateway
  no longer serves.
- hono: start script pointed at a file nitro never emits.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
5.0.1 publishes the 5.x @workflow/ai, fixes nuxt dev, and keeps step
errors whose stack is read-only (postgres.js).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@VaguelySerious VaguelySerious changed the title Update all examples to workflow 5.0.0 Update all examples to workflow 5.0.1 Oct 1, 2026
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
High priority
High CVE: npm devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise

CVE: GHSA-x5rw-q4pp-hg5g devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise (HIGH)

Affected versions: >= 5.8.0 < 5.9.3

Patched version: 5.9.3

From: tanstack-start/pnpm-lock.yaml → npm/workflow@5.0.1 → npm/devalue@5.9.2

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/devalue@5.9.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@VaguelySerious
VaguelySerious merged commit 00d6c08 into main Oct 1, 2026
7 checks passed

This branch was successfully deployed

2 active deployments
Preview – flight-booking-app — 04b0b7de Deployed Oct 1, 2026 by vercel[bot]
Preview – birthday-card-generator — 04b0b7de Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant