Skip to content

fix: require dereference-json-schema with weak caches - #204

Merged
anttiviljami merged 1 commit into
mainfrom
fix/dereference-cache-leak
Oct 8, 2026
Merged

anttiviljami merged 1 commit into
mainfrom
fix/dereference-cache-leak

Conversation

@anttiviljami

Copy link
Copy Markdown
Member

Summary

  • Raises dereference-json-schema from ^0.2.1 to ^0.2.3.
  • Adds a regression test: a discarded client's definition must be garbage-collectable. npm test now runs jest with --expose-gc.

Why

dereference-json-schema < 0.2.3 caches every definition passed to dereferenceSync (and its dereferenced clone) in module-level Maps that are never evicted. Any app that builds clients from a new definition object each time, such as a fresh client per request, leaks the whole definition for the life of the process. 0.2.3 switched both caches to WeakMap.

The old range already allowed 0.2.3, but existing lockfiles stay on 0.2.1/0.2.2. Raising the floor moves consumers on their next upgrade of openapi-client-axios.

Seen in production at epilot: a Lambda creating an @epilot/sdk client per SQS message retained ~85 KB per message and ran containers out of memory after ~8k messages.

Test plan

  • npm test passes (74 tests)
  • New test fails with dereference-json-schema@0.2.2 and passes with 0.2.3
  • npm run lint

🤖 Generated with Claude Code

dereference-json-schema < 0.2.3 caches every definition passed to
dereferenceSync (and its dereferenced clone) in module-level Maps that
are never evicted. A client created from a new definition object each
time - e.g. a fresh client per request - therefore leaks the whole
definition for the life of the process. 0.2.3 switched both caches to
WeakMaps.

The ^0.2.1 range already allowed 0.2.3, but existing lockfiles stay on
0.2.1/0.2.2. Raising the floor moves them on the next upgrade. Adds a
regression test (run with --expose-gc) that fails on 0.2.2.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@anttiviljami
anttiviljami merged commit 899ba47 into main Oct 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant