Repository navigation
vfs-bundle: add buildGitHubBundle (a GitHub repo at a commit, via @preventive/upstream) - #196
Merged
Merged
Conversation
… @preventive/upstream)
buildGitHubBundle({ github, sha, directory?, client?, packageManager, ...buildVfsBundle options })
downloads the commit's tree through a @preventive/upstream/github.js client
(anonymous by default), every download checked against git's tree id:
- with a `directory` holding the package manager's lockfile
(pnpm-lock.yaml / yarn.lock, via listRepoDir), only that subtree
(getRepoTreeId + getRepoTreeTarball), built from its root;
- otherwise the whole repo (getRepoTarball), built from /<directory>,
for a lockfile above it.
The tarball is gunzipped and unpacked with @preventive/archive (its top
directory dropped; only files, dirs and links accepted) into a Vfs and
handed to buildVfsBundle, with `repo: { github, directory | root, commit }`
stamped from the request (validated before anything is fetched).
Adds @preventive/archive 1.0.0-beta.3 (latest) as a dependency.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4wWtS6P5ji71GhZ56NZeh
- Move it to vfs-bundle/github.js; vfs-bundle.js stays a facade (re-export; header mentions GitHub). - Lockfile names come from tree.js (lockfileOf) instead of a second map. - Tar entries go to vfsFromEntries as unpack returns them (top dir dropped); only file/directory/symlink, as GitHub's verified trees hold. - Unpacked size capped at upstream's own 1 GiB. - Check github/sha directly; const flow; shorter comments. - Simpler fake client in the tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01C4wWtS6P5ji71GhZ56NZeh
- A symlink pointing outside the downloaded tree is refused in whole-repo mode instead of silently resolving to a file inside it. - The subtree is used only when it stands alone; otherwise the whole repo is downloaded: a symlink out of it (or one unpack refuses), a lockfile link:/file:/directory: path above it, or a [jt]sconfig path above it. - A `directory` that is no plain tree in git (a symlink, or under one) falls back to the whole repo, which resolves it. - `repo` now names where the lockfile is (the real path), which the bundle's paths are relative to -- not the requested directory, which was wrong under a root lockfile or through a symlink. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01C4wWtS6P5ji71GhZ56NZeh
Validate github/sha/directory with isValidRepoField directly instead of a throwaway Bundle (clearer errors too); run the fallback test cases with Promise.all. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01C4wWtS6P5ji71GhZ56NZeh
This was referenced Oct 1, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
buildGitHubBundleto@exodus/stasis/vfs-bundle. It builds a JS bundle of a GitHub repo at a commit, optionally rooted at a directory, from the repo's lockfile alone. Nothing is read from disk.How it works
github,shaanddirectoryare checked as the bundle'srepoblock checks them (GitHubowner/name, full lowercase sha, URL-safe directory), pluspackageManager, before anything is fetched.@preventive/upstream1.0.0-alpha.3. Every download is checked against git's tree id.directory:listRepoDirchecks whether it holds the package manager's lockfile (pnpm-lock.yaml/yarn.lock). If it does, only that subtree is downloaded (getRepoTreeId+getRepoTreeTarball) and built from its root.getRepoTarball) and built from/<directory>, so a lockfile at the repo root covers a workspace package.@preventive/archive, which is new here. GitHub's top directory is dropped, and only files, directories and links are accepted. A fifo or device is refused, with its path in the error.Vfsand is handed tobuildVfsBundle, withrepo: { github, directory | root, commit }stamped from the request.Dependencies
@preventive/archive1.0.0-beta.3(latest) is added to@exodus/stasisand, for the tests, to the workspace root devDependencies.Tests
tests/vfs-bundle-github.test.jsruns against a fake in-memory client, so nothing is fetched. It covers:buildGitHubBundleis added totests/public-exports.test.js.🤖 Generated with Claude Code
https://claude.ai/code/session_01C4wWtS6P5ji71GhZ56NZeh
Generated by Claude Code