Skip to content

fix(build): prune devDependencies before shrinkwrap - #571

Merged
kriszyp merged 3 commits into
mainfrom
kris/prune-devdeps-shrinkwrap
Jul 14, 2026
Merged

kriszyp merged 3 commits into
mainfrom
kris/prune-devdeps-shrinkwrap

Conversation

@kriszyp

@kriszyp kriszyp commented Jul 13, 2026 •

Copy link
Copy Markdown
Member

Mirrors the core fix in harper#1783 — fix(build): strip devDependencies from published shrinkwrap, the follow-up to the merged-but-no-op harper#1781.

Problem

build-tools/build-pro.sh installs deps with npm ci, builds, then runs npm shrinkwrap. The original approach added npm prune --omit=dev before shrinkwrap — but that's a no-op: npm shrinkwrap generates the lockfile from the package.json manifest, not from node_modules. Prune only removes packages from node_modules, so every devDependency (marked "dev": true) survives into the published npm-shrinkwrap.json. (Thanks to @cb1kenobi's Barber AI review for catching this.)

That matters because the shrinkwrap vendors dev-only platform packages — @esbuild/* pulled in via tsx — each { "dev": true, "optional": true }. When a consumer generates their lockfile with npm 11, npm folds the subtree in and drops the "optional" flag, so npm ci fails everywhere with EBADPLATFORM @esbuild/aix-ppc64 (harper#1780, harper#1782).

Fix

Prune the shrinkwrap after it is generated. build-tools/prune-shrinkwrap-dev.mjs (zero-dependency) removes every package marked "dev": true plus the root devDependencies block, enforcing the invariant that the published shrinkwrap describes only the production tree a consumer installs.

 echo -e "\n📦 Creating shrinkwrap"
 npm shrinkwrap

+echo -e "\n📦 Pruning devDependencies from shrinkwrap"
+node build-tools/prune-shrinkwrap-dev.mjs npm-shrinkwrap.json

Validation

Against the real published shrinkwrap: 417 dev-only entries removed (all @esbuild/* gone, zero "dev": true remaining); production deps and prod-optional natives (@lmdb/*, @harperfast/rocksdb-js-*, @msgpackr-extract/*) untouched with optional: true intact; stripped shrinkwrap installs cleanly and npm ci passes (validated via a local verdaccio registry).

Labeled patch to match the core PR.

🤖 Generated with Claude Code

build-pro.sh installs all deps with `npm ci`, builds, then runs
`npm shrinkwrap` — so the published npm-shrinkwrap.json (shipped via the
`files` allowlist) captures devDependencies as well as production deps.
Prune them first, mirroring the same fix in core (harper#1781 / #1780).

build-studio.sh is unaffected: it clones studio into studio-src/ and uses
its own pnpm install/build in that subdir, so it doesn't depend on the
harper-pro root node_modules that the prune touches. There is no
prepack/prepare script, and `npm pack` ships the `files` list rather than
node_modules, so pack output is unchanged apart from a prod-only shrinkwrap.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@kriszyp
kriszyp requested a review from a team as a code owner July 13, 2026 23:29
@kriszyp kriszyp added the patch label Jul 13, 2026
@kriszyp
kriszyp requested a review from a team as a code owner July 13, 2026 23:29
@kriszyp kriszyp added the patch label Jul 13, 2026
@github-actions

github-actions Bot commented Jul 13, 2026 •

Copy link
Copy Markdown
Contributor

Patch cherry-pick: conflict

Cherry-pick onto v5.1 produced conflicts on commit(s): ebb0717b902e0e0690e9009c85ed32bfac87e56e

The conflict markers are committed on branch cherry-pick/v5.1/pr-571.
A pull request has been opened to land this patch: #584

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the build-pro.sh script to prune development dependencies using npm prune --omit=dev before generating the shrinkwrap file. There are no review comments, so I have no additional feedback to provide.

@claude

claude Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Reviewed; no blockers found.

Comment thread build-tools/build-pro.sh Outdated
kriszyp and others added 2 commits July 13, 2026 19:10
Replace the no-op `npm prune --omit=dev` before `npm shrinkwrap`: prune only
touches node_modules, but the shrinkwrap is generated from the package.json
manifest, so every devDependency survived in the published npm-shrinkwrap.json.
That vendored dev-only platform packages (@esbuild/* via tsx) whose "optional"
flag npm 11 drops when it folds the subtree into a consumer's lockfile, breaking
`npm ci` with EBADPLATFORM.

Prune the shrinkwrap after it is generated instead, removing every "dev": true
package plus the root devDependencies block. Mirrors harper core PR #1783.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@kriszyp
kriszyp merged commit 07acd0f into main Jul 14, 2026
31 of 32 checks passed
@kriszyp
kriszyp deleted the kris/prune-devdeps-shrinkwrap branch July 14, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants