Repository navigation
fix(build): prune devDependencies before shrinkwrap - #571
Merged
Merged
Conversation
build-pro.sh installs all deps with `npm ci`, builds, then runs `npm shrinkwrap` — so the published npm-shrinkwrap.json (shipped via the `files` allowlist) captures devDependencies as well as production deps. Prune them first, mirroring the same fix in core (harper#1781 / #1780). build-studio.sh is unaffected: it clones studio into studio-src/ and uses its own pnpm install/build in that subdir, so it doesn't depend on the harper-pro root node_modules that the prune touches. There is no prepack/prepare script, and `npm pack` ships the `files` list rather than node_modules, so pack output is unchanged apart from a prod-only shrinkwrap. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Contributor
Patch cherry-pick: conflictCherry-pick onto The conflict markers are committed on branch |
Contributor
|
Reviewed; no blockers found. |
cb1kenobi
reviewed
Jul 13, 2026
Replace the no-op `npm prune --omit=dev` before `npm shrinkwrap`: prune only touches node_modules, but the shrinkwrap is generated from the package.json manifest, so every devDependency survived in the published npm-shrinkwrap.json. That vendored dev-only platform packages (@esbuild/* via tsx) whose "optional" flag npm 11 drops when it folds the subtree into a consumer's lockfile, breaking `npm ci` with EBADPLATFORM. Prune the shrinkwrap after it is generated instead, removing every "dev": true package plus the root devDependencies block. Mirrors harper core PR #1783. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Mirrors the core fix in harper#1783 — fix(build): strip devDependencies from published shrinkwrap, the follow-up to the merged-but-no-op harper#1781.
Problem
build-tools/build-pro.shinstalls deps withnpm ci, builds, then runsnpm shrinkwrap. The original approach addednpm prune --omit=devbefore shrinkwrap — but that's a no-op:npm shrinkwrapgenerates the lockfile from thepackage.jsonmanifest, not fromnode_modules. Prune only removes packages fromnode_modules, so every devDependency (marked"dev": true) survives into the publishednpm-shrinkwrap.json. (Thanks to @cb1kenobi's Barber AI review for catching this.)That matters because the shrinkwrap vendors dev-only platform packages —
@esbuild/*pulled in viatsx— each{ "dev": true, "optional": true }. When a consumer generates their lockfile with npm 11, npm folds the subtree in and drops the"optional"flag, sonpm cifails everywhere withEBADPLATFORM @esbuild/aix-ppc64(harper#1780, harper#1782).Fix
Prune the shrinkwrap after it is generated.
build-tools/prune-shrinkwrap-dev.mjs(zero-dependency) removes every package marked"dev": trueplus the rootdevDependenciesblock, enforcing the invariant that the published shrinkwrap describes only the production tree a consumer installs.Validation
Against the real published shrinkwrap: 417 dev-only entries removed (all
@esbuild/*gone, zero"dev": trueremaining); production deps and prod-optional natives (@lmdb/*,@harperfast/rocksdb-js-*,@msgpackr-extract/*) untouched withoptional: trueintact; stripped shrinkwrap installs cleanly andnpm cipasses (validated via a local verdaccio registry).Labeled
patchto match the core PR.🤖 Generated with Claude Code