feat(pm): handle npm 12 blocked install scripts in create and approve-builds - #2336
Merged
Conversation
✅ Deploy Preview for viteplus-preview canceled.
|
Contributor
|
✅ Staging deployment successful! Preview: https://viteplus-staging.void.app/ |
Contributor
Native binary sizes (
|
| Artifact | Format | Base | PR | Change |
|---|---|---|---|---|
vp (Linux x64) |
Binary | 10.52 MiB | 10.52 MiB | 0 B (0.00%) |
vp (Linux x64) |
gzip -9 | 4.55 MiB | 4.55 MiB | +232 B (+0.00%) |
| NAPI (Linux x64) | Binary | 33.68 MiB | 33.68 MiB | 0 B (0.00%) |
| NAPI (Linux x64) | gzip -9 | 13.08 MiB | 13.08 MiB | +52 B (+0.00%) |
vp (macOS ARM64) |
Binary | 7.87 MiB | 7.87 MiB | 0 B (0.00%) |
vp (macOS ARM64) |
gzip -9 | 3.97 MiB | 3.97 MiB | +139 B (+0.00%) |
| NAPI (macOS ARM64) | Binary | 41.00 MiB | 41.00 MiB | 0 B (0.00%) |
| NAPI (macOS ARM64) | gzip -9 | 17.31 MiB | 17.31 MiB | +1.58 KiB (+0.01%) |
vp (Windows x64) |
Binary | 8.41 MiB | 8.41 MiB | 0 B (0.00%) |
vp (Windows x64) |
gzip -9 | 3.66 MiB | 3.66 MiB | +146 B (+0.00%) |
| NAPI (Windows x64) | Binary | 27.77 MiB | 27.77 MiB | 0 B (0.00%) |
| NAPI (Windows x64) | gzip -9 | 10.89 MiB | 10.89 MiB | +155 B (+0.00%) |
| Trampoline (Windows x64) | Binary | 205.00 KiB | 205.00 KiB | 0 B (0.00%) |
| Trampoline (Windows x64) | gzip -9 | 99.00 KiB | 99.00 KiB | +2 B (+0.00%) |
| Installer (Windows x64) | Binary | 4.45 MiB | 4.45 MiB | 0 B (0.00%) |
| Installer (Windows x64) | gzip -9 | 2.09 MiB | 2.09 MiB | -1 B (-0.00%) |
fengmk2
force-pushed
the
feat/npm-v12-compat
branch
from
August 7, 2026 15:15
25a2c53 to
b27de70
Compare
Member
Author
|
@codex review |
fengmk2
force-pushed
the
feat/npm-v12-compat
branch
from
August 9, 2026 08:18
b27de70 to
67527e5
Compare
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…-builds npm 12 skips dependency install scripts that the allowScripts field in package.json does not cover, and stops running scripts on approval: only npm rebuild executes previously skipped scripts. - Parse the npm 12 blocked-scripts install warning and surface gated direct dependencies in vp create like pnpm/bun/yarn, approving via vp pm approve-builds followed by vp pm rebuild - Version-gate the vp pm approve-builds npm note: npm >= 12 points at vp pm rebuild, npm 11.16 - 11.x keeps the advisory wording - Add the command_pm_approve_builds_npm12 PTY fixture (npm@12.0.2) and re-record the npm11 fixture for the reworded note - Document the npm 12 allowScripts flow and the allow-git/allow-remote resolution defaults in the create and install guides Closes #1823
fengmk2
force-pushed
the
feat/npm-v12-compat
branch
from
August 10, 2026 02:30
67527e5 to
883939b
Compare
fengmk2
marked this pull request as ready for review
August 10, 2026 02:34
wan9chi
approved these changes
Aug 10, 2026
Merged
fengmk2
added a commit
that referenced
this pull request
Aug 12, 2026
Release vite-plus v0.2.9: two new commands, and `vp run` now works in AI agent sandboxes. `vp toolchain` prints the tools, versions, and bundling relationships in the active release. `vp hooks` manages the Vite+ dispatcher for Git hooks, and removes the manual setup steps. `vp run` no longer fails in the default Codex CLI and Claude Code sandboxes. Those sandboxes deny Unix sockets and shared memory, which task IPC and file-access tracking used. The rest of the release makes the install path more reliable. It fixes npm 12 blocked install scripts, Yarn 2+ integrity pins, and baseline Bun builds for older CPUs. It also fixes downloads that stopped on slow connections. ### Highlights - New `vp toolchain` command. It prints the tools, versions, and bundling relationships in the active Vite+ release as a tree. The tree shows vite-plus, core, vite, rolldown, oxc, oxc-resolver, and the compiled Vite Task with its build time and revision. Give a tool name to select part of the tree. Use `--json` for machine-readable output. Use `--global` for the global release ([#2111](#2111)), by @fengmk2 - New `vp hooks` command. It manages the Vite+ dispatcher for Git hooks. `enable` installs or refreshes the dispatcher and sets `core.hooksPath`. `disable` removes the dispatcher and keeps that preference, so `prepare` and `vp config` do not install it again. `status` shows the current state. Use `--hooks-dir` to set a custom directory. Vite+ keeps that directory for later commands. Vite+ does not change project-owned hooks, `staged` config, or `package.json` lifecycle scripts ([#2341](#2341)), by @dennybiasiolli - `vp run` now works in the default Codex CLI and Claude Code sandboxes. Before this release, a cached task failed with `Failed to set up task communication: Operation not permitted`. The task code never started. Automatic file-access tracking also failed. Task caching and input tracking now work in both default profiles. You do not need extra sandbox permissions ([vite-task#569](voidzero-dev/vite-task#569), [vite-task#576](voidzero-dev/vite-task#576)), by @wan9chi ### Features - `vp create` now shows the dependencies whose install scripts npm 12 blocked. Before this release, Vite+ left those dependencies unbuilt and gave no message. To approve them, `vp create` runs `vp pm approve-builds` and then `vp pm rebuild` ([#2336](#2336)), by @fengmk2 - Large downloads no longer stop on slow connections. Node.js tarballs and package-manager tarballs now use a 10 minute timeout. Before this release, they used the shared 2 minute per-request limit. That limit stopped healthy downloads below approximately 250 KB/s. It also made `vp env install` and `vp migrate` impossible to complete. Set `VP_DOWNLOAD_TIMEOUT` to a different number of seconds ([#2386](#2386)), by @tarikermis - Package-manager downloads now show a byte progress bar. The managed Node.js runtime already showed one. A slow download no longer looks stopped ([#2369](#2369)), by @semimikoh - You can now select JetBrains editors (IntelliJ, WebStorm, and similar) in the editor setup question. Vite+ writes the Oxc plugin ID to `.idea/externalDependencies.xml`. The docs now describe the gitignore strategy for `.idea` ([#2204](#2204), [#2378](#2378)), by @KTrain5169 - `vp` now shows a warning when it falls back to the global CLI in a project that has no project-local `vite-plus`. If the project declares the dependency, `vp` tells you to run `vp install`. If the project does not declare it, `vp` points to the migration guide. `vp migrate` and commands outside a project stay silent ([#2362](#2362)), by @liangmiQwQ - Generated editor settings now disable nested Oxlint config resolution. The Vite+ config stays authoritative ([#2331](#2331)), by @liangmiQwQ > [!NOTE] > Upstream toolchain upgrade: vite `8.2.0` -> `8.2.1`, rolldown `1.2.2` -> `1.2.3`, oxlint `1.76.0` -> `1.77.0`, oxfmt `0.61.0` -> `0.62.0`, and the oxc npm packages and Rust crates `0.142.0` -> `0.143.0`. oxfmt and oxlint both changed. The new versions can report problems in code that passed before. If your CI runs `vp check`, run `vp fmt` after you upgrade ([#2373](#2373)), by @voidzero-guard[bot] ### Fixes & Enhancements - Yarn 2+ pins from `corepack use` now verify against the extracted CLI (`bin/yarn.js`), not the npm tarball. `vp install` no longer fails on a cold cache. `vp run` no longer downloads Yarn again on every run ([#2227](#2227)), by @leslieeilsel - `vp dev` no longer crashes at startup with `ENOENT` when `experimental.bundledDev` is enabled. The bundled dev client path now points to the packaged layout ([#2384](#2384)), by @lofcz - `vp migrate` now rejects a workspace member as its target. Before this release, it migrated the enclosing workspace instead. It now tells you to run the command from the workspace root ([#2229](#2229)), by @leslieeilsel - `VP_NODE_VERSION=22` and other partial versions now resolve to an exact Node.js release. This applies to shim-dispatched commands such as `vp env exec node -v` ([#2411](#2411)), by @jong-kyung - Managed `bunx` shims now dispatch through `bun x`. `bunx <package>` no longer starts a matching package script recursively. This applies to new Bun installations ([#2151](#2151)), by @liangmiQwQ - Managed Bun now selects the baseline build on x64 CPUs that do not have AVX2. Bun's standard builds require AVX2. Cached installations keep their current files ([#2179](#2179)), by @liangmiQwQ - Generated Nushell env files now escape and normalize paths correctly. A `VP_HOME` path that contains spaces or quotes now loads without an error ([#2191](#2191)), by @naokihaba - `vite-plus/test/browser-*` type exports now add `.js` extensions to relative shim specifiers. Those specifiers now resolve with `NodeNext` module resolution ([#2360](#2360)), by @eai04191 - Tool-backed help is now consistent with upstream. An exact `vp <command> --help` shows the local themed help. A command with more arguments (`vp test --help --coverage`, `vp test list --help`) goes to the bundled tool. Deep help and subcommand help stay complete ([#2345](#2345)), by @liangmiQwQ - Vite Task diagnostics now print paths and working directories without Rust debug formatting. Vite+ no longer prints quoted paths or escaped Windows backslashes ([vite-task#534](voidzero-dev/vite-task#534)), by @liangmiQwQ - Broad workspace globs no longer find and run package scripts inside `node_modules` ([vite-task#539](voidzero-dev/vite-task#539)), by @jong-kyung ### Refactor - Rename the internal Rust crates from `vite_*` to `vp_*` ([#2335](#2335)), by @fengmk2 - Move the shared CLI helpers into `utils` ([#2347](#2347)), by @jong-kyung - Remove a redundant Vite reporter patch from core ([#2355](#2355)), by @jong-kyung - Remove the duplicate export transformers in tools ([#2358](#2358)), by @jong-kyung - Move the accent helpers into `crate::help` ([#2363](#2363)), by @jong-kyung - Sort installed Node.js versions with node-semver ([#2366](#2366)), by @jong-kyung - Remove the duplicate package-manager command resolution tests ([#2393](#2393)), by @jong-kyung - Share the Vite config file order between the CLI code paths ([#2409](#2409)), by @jong-kyung - Use the silent spinner again in the migrators ([#2408](#2408)), by @jong-kyung ### Docs - Document how to write custom Oxlint plugins in the lint guide ([#2381](#2381)), by @connorshea - Document manual installation in the migrate guide ([#2365](#2365)), by @liangmiQwQ - Add a View Prompt dialog for the setup prompt ([#2400](#2400)), by @dennybiasiolli - Correct the documented `overrides` behavior to match Vite+ ([#1942](#1942)), by @liangmiQwQ - Explain `setup-vite-plus-action` version pinning in the CI guide ([#2359](#2359)), by @fengmk2 - Correct the config and staged paths in the CLI `BUNDLING.md` ([#2334](#2334)), by @dennybiasiolli - Remove unused performance data from the docs ([#2392](#2392)), by @jong-kyung - Add the v0.2.8 release learnings to the release-manager skill ([#2333](#2333)), by @fengmk2 ### Chore - Update the compiled Vite Task to `d05b1dc` ([#2339](#2339), [#2403](#2403)), by @wan9chi - Update the Rust nightly toolchain to `2026-08-02` ([#2342](#2342)), by @wan9chi - Update the repository pnpm to v11 ([#1997](#1997)), by @renovate[bot] - Remove the unused VitePress bundling from core ([#2332](#2332)), by @jong-kyung - Remove the unused tool subcommands ([#2324](#2324)), by @jong-kyung - Remove the unused `build:src` task ([#2396](#2396)), by @jong-kyung - Handle upstream help differences in the dependency upgrade workflow ([#2330](#2330)), by @liangmiQwQ - Publish preview builds from fork PRs with GitHub OIDC ([#2387](#2387)), by @fengmk2 - Require the preview publish approval only for fork PRs ([#2404](#2404)), by @fengmk2 - Correct the publishing workflow after its first real runs ([#2397](#2397)), by @fengmk2 - Deploy the production docs on release, and deploy a main preview on push ([#2389](#2389)), by @fengmk2 - Check the format of docs PRs with the `vp` built from the checkout ([#2388](#2388)), by @fengmk2 - Run the e2e migrate test at the clone root ([#2410](#2410)), by @fengmk2 - Pin the `dev_engines_runtime_pnpm11` snapshot to the seeded default Node version ([#2390](#2390)), by @fengmk2 - Use `pnpm test` again as the full gate ([#2376](#2376)), by @jong-kyung - Remove the global compile checks that did nothing ([#2394](#2394)), by @jong-kyung ### Bundled Versions | Tool | Version | Source | | --------------- | ---------- | ---------------------------------------------------------------------------- | | vite | `8.2.1` | [`4216158`](vitejs/vite@4216158) | | rolldown | `1.2.3` | [`52dbd19`](rolldown/rolldown@52dbd19) | | tsdown | `0.22.14` | [npm](https://npmx.dev/package/tsdown/v/0.22.14) | | vitest | `4.1.10` | [npm](https://npmx.dev/package/vitest/v/4.1.10) | | oxlint | `1.77.0` | [npm](https://npmx.dev/package/oxlint/v/1.77.0) | | oxlint-tsgolint | `7.0.2001` | [npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) | | oxfmt | `0.62.0` | [npm](https://npmx.dev/package/oxfmt/v/0.62.0) | ### Upgrade ```bash vp upgrade ``` ### New Contributors @eai04191, @KTrain5169, @lofcz, @tarikermis, @leslieeilsel **Full Changelog**: v0.2.8...v0.2.9 --- Merging this PR will trigger the release workflow. --------- Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com> Co-authored-by: MK <fengmk2@gmail.com>
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
npm 12 (now
latest) skips dependency install scripts that theallowScriptsfield in package.json does not cover; the install succeeds with a warning. Approval only records the allowlist: a reinstall short-circuits on the up-to-date tree, and onlynpm rebuildexecutes previously skipped scripts. npm 12 also stops resolving git and remote tarball dependencies by default (EALLOWGIT/EALLOWREMOTE).vp treated npm as "runs scripts by default", so
vp createwith npm 12 left native direct dependencies silently unbuilt. This PR:parseNpmBlockedScripts) and surfaces gated direct dependencies invp createlike pnpm/bun/yarn; approval runsvp pm approve-builds <pkg>thenvp pm rebuild <pkg>, and retry hints point at rebuild instead of reinstallvp pm approve-buildsnpm note: npm >= 12 explains the approve-then-rebuild two-step, npm 11.16 - 11.x keeps the advisory wording (allowlist recorded, scripts still run), denials get no notecommand_pm_approve_builds_npm12PTY fixture recorded against real npm 12.0.2 and re-records the npm11 fixture for the reworded noteallow-git/allow-remotedefaultsThe npm 11.x wording ("not yet covered") is deliberately not parsed: those versions still run scripts, so there is nothing to fix up.
Verified end-to-end against npm 12.0.2: install of a project with a gated direct dep detects it, auto-approval writes
allowScriptsand the rebuild runs its postinstall. 54 TS unit tests and 34 Rust tests pass; all three npm approve-builds snapshot fixtures pass.Audited but left as follow-ups:
vp install -ghas no--allow-scriptsplumbing (vp's own global installs have no scripts),vp migratepreserves git/remote specs that now fail under npm 12, and migrate installs do not surface gated builds (pre-existing, also true for pnpm).Closes #1823