Skip to content

feat(pm): handle npm 12 blocked install scripts in create and approve-builds - #2336

Merged
fengmk2 merged 2 commits into
mainfrom
feat/npm-v12-compat
Aug 10, 2026
Merged

feat(pm): handle npm 12 blocked install scripts in create and approve-builds#2336
fengmk2 merged 2 commits into
mainfrom
feat/npm-v12-compat

Conversation

@fengmk2

@fengmk2 fengmk2 commented Aug 5, 2026

Copy link
Copy Markdown
Member

npm 12 (now latest) skips dependency install scripts that the allowScripts field in package.json does not cover; the install succeeds with a warning. Approval only records the allowlist: a reinstall short-circuits on the up-to-date tree, and only npm rebuild executes previously skipped scripts. npm 12 also stops resolving git and remote tarball dependencies by default (EALLOWGIT / EALLOWREMOTE).

vp treated npm as "runs scripts by default", so vp create with npm 12 left native direct dependencies silently unbuilt. This PR:

  • parses the npm 12 blocked-scripts install warning (parseNpmBlockedScripts) and surfaces gated direct dependencies in vp create like pnpm/bun/yarn; approval runs vp pm approve-builds <pkg> then vp pm rebuild <pkg>, and retry hints point at rebuild instead of reinstall
  • version-gates the vp pm approve-builds npm note: npm >= 12 explains the approve-then-rebuild two-step, npm 11.16 - 11.x keeps the advisory wording (allowlist recorded, scripts still run), denials get no note
  • adds the command_pm_approve_builds_npm12 PTY fixture recorded against real npm 12.0.2 and re-records the npm11 fixture for the reworded note
  • updates the create and install guides: npm joins the gated-scripts package managers, new "Dependency build scripts (npm v12+)" section, and a note on the allow-git / allow-remote defaults

The npm 11.x wording ("not yet covered") is deliberately not parsed: those versions still run scripts, so there is nothing to fix up.

Verified end-to-end against npm 12.0.2: install of a project with a gated direct dep detects it, auto-approval writes allowScripts and the rebuild runs its postinstall. 54 TS unit tests and 34 Rust tests pass; all three npm approve-builds snapshot fixtures pass.

Audited but left as follow-ups: vp install -g has no --allow-scripts plumbing (vp's own global installs have no scripts), vp migrate preserves git/remote specs that now fail under npm 12, and migrate installs do not surface gated builds (pre-existing, also true for pnpm).

Closes #1823

@netlify

netlify Bot commented Aug 5, 2026

Copy link
Copy Markdown

Deploy Preview for viteplus-preview canceled.

Name Link
🔨 Latest commit d322477
🔍 Latest deploy log https://app.netlify.com/projects/viteplus-preview/deploys/6a7949fdefa6960008e9d0e6

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

✅ Staging deployment successful!

Preview: https://viteplus-staging.void.app/
Commit: d322477

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Native binary sizes (d322477)

Final release artifacts built by the canonical build-upstream and build-windows-cli actions.

Artifact Format Base PR Change
vp (Linux x64) Binary 10.52 MiB 10.52 MiB 0 B (0.00%)
vp (Linux x64) gzip -9 4.55 MiB 4.55 MiB +232 B (+0.00%)
NAPI (Linux x64) Binary 33.68 MiB 33.68 MiB 0 B (0.00%)
NAPI (Linux x64) gzip -9 13.08 MiB 13.08 MiB +52 B (+0.00%)
vp (macOS ARM64) Binary 7.87 MiB 7.87 MiB 0 B (0.00%)
vp (macOS ARM64) gzip -9 3.97 MiB 3.97 MiB +139 B (+0.00%)
NAPI (macOS ARM64) Binary 41.00 MiB 41.00 MiB 0 B (0.00%)
NAPI (macOS ARM64) gzip -9 17.31 MiB 17.31 MiB +1.58 KiB (+0.01%)
vp (Windows x64) Binary 8.41 MiB 8.41 MiB 0 B (0.00%)
vp (Windows x64) gzip -9 3.66 MiB 3.66 MiB +146 B (+0.00%)
NAPI (Windows x64) Binary 27.77 MiB 27.77 MiB 0 B (0.00%)
NAPI (Windows x64) gzip -9 10.89 MiB 10.89 MiB +155 B (+0.00%)
Trampoline (Windows x64) Binary 205.00 KiB 205.00 KiB 0 B (0.00%)
Trampoline (Windows x64) gzip -9 99.00 KiB 99.00 KiB +2 B (+0.00%)
Installer (Windows x64) Binary 4.45 MiB 4.45 MiB 0 B (0.00%)
Installer (Windows x64) gzip -9 2.09 MiB 2.09 MiB -1 B (-0.00%)

@fengmk2 fengmk2 self-assigned this Aug 7, 2026
@fengmk2
fengmk2 force-pushed the feat/npm-v12-compat branch from 25a2c53 to b27de70 Compare August 7, 2026 15:15
@fengmk2

fengmk2 commented Aug 9, 2026

Copy link
Copy Markdown
Member Author

@codex review

@fengmk2
fengmk2 force-pushed the feat/npm-v12-compat branch from b27de70 to 67527e5 Compare August 9, 2026 08:18
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

Reviewed commit: b27de706a8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…-builds

npm 12 skips dependency install scripts that the allowScripts field in
package.json does not cover, and stops running scripts on approval: only
npm rebuild executes previously skipped scripts.

- Parse the npm 12 blocked-scripts install warning and surface gated
  direct dependencies in vp create like pnpm/bun/yarn, approving via
  vp pm approve-builds followed by vp pm rebuild
- Version-gate the vp pm approve-builds npm note: npm >= 12 points at
  vp pm rebuild, npm 11.16 - 11.x keeps the advisory wording
- Add the command_pm_approve_builds_npm12 PTY fixture (npm@12.0.2) and
  re-record the npm11 fixture for the reworded note
- Document the npm 12 allowScripts flow and the allow-git/allow-remote
  resolution defaults in the create and install guides

Closes #1823
@fengmk2
fengmk2 force-pushed the feat/npm-v12-compat branch from 67527e5 to 883939b Compare August 10, 2026 02:30
@fengmk2
fengmk2 marked this pull request as ready for review August 10, 2026 02:34
@fengmk2
fengmk2 requested review from cpojer and wan9chi August 10, 2026 02:34
@fengmk2
fengmk2 merged commit 6ae7ec7 into main Aug 10, 2026
79 checks passed
@fengmk2
fengmk2 deleted the feat/npm-v12-compat branch August 10, 2026 04:03
@fengmk2 fengmk2 mentioned this pull request Aug 11, 2026
fengmk2 added a commit that referenced this pull request Aug 12, 2026
Release vite-plus v0.2.9: two new commands, and `vp run` now works in AI
agent sandboxes.

`vp toolchain` prints the tools, versions, and bundling relationships in
the active release. `vp hooks` manages the Vite+ dispatcher for Git
hooks, and removes the manual setup steps. `vp run` no longer fails in
the default Codex CLI and Claude Code sandboxes. Those sandboxes deny
Unix sockets and shared memory, which task IPC and file-access tracking
used. The rest of the release makes the install path more reliable. It
fixes npm 12 blocked install scripts, Yarn 2+ integrity pins, and
baseline Bun builds for older CPUs. It also fixes downloads that stopped
on slow connections.

### Highlights

- New `vp toolchain` command. It prints the tools, versions, and
bundling relationships in the active Vite+ release as a tree. The tree
shows vite-plus, core, vite, rolldown, oxc, oxc-resolver, and the
compiled Vite Task with its build time and revision. Give a tool name to
select part of the tree. Use `--json` for machine-readable output. Use
`--global` for the global release
([#2111](#2111)), by
@fengmk2
- New `vp hooks` command. It manages the Vite+ dispatcher for Git hooks.
`enable` installs or refreshes the dispatcher and sets `core.hooksPath`.
`disable` removes the dispatcher and keeps that preference, so `prepare`
and `vp config` do not install it again. `status` shows the current
state. Use `--hooks-dir` to set a custom directory. Vite+ keeps that
directory for later commands. Vite+ does not change project-owned hooks,
`staged` config, or `package.json` lifecycle scripts
([#2341](#2341)), by
@dennybiasiolli
- `vp run` now works in the default Codex CLI and Claude Code sandboxes.
Before this release, a cached task failed with `Failed to set up task
communication: Operation not permitted`. The task code never started.
Automatic file-access tracking also failed. Task caching and input
tracking now work in both default profiles. You do not need extra
sandbox permissions
([vite-task#569](voidzero-dev/vite-task#569),
[vite-task#576](voidzero-dev/vite-task#576)), by
@wan9chi

### Features

- `vp create` now shows the dependencies whose install scripts npm 12
blocked. Before this release, Vite+ left those dependencies unbuilt and
gave no message. To approve them, `vp create` runs `vp pm
approve-builds` and then `vp pm rebuild`
([#2336](#2336)), by
@fengmk2
- Large downloads no longer stop on slow connections. Node.js tarballs
and package-manager tarballs now use a 10 minute timeout. Before this
release, they used the shared 2 minute per-request limit. That limit
stopped healthy downloads below approximately 250 KB/s. It also made `vp
env install` and `vp migrate` impossible to complete. Set
`VP_DOWNLOAD_TIMEOUT` to a different number of seconds
([#2386](#2386)), by
@tarikermis
- Package-manager downloads now show a byte progress bar. The managed
Node.js runtime already showed one. A slow download no longer looks
stopped ([#2369](#2369)),
by @semimikoh
- You can now select JetBrains editors (IntelliJ, WebStorm, and similar)
in the editor setup question. Vite+ writes the Oxc plugin ID to
`.idea/externalDependencies.xml`. The docs now describe the gitignore
strategy for `.idea`
([#2204](#2204),
[#2378](#2378)), by
@KTrain5169
- `vp` now shows a warning when it falls back to the global CLI in a
project that has no project-local `vite-plus`. If the project declares
the dependency, `vp` tells you to run `vp install`. If the project does
not declare it, `vp` points to the migration guide. `vp migrate` and
commands outside a project stay silent
([#2362](#2362)), by
@liangmiQwQ
- Generated editor settings now disable nested Oxlint config resolution.
The Vite+ config stays authoritative
([#2331](#2331)), by
@liangmiQwQ

> [!NOTE]
> Upstream toolchain upgrade: vite `8.2.0` -> `8.2.1`, rolldown `1.2.2`
-> `1.2.3`, oxlint `1.76.0` -> `1.77.0`, oxfmt `0.61.0` -> `0.62.0`, and
the oxc npm packages and Rust crates `0.142.0` -> `0.143.0`. oxfmt and
oxlint both changed. The new versions can report problems in code that
passed before. If your CI runs `vp check`, run `vp fmt` after you
upgrade ([#2373](#2373)),
by @voidzero-guard[bot]

### Fixes & Enhancements

- Yarn 2+ pins from `corepack use` now verify against the extracted CLI
(`bin/yarn.js`), not the npm tarball. `vp install` no longer fails on a
cold cache. `vp run` no longer downloads Yarn again on every run
([#2227](#2227)), by
@leslieeilsel
- `vp dev` no longer crashes at startup with `ENOENT` when
`experimental.bundledDev` is enabled. The bundled dev client path now
points to the packaged layout
([#2384](#2384)), by
@lofcz
- `vp migrate` now rejects a workspace member as its target. Before this
release, it migrated the enclosing workspace instead. It now tells you
to run the command from the workspace root
([#2229](#2229)), by
@leslieeilsel
- `VP_NODE_VERSION=22` and other partial versions now resolve to an
exact Node.js release. This applies to shim-dispatched commands such as
`vp env exec node -v`
([#2411](#2411)), by
@jong-kyung
- Managed `bunx` shims now dispatch through `bun x`. `bunx <package>` no
longer starts a matching package script recursively. This applies to new
Bun installations
([#2151](#2151)), by
@liangmiQwQ
- Managed Bun now selects the baseline build on x64 CPUs that do not
have AVX2. Bun's standard builds require AVX2. Cached installations keep
their current files
([#2179](#2179)), by
@liangmiQwQ
- Generated Nushell env files now escape and normalize paths correctly.
A `VP_HOME` path that contains spaces or quotes now loads without an
error ([#2191](#2191)), by
@naokihaba
- `vite-plus/test/browser-*` type exports now add `.js` extensions to
relative shim specifiers. Those specifiers now resolve with `NodeNext`
module resolution
([#2360](#2360)), by
@eai04191
- Tool-backed help is now consistent with upstream. An exact `vp
<command> --help` shows the local themed help. A command with more
arguments (`vp test --help --coverage`, `vp test list --help`) goes to
the bundled tool. Deep help and subcommand help stay complete
([#2345](#2345)), by
@liangmiQwQ
- Vite Task diagnostics now print paths and working directories without
Rust debug formatting. Vite+ no longer prints quoted paths or escaped
Windows backslashes
([vite-task#534](voidzero-dev/vite-task#534)),
by @liangmiQwQ
- Broad workspace globs no longer find and run package scripts inside
`node_modules`
([vite-task#539](voidzero-dev/vite-task#539)),
by @jong-kyung

### Refactor

- Rename the internal Rust crates from `vite_*` to `vp_*`
([#2335](#2335)), by
@fengmk2
- Move the shared CLI helpers into `utils`
([#2347](#2347)), by
@jong-kyung
- Remove a redundant Vite reporter patch from core
([#2355](#2355)), by
@jong-kyung
- Remove the duplicate export transformers in tools
([#2358](#2358)), by
@jong-kyung
- Move the accent helpers into `crate::help`
([#2363](#2363)), by
@jong-kyung
- Sort installed Node.js versions with node-semver
([#2366](#2366)), by
@jong-kyung
- Remove the duplicate package-manager command resolution tests
([#2393](#2393)), by
@jong-kyung
- Share the Vite config file order between the CLI code paths
([#2409](#2409)), by
@jong-kyung
- Use the silent spinner again in the migrators
([#2408](#2408)), by
@jong-kyung

### Docs

- Document how to write custom Oxlint plugins in the lint guide
([#2381](#2381)), by
@connorshea
- Document manual installation in the migrate guide
([#2365](#2365)), by
@liangmiQwQ
- Add a View Prompt dialog for the setup prompt
([#2400](#2400)), by
@dennybiasiolli
- Correct the documented `overrides` behavior to match Vite+
([#1942](#1942)), by
@liangmiQwQ
- Explain `setup-vite-plus-action` version pinning in the CI guide
([#2359](#2359)), by
@fengmk2
- Correct the config and staged paths in the CLI `BUNDLING.md`
([#2334](#2334)), by
@dennybiasiolli
- Remove unused performance data from the docs
([#2392](#2392)), by
@jong-kyung
- Add the v0.2.8 release learnings to the release-manager skill
([#2333](#2333)), by
@fengmk2

### Chore

- Update the compiled Vite Task to `d05b1dc`
([#2339](#2339),
[#2403](#2403)), by
@wan9chi
- Update the Rust nightly toolchain to `2026-08-02`
([#2342](#2342)), by
@wan9chi
- Update the repository pnpm to v11
([#1997](#1997)), by
@renovate[bot]
- Remove the unused VitePress bundling from core
([#2332](#2332)), by
@jong-kyung
- Remove the unused tool subcommands
([#2324](#2324)), by
@jong-kyung
- Remove the unused `build:src` task
([#2396](#2396)), by
@jong-kyung
- Handle upstream help differences in the dependency upgrade workflow
([#2330](#2330)), by
@liangmiQwQ
- Publish preview builds from fork PRs with GitHub OIDC
([#2387](#2387)), by
@fengmk2
- Require the preview publish approval only for fork PRs
([#2404](#2404)), by
@fengmk2
- Correct the publishing workflow after its first real runs
([#2397](#2397)), by
@fengmk2
- Deploy the production docs on release, and deploy a main preview on
push ([#2389](#2389)), by
@fengmk2
- Check the format of docs PRs with the `vp` built from the checkout
([#2388](#2388)), by
@fengmk2
- Run the e2e migrate test at the clone root
([#2410](#2410)), by
@fengmk2
- Pin the `dev_engines_runtime_pnpm11` snapshot to the seeded default
Node version
([#2390](#2390)), by
@fengmk2
- Use `pnpm test` again as the full gate
([#2376](#2376)), by
@jong-kyung
- Remove the global compile checks that did nothing
([#2394](#2394)), by
@jong-kyung

### Bundled Versions

| Tool | Version | Source |
| --------------- | ---------- |
----------------------------------------------------------------------------
|
| vite | `8.2.1` |
[`4216158`](vitejs/vite@4216158)
|
| rolldown | `1.2.3` |
[`52dbd19`](rolldown/rolldown@52dbd19)
|
| tsdown | `0.22.14` | [npm](https://npmx.dev/package/tsdown/v/0.22.14)
|
| vitest | `4.1.10` | [npm](https://npmx.dev/package/vitest/v/4.1.10) |
| oxlint | `1.77.0` | [npm](https://npmx.dev/package/oxlint/v/1.77.0) |
| oxlint-tsgolint | `7.0.2001` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) |
| oxfmt | `0.62.0` | [npm](https://npmx.dev/package/oxfmt/v/0.62.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@eai04191, @KTrain5169, @lofcz, @tarikermis, @leslieeilsel

**Full Changelog**:
v0.2.8...v0.2.9

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Track npm v12 compatibility

2 participants