Skip to content

Commit 709601b

Browse files
AsiaOstrichclaude
andcommitted
fix(ci): declare allowScripts in package.json instead of imperative CI step
npm approve-scripts writes a persistent, version-pinned allowScripts entry into package.json rather than just approving for one run — so the correct fix is to commit that declaration (covering ryugraph, tree-sitter*, and esbuild, the package's actual native/build-tool deps with install scripts) rather than run an imperative `npm approve-scripts` step in CI. A plain `npm install` now picks it up with no extra step. Verified locally in Docker (node:24-trixie, linux/amd64 — matching ubuntu-latest's Ubuntu 24.04 glibc, not node:24's Debian 12 bookworm default): install/build/typecheck succeed cleanly; 5 structural-memory L3 tests (god-nodes/communities) timed out waiting on ryugraph's algo extension download, matching a known sandboxed-network limitation of this nested container (extension.ryugraph.io unreachable) — the same suite passed 81/81 on the real dev machine (normal internet) earlier today, so this is not expected to reproduce on GitHub's actual runners. npm approve-scripts 會把核准結果寫成 package.json 裡持久化、版本綁定的 allowScripts 項目,不只是核准當次執行——所以正確做法是直接 commit 這個宣告 (涵蓋 ryugraph、tree-sitter*、esbuild,這個套件實際會跑 install script 的 原生/建置工具依賴),而非在 CI 裡跑一次性的 `npm approve-scripts` 指令。 現在單純的 `npm install` 就會自動套用,不需要額外步驟。 已在本機 Docker 驗證(node:24-trixie,linux/amd64——對應 ubuntu-latest 實際 是 Ubuntu 24.04 的 glibc,而非 node:24 預設的 Debian 12 bookworm): install/build/typecheck 全部乾淨通過;5 個 structural-memory L3 測試 (god-nodes/communities)在等待 ryugraph 的 algo 擴充下載時逾時,符合這個 巢狀容器已知的網路受限現況(連不到 extension.ryugraph.io)——同一套測試 今天稍早在真實開發機(正常網路)跑過 81/81 全過,預期不會在 GitHub 真正 的 runner 上重現。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
1 parent 6cd70e6 commit 709601b

2 files changed

Lines changed: 17 additions & 13 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 10 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -34,20 +34,17 @@ jobs:
3434
- run: npm install -g npm@latest
3535
- run: npm --version
3636

37-
- run: npm install --legacy-peer-deps
38-
3937
# npm >= 11 gates native install scripts behind an approval list by
40-
# default — `npm install` alone silently skips them, leaving native
41-
# bindings / generated type declarations missing (this broke this
42-
# exact workflow on 2026-07-10 once `npm install -g npm@latest` above
43-
# started pulling npm 11.x: DTS build failed with "Cannot find module
44-
# 'ryugraph'"). Approve only this package's known direct native
45-
# dependencies by name (not `--all`, to avoid silently trusting any
46-
# future dependency's install script in this OIDC-publish-privileged
47-
# job) and rebuild to force them to actually run; `|| true` keeps
48-
# this a no-op on older npm that lacks the subcommand entirely.
49-
- run: npm approve-scripts ryugraph tree-sitter tree-sitter-javascript tree-sitter-typescript || true
50-
- run: npm rebuild || true
38+
# default (this broke this exact workflow on 2026-07-10 once `npm
39+
# install -g npm@latest` above started pulling npm 11.x: DTS build
40+
# failed with "Cannot find module 'ryugraph'", because ryugraph's own
41+
# install step — which copies its native binary into place — never
42+
# ran). The fix lives in package.json's `allowScripts` field
43+
# (declarative, version-pinned pre-approval for this repo's known
44+
# native deps: ryugraph/tree-sitter*/esbuild) rather than an
45+
# imperative `--all` here, so a plain install picks it up with no
46+
# extra step and no silent trust extended to future dependencies.
47+
- run: npm install --legacy-peer-deps
5148

5249
# Build + verify before publishing (native: kuzu + tree-sitter compile here).
5350
- run: npm run build

‎package.json‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,5 +73,12 @@
7373
"tsup": "^8.0.0",
7474
"typescript": "^5.6.0",
7575
"vitest": "^4.0.0"
76+
},
77+
"allowScripts": {
78+
"ryugraph@25.9.1": true,
79+
"tree-sitter@0.22.4": true,
80+
"tree-sitter-javascript@0.23.1": true,
81+
"tree-sitter-typescript@0.23.2": true,
82+
"esbuild@0.27.7": true
7683
}
7784
}

0 commit comments

Comments
 (0)