Skip to content

[defer] feat(release): bun-pack — bun-first global installs (build stays on Node) - #12801

Open
opensource-elearning wants to merge 3 commits into
diegosouzapw:release/v3.8.52from
opensource-elearning:feat/bun-pack-release
Open

opensource-elearning wants to merge 3 commits into
diegosouzapw:release/v3.8.52from
opensource-elearning:feat/bun-pack-release

Conversation

@opensource-elearning

Copy link
Copy Markdown
Contributor

⚠️ base-red inherited: #12732 (base tip is red; unrelated to this PR)

What

Adds a bun-first companion to the npm release path so users can install
omniroute globally with bun, without changing how the package is built or
published.

  • scripts/release/bun-pack.mjs — release pack script, Bun-first:
    • default --pm bun → bun run build:release (bun orchestrates, Node runs
      the actual next build and the dist assembly), then bun pm pack into a
      universal npm tarball.
    • --pm npm fallback → same flow via npm (works on machines without bun).
    • --skip-build reuses a staged dist/.
    • cross-platform: no shell string interpolation (paths/env travel as spawn
      options), bun >=1.1, node >=22.
  • package.json → bun:release script ( bun scripts/release/bun-pack.mjs ).
  • README.md → Bun (global) row in the install table.

Why

bun pm pack and npm pack produce the same universal npm tarball format, so
a bun-packed artifact installs with both bun add -g <tarball> and
npm install -g <tarball>. Bun is measurably faster on installs and lighter on
memory, and bun install -g omniroute is already a supported path (the
best-effort bun:sqlite adapter lets it boot without better-sqlite3). The
npm publish channel (npm-publish.yml, verify-published.mjs) is unchanged —
this is strictly additive: bun is only packer + install path, never the build
or the published runtime (AGENTS.md scope guard).

Verification

  • Fresh production release build of 3.8.51 (webpack, OMNIROUTE_BUILD_MEMORY_MB
    heap cap) completed green in an isolated worktree.
  • Packed with both --pm bun and --pm npm: same tarball, 4168 tracked
    dist/ entries verified in each, bin/omniroute.mjs,
    bin/reset-password.mjs, and package.json present.
  • Output: _artifacts/omniroute-3.8.51.tgz (~73 MB).
bun run bun:release            # build + pack (Bun, default)
bun run bun:release -- --pm npm  # npm fallback
node scripts/release/bun-pack.mjs --skip-build --destination .  # reuse staged dist

bun pm pack produces the same universal npm tarball npm pack does, so a
bun-packed artifact installs with both 'bun add -g' and 'npm install -g'.
Add scripts/release/bun-pack.mjs (--pm bun|npm, --skip-build,
--destination) plus the bun:release npm script, and a Bun row in the
README install table. The next build and dist assembly stay on Node;
Bun handles the build orchestration, packing, and the end-user install.
@diegosouzapw

Copy link
Copy Markdown
Owner

Nice, and careful about the Bun-scope boundary — verified that bun run build:release
still shells out to literal npm run build / npm run build:cli internally, so the actual
Next build and prepublish step stay on Node as intended; only the packer/orchestrator is
Bun-first. No shell-interpolation issues either (spawnSync with array args throughout).
One gap: there's no unit test for the script's own logic (arg parsing, tarball verification).
Could you extract parseArgs/verifyTarball so they're testable without needing a real build,
and add a small test file? Everything else looks solid.

@diegosouzapw

Copy link
Copy Markdown
Owner

Follow-up on the one pre-merge item left here (a unit test for parseArgs/verifyTarball, Hard
Rule #8): we run a maintainer fix-sweep that pushes small pre-merge fixes straight into the
contributor's branch (authored by you, with a Co-authored-by for the maintainer), but this fork
has "Allow edits by maintainers" unchecked, so we can't land it for you.

Two ways forward, whichever you prefer:

  1. Tick "Allow edits by maintainers" in the PR sidebar and reply here — we'll push the test
    ourselves (extracting parseArgs/verifyTarball so they're importable without running a real
    build) and nothing else.
  2. Push it yourself: a tests/unit/ file that imports those two functions directly and covers the
    arg parsing plus a tampered/short tarball rejection. No need to exercise a real npm pack.

Everything else on this PR came out clean in review (⭐4) — the Bun-scope boundary is respected
(build:release still shells out to npm run build*), so this is the last thing between it and
the merge queue.

@opensource-elearning

Copy link
Copy Markdown
Contributor Author

done, try now

Extract the two pure pieces of logic in scripts/release/bun-pack.mjs so
they are importable and testable without running a real build: parseArgs
and verifyTarball now throw UsageError on bad input instead of calling
fail()/process.exit directly, and the top-level script body is wrapped in
main() behind a direct-run guard (import.meta.url check) that still
translates a UsageError into the same fail() CLI output as before -
verified manually that --pm bogus / --skip-build without dist/ / an
unknown flag print identical messages and exit codes to pre-change
behavior.

Adds tests/unit/bun-pack.test.ts (node:test) covering parseArgs flag
parsing, defaults and bad input, and verifyTarball against real tarballs
built in a temp dir (good tarball, missing/corrupted tarball, missing
required bin entry, empty dist/) - satisfies Hard Rule diegosouzapw#8 for this PR's
production code.

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
@diegosouzapw diegosouzapw added the deferred-v3.8.52 Grande demais / suspeito para o lote atual; precisa de sessão dedicada no ciclo v3.8.52 label Sep 25, 2026
@diegosouzapw diegosouzapw changed the title feat(release): bun-pack — bun-first global installs (build stays on Node) [defer] feat(release): bun-pack — bun-first global installs (build stays on Node) Sep 25, 2026
@diegosouzapw
diegosouzapw changed the base branch from release/v3.8.51 to release/v3.8.52 September 29, 2026 11:27
@diegosouzapw

Copy link
Copy Markdown
Owner

Re-homed to release/v3.8.52: v3.8.51 entered its release freeze, so the branch now belongs to the release captain and development continues on the next cycle. Nothing is wrong with this PR — it just needed a live base. No action needed from you; CI will re-run against the new base.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deferred-v3.8.52 Grande demais / suspeito para o lote atual; precisa de sessão dedicada no ciclo v3.8.52

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants