Skip to content

fix(cli): ship scripts/build/runtime-env.mjs in npm package (#5227) - #5230

Merged
diegosouzapw merged 1 commit into
release/v3.8.40from
fix/5227-pack-runtime-env
Jun 28, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.40from
fix/5227-pack-runtime-env

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Closes #5227

Problem

The v3.8.39 heap auto-calibration fix (#5213) made bin/cli/commands/serve.mjs import scripts/build/runtime-env.mjs, but that file was never added to the files whitelist in package.json. The published npm tarball therefore shipped the importing CLI without the imported module, so every npm install -g omniroute failed at startup:

✖ Cannot find module '.../omniroute/scripts/build/runtime-env.mjs' imported from '.../omniroute/bin/cli/commands/serve.mjs'

Confirmed on macOS (#5227, @PriyomSaha), and reproduced by @m-Yaghoubi and @jonlwheat2-gif (Windows 10).

Fix

  • Add scripts/build/runtime-env.mjs to the files whitelist in package.json (the other two bin/→scripts/ runtime imports — native-binary-compat.mjs, postinstallSupport.mjs — were already whitelisted; only the new one was missing). npm pack --dry-run now confirms the file ships.

Regression test (TDD)

tests/unit/cli-runtime-imports-packaged-5227.test.ts scans every bin/** entrypoint for static/dynamic imports resolving under scripts/ and asserts each resolved path is covered by the package files whitelist. Fails on the unfixed tree (runtime-env.mjs uncovered) and passes after the whitelist entry — and guards against any future unpackaged bin/→scripts/ import failing users' installs instead of CI.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds the missing 'scripts/build/runtime-env.mjs' script to the package.json 'files' whitelist and introduces a regression test to ensure all scripts imported by CLI entrypoints are packaged. The reviewer suggested improving the test's regex scanner by stripping comments from the source files first to avoid false positives from commented-out imports.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment on lines +38 to +41
const src = readFileSync(binFile, "utf8");
const specifiers = new Set<string>();
// static: from "..." dynamic: import("...")
const re = /(?:from|import)\s*\(?\s*["']([^"']+)["']/g;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The current regex-based import scanner can match commented-out imports (e.g., // import ...), which may lead to false-positive test failures if a developer comments out an import during debugging or refactoring. Stripping single-line and multi-line comments from the source code before running the regex will make the test more robust.

Suggested change
const src = readFileSync(binFile, "utf8");
const specifiers = new Set<string>();
// static: from "..." dynamic: import("...")
const re = /(?:from|import)\s*\(?\s*["']([^"']+)["']/g;
const rawSrc = readFileSync(binFile, "utf8");
const src = rawSrc.replace(/\/\*[\s\S]*?\*\/|\/\/.*$/gm, '');
const specifiers = new Set<string>();
// static: from "..." dynamic: import("...")
const re = /(?:from|import)\s*\(?\s*["']([^"']+)["']/g;

serve.mjs imports scripts/build/runtime-env.mjs (added with the #5213 heap
auto-calibration fix) but it was missing from package.json files whitelist,
breaking every global npm install at startup. Add it to files and guard with
a regression test that asserts all bin/ runtime imports of scripts/ are
packaged.
@diegosouzapw
diegosouzapw force-pushed the fix/5227-pack-runtime-env branch from e631672 to fbd1f91 Compare June 28, 2026 15:31
@diegosouzapw
diegosouzapw merged commit 6143ffc into release/v3.8.40 Jun 28, 2026
7 checks passed
@diegosouzapw
diegosouzapw deleted the fix/5227-pack-runtime-env branch June 28, 2026 16:03
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…zapw#5227) (diegosouzapw#5230)

serve.mjs imports scripts/build/runtime-env.mjs (added with the diegosouzapw#5213 heap
auto-calibration fix) but it was missing from package.json files whitelist,
breaking every global npm install at startup. Add it to files and guard with
a regression test that asserts all bin/ runtime imports of scripts/ are
packaged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant