Skip to content

fix(package): resolve consumer bundling errors for server adapters - #837

Merged
murdore merged 1 commit into
juspay:releasefrom
YaswanthKurapati24:BZ-48849-move-the-packages-from-dev-dependencies-to-dependencies-being-used-in-source-code
Feb 24, 2026
Merged

murdore merged 1 commit into
juspay:releasefrom
YaswanthKurapati24:BZ-48849-move-the-packages-from-dev-dependencies-to-dependencies-being-used-in-source-code

Conversation

@YaswanthKurapati24

@YaswanthKurapati24 YaswanthKurapati24 commented Feb 24, 2026 •

Copy link
Copy Markdown
Contributor
  • Two-part fix for Vite/Rollup "failed to resolve import" errors:
  1. Fix TypeScript type leak: Changed getFrameworkInstance() return type from framework-specific types (FastifyInstance, Express, Hono) to 'unknown' in all server adapters. Prevents TypeScript from emitting framework type imports in .d.ts files.

  2. Move to optionalDependencies: Moved server frameworks from devDependencies to optionalDependencies (fastify, @fastify/cors, @fastify/rate-limit, koa, koa-bodyparser, @koa/cors, @koa/router, express, cors, express-rate-limit).

This allows Vite/Rollup to resolve framework imports without forcing installation for consumers who don't use server features.

Pull Request

Description

What does this PR do?

A clear and concise description of the changes in this pull request.

Related Issues

Does this PR close any issues?

Fixes #(issue number)
Closes #(issue number)
Relates to #(issue number)

Type of Change

Please select the type of change:

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Refactoring (no functional changes)
  • Performance improvement
  • Test coverage improvement
  • Build/CI configuration
  • Other (please describe):

Motivation and Context

Why is this change needed? What problem does it solve?

Provide context for reviewers:

  • Background information
  • Use case or scenario
  • Links to relevant discussions or documentation
  • Screenshots/GIFs (if UI-related)

Changes Made

What specific changes were made?

Provide a bullet-point list of the key changes:

  • Added X functionality to Y component
  • Modified Z behavior to handle edge case A
  • Updated documentation in file B
  • Refactored C for better performance

Breaking Changes

Does this PR introduce breaking changes?

  • No breaking changes
  • Yes, breaking changes (describe below)

If yes, describe:

  • What breaks?
  • Migration path for users
  • Deprecation warnings added?

Testing

How has this been tested?

Please describe the tests you ran and their results:

  • Unit tests added/updated
  • Integration tests added/updated
  • E2E tests pass
  • Manual testing completed
  • Tested with multiple providers: [list providers]
  • Tested on multiple platforms: [list platforms]

Test Coverage

  • All new code is covered by tests
  • Existing tests pass
  • Coverage percentage maintained or improved

Manual Testing Steps

Provide steps for manual testing:

  1. Set up environment with [...]
  2. Run command [...]
  3. Verify that [...]
  4. Check that [...]

Code Quality

Have you followed code quality standards?

  • Code follows the project's style guidelines (ESLint passes)
  • Code is properly formatted (Prettier applied)
  • Self-review of code completed
  • No console.log statements (using logger instead)
  • No hardcoded API keys or secrets
  • TypeScript strict mode compliance
  • Proper error handling implemented
  • TODO/FIXME comments reference issues

Documentation

Have you updated documentation?

  • JSDoc comments added/updated for public APIs
  • README.md updated (if needed)
  • Documentation in /docs updated (if needed)
  • Code examples added/updated (if needed)
  • CHANGELOG.md updated (if applicable)
  • Migration guide provided (if breaking changes)

Commit Message Format

Does your commit follow semantic commit conventions?

  • Commit message follows format: type(scope): description
  • Valid type used: feat, fix, docs, style, refactor, test, chore, build, ci, perf, revert
  • Scope specified (e.g., providers, cli, docs, middleware)

Example: feat(providers): add support for LiteLLM proxy

Dependencies

Does this PR add, update, or remove dependencies?

  • No dependency changes
  • Dependencies added (list below)
  • Dependencies updated (list below)
  • Dependencies removed (list below)

If yes, list dependencies and justification:

package-name@version - Reason for adding/updating

Performance Impact

Does this change affect performance?

  • No performance impact
  • Performance improved (provide metrics)
  • Performance degraded (justify why acceptable)

If applicable, provide benchmark results:

Before: X ms
After: Y ms
Improvement: Z%

Security Considerations

Are there any security implications?

  • No security implications
  • Security review needed
  • Security vulnerability fixed

If applicable, describe:

  • Security measures implemented
  • Potential risks mitigated
  • Compliance considerations (HIPAA, SOC2, GDPR)

Deployment Notes

Special deployment instructions?

  • No special deployment steps
  • Requires environment variable changes (list below)
  • Requires database migration
  • Requires Redis schema update
  • Other (describe below)

Screenshots / Videos

If applicable, add screenshots or videos to demonstrate changes:

[Add screenshots or videos here]

Reviewer Checklist

For reviewers:

  • Code follows project style and conventions
  • Changes are well-documented
  • Tests provide adequate coverage
  • No obvious performance issues
  • No security vulnerabilities introduced
  • Breaking changes are properly documented
  • Documentation is clear and accurate

Additional Notes

Any additional information for reviewers:

[Add any extra context, concerns, or questions here]


Pre-submission Checklist

Before submitting, ensure you have:

  • Read and followed the Contributing Guidelines
  • Verified all automated pre-commit checks pass
  • Tested changes locally with pnpm test
  • Built the project successfully with pnpm build
  • Run pnpm run validate:all and all checks pass
  • Reviewed your own code for obvious issues
  • Ensured commit messages follow semantic format
  • Updated relevant documentation
  • Added tests for new functionality
  • Checked that CI/CD pipeline passes (after creating PR)

Thank you for contributing to NeuroLink!

Summary by CodeRabbit

Release Notes

  • Chores
    • Reorganized package dependencies to make server framework packages available as optional dependencies rather than development-only dependencies.

- Two-part fix for Vite/Rollup "failed to resolve import" errors:

1. **Fix TypeScript type leak**: Changed getFrameworkInstance() return type
   from framework-specific types (FastifyInstance, Express, Hono) to 'unknown'
   in all server adapters. Prevents TypeScript from emitting framework type
   imports in .d.ts files.

2. **Move to optionalDependencies**: Moved server frameworks from devDependencies
   to optionalDependencies (fastify, @fastify/cors, @fastify/rate-limit, koa,
   koa-bodyparser, @koa/cors, @koa/router, express, cors, express-rate-limit).

This allows Vite/Rollup to resolve framework imports without forcing installation
for consumers who don't use server features.
@vercel

vercel Bot commented Feb 24, 2026

Copy link
Copy Markdown

@YaswanthKurapati24 is attempting to deploy a commit to the Sachin Sharma's projects Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Feb 24, 2026 •

Copy link
Copy Markdown

Walkthrough

The pull request reorganizes server and framework-related packages in package.json, moving them from devDependencies to optionalDependencies. This includes packages for fastify, express, koa, and related middleware and utilities totaling 10 package entries.

Changes

Cohort / File(s) Summary
Dependency Reorganization
package.json
Moves server/framework packages (fastify, koa, express, cors, and associated plugins) from devDependencies to optionalDependencies for optional runtime availability.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 Hoppy changes, packages rearranged,
From dev to optional, the dependencies exchanged,
Server frameworks now optional they stay,
A lighter load for production's way! 🚀

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: moving server adapter packages from devDependencies to optionalDependencies to fix bundling errors for consumers.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@YaswanthKurapati24 YaswanthKurapati24 self-assigned this Feb 24, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
package.json (1)

232-247: ⚠️ Potential issue | 🟠 Major

Optional dependencies still install by default; the proposed peer-dependency workaround is unreliable.

optionalDependencies are installed by default in npm, pnpm, and Yarn (skipped only with explicit flags like --omit=optional or --no-optional), so this approach still inflates installs for consumers who never use server adapters.

The suggested workaround (peerDependencies + peerDependenciesMeta.optional) does not reliably prevent installation. Setting optional: true primarily suppresses missing-peer warnings but does not prevent installation; npm v7+ auto-installs peerDependencies regardless, and registry/metadata inconsistencies can cause even optional peers to be pulled in. This would not achieve the stated goal of avoiding forced installs.

For server adapters to be truly optional, consider instead:

  • Lazy/dynamic imports at the adapter entry points so bundlers only resolve when actually used.
  • Accepting that the frameworks are present in node_modules (from optionalDependencies) but ensuring they're tree-shaken away when unused (requires bundler config).
  • Alternatively, moving server adapters to a separate package tree to keep them out of the main consumer's lockfile entirely.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@package.json` around lines 232 - 247, The package.json approach using
optionalDependencies/peerDependenciesMeta does not prevent those frameworks from
being installed; remove framework entries from optionalDependencies and instead
make server adapters truly optional by (1) moving all adapter code that
references frameworks into separate modules/packages (e.g., move
express/koa/fastify adapter implementations out of the main package into a
workspace package like "server-adapters" or separate npm packages), or (2)
update the adapter entry points (eg. files named expressAdapter, koaAdapter,
fastifyAdapter) to use lazy dynamic imports (use import() inside try/catch) so
the runtime only attempts to load the framework when the adapter is invoked;
also add clear docs stating the separate package or runtime install requirement
and ensure the adapter catch path surfaces a helpful error if the framework is
not installed so consumers aren’t surprised.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Outside diff comments:
In `@package.json`:
- Around line 232-247: The package.json approach using
optionalDependencies/peerDependenciesMeta does not prevent those frameworks from
being installed; remove framework entries from optionalDependencies and instead
make server adapters truly optional by (1) moving all adapter code that
references frameworks into separate modules/packages (e.g., move
express/koa/fastify adapter implementations out of the main package into a
workspace package like "server-adapters" or separate npm packages), or (2)
update the adapter entry points (eg. files named expressAdapter, koaAdapter,
fastifyAdapter) to use lazy dynamic imports (use import() inside try/catch) so
the runtime only attempts to load the framework when the adapter is invoked;
also add clear docs stating the separate package or runtime install requirement
and ensure the adapter catch path surfaces a helpful error if the framework is
not installed so consumers aren’t surprised.

ℹ️ Review info

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 46b1da4 and a322e46.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

@murdore
murdore merged commit 0f4f71d into juspay:release Feb 24, 2026
9 of 10 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 9.12.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants