From 2fabdface73ca4a408dcef5138ba9fb48a80f9d4 Mon Sep 17 00:00:00 2001 From: Thomas Luizon Rodrigues Gregorio Date: Thu, 16 Jul 2026 12:53:04 -0300 Subject: [PATCH] fix(mobile,ci): restore the expo-modules-core pin the Android release guard enforces PR #502 (React Doctor burn-down) dropped "expo-modules-core": "57.0.3" from apps/mobile/package.json as an unrelated drive-by. The release job installs the isolated mobile workspace with --package-lock=false, so a from-scratch resolve is free to pick any version satisfying expo 57.0.4's ~57.0.3 range; it took the newest, 57.0.5, and the pin guard failed the first release run since (29512207801). Restore the pin at 57.0.3, the version the root lockfile and the last green release (2026-07-09) both resolved. Also make the guard distinguish a deleted pin from a real drift. It read the expected version straight out of package.json, so a removed entry compared against undefined and reported "pinned to undefined" instead of naming the actual fault. A missing pin now fails as UNPINNED with a message that says the pin must be restored, not dropped from the guard. Verified by reproducing the release step locally: prepare-release-workspace plus the same lockfile-free install, then the guard extracted verbatim from the workflow YAML. All five modules resolve to the verified set and the step exits 0; deleting the pin again reproduces the UNPINNED failure. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_01Sz19TStgQiJxZCZiE9tNsr --- .github/workflows/android-release.yml | 20 +++++++++++++++++++- apps/mobile/package.json | 1 + package-lock.json | 1 + 3 files changed, 21 insertions(+), 1 deletion(-) diff --git a/.github/workflows/android-release.yml b/.github/workflows/android-release.yml index 6634cb521..520bddd0a 100644 --- a/.github/workflows/android-release.yml +++ b/.github/workflows/android-release.yml @@ -146,22 +146,40 @@ jobs: ['expo-router', pkg.dependencies['expo-router']], ] + // A pin read as undefined means the entry was deleted from package.json, + // not that the resolve drifted: the guard silently loses its teeth for + // that module, so name that failure separately from a real drift. + const unpinned = [] const mismatches = [] for (const [name, expected] of checks) { const actual = require(`${name}/package.json`).version + if (expected === undefined) { + console.log(`UNPINNED ${name}: resolved=${actual} pinned=`) + unpinned.push(`${name} (resolved ${actual})`) + continue + } const ok = actual === expected console.log(`${ok ? 'ok ' : 'MISMATCH'} ${name}: resolved=${actual} pinned=${expected}`) if (!ok) mismatches.push(`${name} resolved ${actual} but is pinned to ${expected}`) } + if (unpinned.length > 0) { + console.error( + `::error::Guarded native modules have no version pin in apps/mobile/package.json: ${unpinned.join('; ')}. ` + + 'Every module listed in this guard must keep an exact pin in dependencies or overrides. ' + + 'Restore the pin instead of dropping it from the guard.' + ) + } + if (mismatches.length > 0) { console.error( `::error::Pinned native module versions drifted: ${mismatches.join('; ')}. ` + 'This is the verified coherent reanimated + Expo SDK 57.0.4 set; a newer ' + 'resolve can break reanimated or the release build. Fix the pins/overrides in apps/mobile/package.json.' ) - process.exit(1) } + + if (unpinned.length > 0 || mismatches.length > 0) process.exit(1) NODE - name: Validate Expo dependency compatibility diff --git a/apps/mobile/package.json b/apps/mobile/package.json index e1b616913..164ddb69e 100644 --- a/apps/mobile/package.json +++ b/apps/mobile/package.json @@ -50,6 +50,7 @@ "expo-image-picker": "57.0.2", "expo-linear-gradient": "57.0.0", "expo-linking": "57.0.2", + "expo-modules-core": "57.0.3", "expo-notifications": "57.0.3", "expo-router": "57.0.4", "expo-secure-store": "57.0.0", diff --git a/package-lock.json b/package-lock.json index ff510db92..7bfe99d77 100644 --- a/package-lock.json +++ b/package-lock.json @@ -63,6 +63,7 @@ "expo-image-picker": "57.0.2", "expo-linear-gradient": "57.0.0", "expo-linking": "57.0.2", + "expo-modules-core": "57.0.3", "expo-notifications": "57.0.3", "expo-router": "57.0.4", "expo-secure-store": "57.0.0",