Skip to content

ci: use locked ESM smoke dependencies - #11128

Merged
jasonsaayman merged 2 commits into
v1.xfrom
fix/esm-smoke-npm10-ci
Aug 4, 2026
Merged

jasonsaayman merged 2 commits into
v1.xfrom
fix/esm-smoke-npm10-ci

Conversation

@jasonsaayman

@jasonsaayman jasonsaayman commented Aug 4, 2026 •

Copy link
Copy Markdown
Member

Summary

Fixes CI runs

Linked issue

N/A

Changes

N/A

Checklist

  • Tests added or updated (or N/A with reason)
  • Docs/types updated if public API changed (index.d.ts and index.d.cts)
  • No breaking changes (or called out explicitly above)

Summary by cubic

Lock ESM smoke test dependencies and switch CI to use npm ci for deterministic installs on npm 10, reducing flakiness in ESM smoke runs. Updates the tests/smoke/esm lockfile to pin versions and align with newer vite/rolldown.

Description

  • Summary of changes

    • CI: replace npm install with npm ci --ignore-scripts for tests/smoke/esm.
    • Update tests/smoke/esm/package-lock.json to lock deps (e.g. vitest@4.1.9, vite@8.2.0, rolldown@1.2.2, lightningcss@1.33.0, postcss@8.5.25).
    • Pin @rolldown/* native bindings to 1.2.2; remove wasm/emnapi optional deps from the lockfile.
  • Reasoning

    • npm ci enforces reproducible installs under npm 10 and prevents drift from upstream minor releases.
    • Newer vite/rolldown match current engines and stabilize the ESM smoke build.
  • Additional context

    • Affects only CI and the tests/smoke/esm fixture; no runtime or public API changes.

Docs

  • Suggest adding a short note in /docs/ (e.g., contributing/CI) that smoke test fixtures should be installed with npm ci --ignore-scripts and keep their lockfiles committed.

Testing

  • No new tests. ESM smoke tests continue to run in CI with the locked dependencies. Additional tests are not needed for this CI-only change.

Semantic version impact

  • None. CI/test-only changes with no impact on published packages.

Written for commit fd747ca. Summary will update on new commits.

Review in cubic

Copilot AI lite review requested due to automatic review settings August 4, 2026 17:06
@jasonsaayman jasonsaayman self-assigned this Aug 4, 2026
@jasonsaayman jasonsaayman added the commit::fix The PR is related to a bugfix label Aug 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aims to stabilize CI by making the ESM smoke test dependency installation deterministic, ensuring the ESM smoke suite uses the committed lockfile rather than resolving dependencies at install time.

Changes:

  • Updated tests/smoke/esm/package-lock.json to lock updated ESM smoke test tooling dependencies (notably vitest).
  • Switched the ESM smoke workflow step from npm install to npm ci to enforce lockfile-based installs in CI.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
tests/smoke/esm/package-lock.json Updates locked dependency graph for the ESM smoke test workspace (including vitest bump).
.github/workflows/run-ci.yml Uses npm ci for ESM smoke dependency install to ensure reproducible CI runs.
Files not reviewed (1)
  • tests/smoke/esm/package-lock.json: Generated file

@greptile-apps

greptile-apps Bot commented Aug 4, 2026

Copy link
Copy Markdown

Greptile Summary

This change makes ESM smoke-test dependency installation reproducible by using the checked-in lockfile with npm ci and refreshing the locked Vitest dependency graph.

The ESM smoke path was checked by building and packing axios locally, installing the packed tarball in the ESM workspace after npm ci --ignore-scripts, and running the Vitest smoke suite. All 16 test files and 74 tests passed on Node 24. No defects were found.

Confidence Score: 5/5

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex built and packed axios locally and installed the package into isolated ESM smoke-test workspaces.
  • T-Rex ran the parent install path and the npm ci --ignore-scripts path, then executed npm run test:smoke:esm:vitest in each workspace.
  • T-Rex observed that both runs exited successfully with all 16 ESM smoke files and 74 tests passing.
  • Artifacts were prepared to support review, including the ESM smoke CI comparison harness and the two workflow logs.

View all artifacts

T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "Merge branch 'v1.x' into fix/esm-smoke-n..." | Re-trigger Greptile

@jasonsaayman
jasonsaayman merged commit ac28131 into v1.x Aug 4, 2026
29 checks passed
@jasonsaayman
jasonsaayman deleted the fix/esm-smoke-npm10-ci branch August 4, 2026 17:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

commit::fix The PR is related to a bugfix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants