Build/Test Tools: Remove npx commands in 7.0 - #13107
Conversation
npx commands.`npx` downloads and installs a package when the binary is not already present, and it runs the install scripts of every package it installs. `npm exec --no` runs an installed binary only, and fails when the package is missing. `update-browserslist-db` is now a direct `devDependency`, so the task does not depend on it staying hoisted as a transitive dependency. Backport of r63309 to the 7.0 branch.
da93c7b to
f1e054e
Compare
Test using WordPress PlaygroundThe changes in this pull request can previewed and tested using a WordPress Playground instance. WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser. Some things to be aware of
For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation. |
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
There was a problem hiding this comment.
Pull request overview
This PR backports the remaining npx removals to the 7.0 branch by switching Grunt tasks to npm exec --no (ensuring only locally-installed binaries are run) and by making update-browserslist-db an explicit devDependency.
Changes:
- Replace
npx wp-scripts ...withnpm exec --no -- wp-scripts ...in thewp-packages:updateGrunt task. - Replace
npx update-browserslist-db@latestwithnpm exec --no -- update-browserslist-dband pin it as a directdevDependencyat1.2.3. - Update
package-lock.jsonto reflect the new direct devDependency.
Reviewed changes
Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| package.json | Adds update-browserslist-db as a direct devDependency (pinned). |
| package-lock.json | Records update-browserslist-db@1.2.3 as a direct devDependency and keeps lock data consistent. |
| Gruntfile.js | Replaces the last npx invocations with npm exec --no to avoid on-demand package downloads during build tooling runs. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Backport of r63309, already in
trunkvia #13021, to the7.0branch. It replaces the last twonpxcalls inGruntfile.jswithnpm exec --no, which runs an installed binary instead of downloading and installing one, and declaresupdate-browserslist-dbas a directdevDependency.Trac ticket: https://core.trac.wordpress.org/ticket/65864
Testing instructions
npm ci. It completes, andgit statusstays clean. This confirmspackage.jsonandpackage-lock.jsonagree.npm ls update-browserslist-db. It reportsupdate-browserslist-db@1.2.3as a direct dependency.npm exec --no -- update-browserslist-db --helpandnpm exec --no -- wp-scripts. Each runs the local binary and downloads nothing.node_modules/update-browserslist-dband runnpm exec --no -- update-browserslist-db. It fails withnpx canceled due to missing packages and no YES optioninstead of fetching the package. Restore the tree withnpm ci.Use of AI Tools
AI assistance: Yes — Claude Code (Claude Opus 5) applied r63309 to the
7.0branch and verified the changeset.This Pull Request is for code review only. Please keep all other discussion in the Trac ticket. Do not merge this Pull Request. See GitHub Pull Requests for Code Review in the Core Handbook for more details.