Repository navigation
chore(cli): stop installing libraries the bundle already contains - #457
Conversation
|
@claude /review please verify that inlining these dependencies are unlikely to cause issues across installed architectures or in different deployments... specifically in situations where vite's node externals would be a better solution |
|
Claude finished @theCodeDrift's task in 3m 24s —— View job Review: architecture/deployment risk of moving 13 libs to
|
vite inlines every npm package into dist/ (rollupOptions.external is node builtins only), so the 13 libraries listed under dependencies were downloaded on every install and never loaded. They move to devDependencies. tsx stays: invoke.ts resolves and spawns it at runtime. The ast-grep and Vale binaries stay in optionalDependencies, unchanged.
07bbcc7 to
7c7fa23
Compare
Every install of
@taskless/clidownloads 12 JavaScript libraries that never run. vite inlines every npm package intodist/:rollupOptions.externalinvite.config.tslists only Node builtins. So zod, yaml, citty, @clack/prompts, posthog-node and the rest are already compiled into the bundle, and the copies innode_modulesare never loaded.This moves those 12 to
devDependencies. Two things stay as real install-time dependencies, because the CLI looks them up at runtime:tsx:src/rules/runtime/invoke.tsresolvestsx/package.jsonand spawns it to run runtime rules.src/rules/platform-binary.tsresolves them by package name. They stay inoptionalDependencies, unchanged.No versions change; the lockfile diff only reclassifies dependency types.
Verification
pnpm typecheck,pnpm lint(which builds the CLI and runs its owncheck), andpnpm test(2007/2007) all pass.npm installof thepnpm packoutput installs 6 packages: the CLI,tsx(plus esbuild), and one ast-grep and one Vale binary for the platform. None of the 12 libraries are installed. From that install:--version,init --no-interactiveandagent create-sg-rulework.checkreports an ast-grep finding (a plantedeval()) and Vale findings (no-hedgingon a README).tsxpath. That needs a signed rule.tsxis unchanged by this PR either way.The trade-off: the bundled libraries no longer show up in a consumer's
npm lsor dependency scanners, which matches what actually runs.Rebased onto
mainafter #457 conflicted with 057683c, which droppedpicocolorsfrom the CLI entirely, so 12 libraries move rather than 13. Checks re-run after the rebase:pnpm typecheck,pnpm lint,pnpm test(2098/2098).