Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The declared Node minimum is incompatible with the CLI syntax, and empty bucket IDs can silently select an ambient bucket token.
Review effort: Balanced
Findings: 2
Open (3)
What changed in this PR
Adds recursive Blob uploads with streaming, multipart support, retries, concurrency controls, credential refresh, and dry-run/skip options.
Changes:
- Implements and registers
blob upload. - Extends bucket-token authentication and upload documentation.
- Adds dependencies, tests, Node requirements, and canary publishing.
| File | Description |
|---|---|
src/commands/blob/upload.ts |
Implements upload planning and execution. |
src/commands/blob/credentials.ts |
Adds explicit token support. |
src/commands/blob/index.ts |
Registers the upload command. |
tests/unit/blob-upload.test.ts |
Tests upload behavior and SDK integration. |
tests/unit/blob.test.ts |
Tests registration and token authentication. |
README.md |
Documents uploads and runtime requirements. |
package.json |
Adds dependencies and updates Node engines. |
package-lock.json |
Locks dependency and engine changes. |
.github/workflows/release.yml |
Publishes prereleases under canary. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| }, | ||
| "engines": { | ||
| "node": ">=18.0.0" | ||
| "node": ">=20.0.0" |
| return; | ||
| } | ||
| if (files.length === 0) throw new Error("source contains no regular files to upload"); | ||
| const { token, unauthorizedRetries } = await resolveBucketToken(options, command); |
|
|
||
| ## Installation | ||
|
|
||
| Requires Node.js 20 or newer. |
CahidArda
left a comment
There was a problem hiding this comment.
Static review (couldn't run the tests locally).
Stack note: #22 → #24 → #25. #24 deletes this PR's upload.ts and its tests, so the upload logic here doesn't ship on its own. What survives is --token, the deps, the engines bump and the release-tag change. I'd merge the three as one unit, or squash this into #24, rather than review the upload logic separately. Main review is on #24.
On the parts that survive:
- Prerelease dist-tag changes from
nexttocanary. Anyone installing@nextsilently stops getting updates, so please call this out in the release notes. enginesmoves to Node >= 20. Fine, since Node 18 is EOL and the SDK requires 20, but it's a breaking change worth noting.--tokenon the command line ends up in shell history andps. The env var is the safer route; the help text could say so.


Adds
upstash blob upload <source>for files and directories, with multipart uploads, concurrency, retries, and credential refresh so long uploads outlive Blob's temporary S3 credentials.Auth via bucket token (
--token,UPSTASH_BLOB_TOKEN,.env) or--bucket-id; progress on stderr, JSON summary on stdout;--dry-run,--skip-existing.Pins
@upstash/blob@0.0.5andmime@4.1.0, requires Node 20, publishes prereleases to npmcanary. Closes DX-3059.