Skip to content

DX-3059: add Blob file and directory uploads - #22

Open
ytkimirti wants to merge 8 commits into
mainfrom
DX-3059-blob-upload
Open

ytkimirti wants to merge 8 commits into
mainfrom
DX-3059-blob-upload

Conversation

@ytkimirti

@ytkimirti ytkimirti commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Adds upstash blob upload <source> for files and directories, with multipart uploads, concurrency, retries, and credential refresh so long uploads outlive Blob's temporary S3 credentials.
Auth via bucket token (--token, UPSTASH_BLOB_TOKEN, .env) or --bucket-id; progress on stderr, JSON summary on stdout; --dry-run, --skip-existing.
Pins @upstash/blob@0.0.5 and mime@4.1.0, requires Node 20, publishes prereleases to npm canary. Closes DX-3059.

@linear-code

linear-code Bot commented Sep 22, 2026

Copy link
Copy Markdown

DX-3059

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The declared Node minimum is incompatible with the CLI syntax, and empty bucket IDs can silently select an ambient bucket token.

Review effort: Balanced
Findings: 2 High severity · 1 Low severity

Open (3)
What changed in this PR

Adds recursive Blob uploads with streaming, multipart support, retries, concurrency controls, credential refresh, and dry-run/skip options.

Changes:

  • Implements and registers blob upload.
  • Extends bucket-token authentication and upload documentation.
  • Adds dependencies, tests, Node requirements, and canary publishing.
File Description
src/​commands/​blob/​upload.ts Implements upload planning and execution.
src/​commands/​blob/​credentials.ts Adds explicit token support.
src/​commands/​blob/​index.ts Registers the upload command.
tests/​unit/​blob-upload.test.ts Tests upload behavior and SDK integration.
tests/​unit/​blob.test.ts Tests registration and token authentication.
README.md Documents uploads and runtime requirements.
package.json Adds dependencies and updates Node engines.
package-lock.json Locks dependency and engine changes.
.github/​workflows/​release.yml Publishes prereleases under canary.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
},
"engines": {
"node": ">=18.0.0"
"node": ">=20.0.0"
return;
}
if (files.length === 0) throw new Error("source contains no regular files to upload");
const { token, unauthorizedRetries } = await resolveBucketToken(options, command);
Comment thread README.md

## Installation

Requires Node.js 20 or newer.

@CahidArda CahidArda left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Static review (couldn't run the tests locally).

Stack note: #22 → #24 → #25. #24 deletes this PR's upload.ts and its tests, so the upload logic here doesn't ship on its own. What survives is --token, the deps, the engines bump and the release-tag change. I'd merge the three as one unit, or squash this into #24, rather than review the upload logic separately. Main review is on #24.

On the parts that survive:

  • Prerelease dist-tag changes from next to canary. Anyone installing @next silently stops getting updates, so please call this out in the release notes.
  • engines moves to Node >= 20. Fine, since Node 18 is EOL and the SDK requires 20, but it's a breaking change worth noting.
  • --token on the command line ends up in shell history and ps. The env var is the safer route; the help text could say so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants