Files
msd-core/tests/bug-2519-sdk-tarball-dist.test.cjs
Tom Boucher 334a64168e chore(npm): rebrand packages to @opengsd scope (#127)
* chore(npm): rebrand packages to @opengsd scope

Rename:
- get-shit-done-redux → @opengsd/get-shit-done-redux
- @gsd-redux/sdk → @opengsd/gsd-sdk

Add publishConfig.access=public for first-time scoped publish.
CLI binary names (get-shit-done-redux, gsd-sdk, gsd-tools) unchanged.

Sweeps install commands, npx invocations, CI publish/version-check
workflows, tests, docs, READMEs (all translations), and the
PACKAGE_NAME constant in check-latest-version.

Bumps qs 6.15.1 → 6.15.2 to clear a moderate advisory surfaced by
the audit-clean test (GHSA-q8mj-m7cp-5q26).

Closes #126

* chore: pin 2.0.0 release + remove canary workflow

- Bump both packages 1.50.0-canary.0 → 2.0.0 for first @opengsd publish
- Remove .github/workflows/canary.yml and canary dist-tag handling in
  release.yml / release-sdk.yml
- Drop canary section from VERSIONING.md

Refs #126

* chore: address review findings + harden tarball-smoke timeout

- .changeset/opengsd-org-rename.md: match project's custom
  parse.cjs frontmatter (type: Changed / pr: 127); the scoped
  @changesets/cli keys were silently rejected.
- CONTEXT.md: drop two canary-stream policy lines and a dangling
  DEFECT.CANARY-VERSION-LEAK.cross-ref now that canary.yml is gone.
- tests/release-tarball-smoke.install.test.cjs: pass
  timeout: 600_000 for npm pack + global install; the 3-minute
  runNpm default was timing out on slower Docker hosts (cartographer).

Refs #126

* fix(sdk): add missing type/runtime devDependencies for build

prepublishOnly invokes tsc which couldn't resolve @types/node,
@types/ws, or synckit. They had been hoisted from root but were
not declared in sdk/'s own package.json — first publish from a
clean SDK tree failed.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(ci): use npm pack stdout instead of glob to find tarball

`npm pack --silent` for a scoped package (@opengsd/get-shit-done-redux)
produces `opengsd-get-shit-done-redux-*.tgz`, not `get-shit-done-redux-*.tgz`.
Capture the filename from stdout instead of a hardcoded glob so the step
works regardless of package name format.

Fixes smoke (ubuntu-latest, 22, false) CI failure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* ci: treat workflow-file changes as test-skip eligible

`.github/workflows/install-smoke.yml` (and other workflow files)
were in neither `test.yml` paths nor `test-skip.yml` paths-ignore,
so neither workflow ran on a workflow-only commit — leaving the
required test-skip check perpetually missing.

Refs #126

* chore: reset version to 1.0.0 for first @opengsd publish

Nothing has been published yet under the @opengsd scope, so the
inaugural release uses 1.0.0 rather than 2.0.0. The "major bump"
in the changeset reflects the breaking install-command change for
users migrating from the prior unscoped `get-shit-done-redux`, not
a numeric continuation from a 1.x line under the new identity.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 16:22:41 -04:00

78 lines
3.0 KiB
JavaScript

/**
* Regression test for #2519: @opengsd/gsd-sdk tarball shipped without dist/
*
* The published 0.1.0 tarball lacked a `files` whitelist including `dist/` and
* a `prepublishOnly` hook to build `dist/` before publish. As a result the
* tarball contained only source and the declared `bin` target `./dist/cli.js`
* was absent at install time, breaking every `gsd-sdk query …` call.
*
* This test guards sdk/package.json so future edits cannot silently drop
* either safeguard.
*/
'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const SDK_PACKAGE_JSON = path.join(__dirname, '..', 'sdk', 'package.json');
describe('bug #2519: sdk/package.json ships dist/ in tarball', () => {
const pkg = JSON.parse(fs.readFileSync(SDK_PACKAGE_JSON, 'utf-8'));
test('has a files whitelist (array) so publish is explicit', () => {
assert.ok(
Array.isArray(pkg.files),
'sdk/package.json must declare a `files` array so the tarball contents are explicit',
);
assert.ok(
pkg.files.length > 0,
'`files` array must not be empty',
);
});
test('files whitelist includes dist/ so compiled output is published', () => {
assert.ok(Array.isArray(pkg.files), '`files` must be an array');
const includesDist = pkg.files.some((entry) => {
if (typeof entry !== 'string') return false;
const normalized = entry.replace(/\\/g, '/').replace(/^\.\//, '');
return /^dist(?:$|\/|\/\*\*|\/\*\*\/\*)/.test(normalized);
});
assert.ok(
includesDist,
`sdk/package.json \`files\` must include "dist" so the published tarball contains the compiled CLI (bin target ./dist/cli.js). Found: ${JSON.stringify(pkg.files)}`,
);
});
test('has prepublishOnly script that runs a build', () => {
assert.ok(
pkg.scripts && typeof pkg.scripts === 'object',
'sdk/package.json must have a `scripts` object',
);
const prepub = pkg.scripts.prepublishOnly;
assert.ok(
typeof prepub === 'string' && prepub.length > 0,
'sdk/package.json must define `scripts.prepublishOnly` so dist/ is (re)built before every publish',
);
// Must invoke a build — either `npm run build`, `tsc`, or similar.
const looksLikeBuild = /\b(build|tsc)\b/.test(prepub);
assert.ok(
looksLikeBuild,
`scripts.prepublishOnly must run a build command (e.g. "npm run build" or "tsc"). Got: ${JSON.stringify(prepub)}`,
);
});
test('bin target lives under dist/ (sanity: the thing files+prepublish must ship)', () => {
assert.ok(pkg.bin, 'sdk/package.json must declare a `bin` field');
const binValues = typeof pkg.bin === 'string'
? [pkg.bin]
: Object.values(pkg.bin);
assert.ok(
binValues.some((p) => typeof p === 'string' && p.includes('dist/')),
`bin target must reference dist/ — otherwise the files+prepublishOnly guard is pointless. Got: ${JSON.stringify(pkg.bin)}`,
);
});
});