feat(release): guard template lockfile version + registry parity - #627
Draft
atilafassina wants to merge 1 commit into
Draft
atilafassina wants to merge 1 commit into
atilafassina wants to merge 1 commit into
Conversation
Add a fail-closed guard so a stale or internal-registry template lockfile can never ship — the gap that let the Phase-1 regression reach a release. - check-template-lock-versions.ts: new verifier reading the resolved @databricks/appkit(-ui) version from both lock formats (npm packages[] entry; pnpm importers["."].dependencies, peer suffix stripped). Pure function plus a CLI. Unit tests cover both formats, both packages, and the stale-pnpm-lock regression. - check-template-deps.ts: assert lock<->package.json version parity, so drift fails this repo's PR CI. - publish-template-tag.ts: before commit, abort the release if the regenerated locks disagree with the version, or if either lock references a non-public registry (validate-only, no rewrite). Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: Atila Fassina <atila@fassina.eu>
Contributor
🤖 AppKit PR bot🔬 Run evalsStart an eval for this PR from the evals-monitor app: Go to Evals Monitor → 📦 Try this PR's app templateScaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh run download 37032617265 -R databricks/appkit -n appkit-template-0.82.0-pr.0cf5fd0-template-lock-parity-guard-627 -D appkit-pr-627 \
&& unzip -o "appkit-pr-627/appkit-template-0.82.0-pr.0cf5fd0-template-lock-parity-guard-627.zip" -d "appkit-pr-627" \
&& databricks apps init --template "appkit-pr-627"The template pins |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Follow-up to #626 (the Fix). That PR made the release-publish sites regenerate both template lockfiles; this adds the Guard so a stale or internal-registry template lockfile can never silently ship again — the gap that let the original regression reach a release.
The template is pnpm-first and ships both
package-lock.jsonandpnpm-lock.yaml;databricks apps initkeeps the chosen PM's lock and drops the other, so either lock can be the one a user installs from. These guards assert both are correct before anything is published.Changes
tools/check-template-lock-versions.ts(new) — parity verifier. Reads the resolved@databricks/appkit/@databricks/appkit-uiversion from each lock, dispatching by format: npmpackages["node_modules/<pkg>"].version; pnpmimporters["."].dependencies[<pkg>].version(peer-dependency suffix stripped). PureverifyLockVersions(lockPaths, expected)function plus a CLI. Unit tests cover both formats, both packages, and the exact stale-pnpm-lock regression.tools/check-template-deps.ts— asserts lock↔package.jsonversion parity, so drift fails this repo's PR CI (already wired atci.yml).tools/publish-template-tag.ts— before commit, aborts the release if (a) the regenerated locks disagree with the published version, or (b) either committed lock references a non-public registry (validate-only, fail-closed — no rewrite, since a JFrog URL on the public-npm tag path means the environment is wrong).Why the registry check is validate-only here
Unlike the artifact-zip path (which installs under JFrog and rewrites back to public npm), the git-tag path installs from public npm. A non-public URL there is an environment fault that should abort loudly, not be silently rewritten.
Testing
pnpm check,pnpm -r typecheck,pnpm testall green (5370 passed, +9 new).This pull request and its description were written by Isaac.