Skip to content

feat(apps): package the data app runtime as an npm dependency - #124

Merged
francoischalifour merged 5 commits into
mainfrom
fc/data-app-npm
Oct 1, 2026
Merged

francoischalifour merged 5 commits into
mainfrom
fc/data-app-npm

Conversation

@francoischalifour

Copy link
Copy Markdown
Member

The data app runtime is now published independently as @altertable/data-app. Move the CLI to consuming that package so runtime development and releases live in the Data App repository.

  • Pin generated apps to @altertable/data-app@0.61.0 (currently releasing) with a frozen lockfile.
  • Embed only the starter in npm and native CLI builds; remove runtime source, setup tooling, and the runtime watcher.
  • Update the starter to public package exports, explicit stylesheet imports, and installed package documentation.
  • Make app check validate the installed package and browser/server boundaries.
  • Limit app upgrade to manifest and lockfile updates, preserving unrelated dependencies, checking peers, avoiding downgrades, and restoring both files if resolution fails.

Legacy vendored apps are intentionally unsupported. The CLI no longer migrates runtime copies or rewrites app source.

Validation: full repository verification passed, including CLI tests, 79 black-box tests, 40 desktop/phone browser tests, and npm bundle smoke testing. A fresh app created with the native CLI installed the published package and successfully completed a live lakehouse query in the browser.

Pin the starter to @altertable/data-app 0.59.1 and embed only app-owned
starter files in npm and native CLI builds. Runtime source, dependencies,
and API documentation now belong to the standalone package repository.

Migrate checksum-verified legacy apps to registry dependencies, public Bun
server exports, explicit styles, and installed package documentation.
Validate migrated consumers before removing their runtime and restore both
project files and installed dependencies on failure. Preserve unrelated
app dependencies and never downgrade a newer installed package.

Remove the runtime source watcher and repository runtime checks. Keep app
contract and browser boundary checks against the installed public package.

Validation: full repository verify gate, 773 CLI tests, 79 black-box tests,
40 desktop/phone browser tests, npm and native smoke checks, and a native
migration of a genuine app from the previous starter.
Support only published data app packages. Remove checksum validation,
legacy import and documentation rewrites, and migration-only consumer
validation and dependency backups.

Limit upgrades to package.json and bun.lock, restoring their original
contents if resolution fails. Retain peer compatibility checks and avoid
downgrading newer installed package versions.

Update generated command references, contributor guidance, and upgrade
tests to describe the package-only workflow.
Pin the generated starter and browser-test consumer to the published
0.61.0 release and regenerate both Bun lockfiles.

Derive compatible ranges in upgrade tests from the starter's tested
version so future release bumps do not require fixture edits.

@albert20260301 albert20260301 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Required: the new authoring-link test fails on this branch because it resolves node_modules/@altertable/data-app/... relative to data-app/starter, where that package is never present. I reproduced it with:

bun test cli/src/commands/app/lib/distribution.test.ts
# AGENTS.md links to missing node_modules/@altertable/data-app/docs/app-authoring.md

@altertable/data-app@0.61.0 does publish the linked docs, so please make this validation exercise the installed/package artifact (or otherwise validate the pinned tarball) instead of a path under the starter source. That is the boundary generated apps actually rely on.

The distribution link test accidentally required dependencies installed
under the starter source directory, so isolated runs failed in clean
checkouts even though the pinned npm artifact ships the documentation.

Keep app-owned link checks in the offline distribution test. Check all
generated Markdown links after the existing generated-app frozen install,
and assert that its installed package matches the tested starter version.

Verified both affected tests with starter node_modules temporarily absent:
the original test failed, and the revised tests passed.
@francoischalifour
francoischalifour enabled auto-merge (squash) October 1, 2026 08:41
@francoischalifour
francoischalifour merged commit bd807c1 into main Oct 1, 2026
12 checks passed
@francoischalifour
francoischalifour deleted the fc/data-app-npm branch October 1, 2026 08:47
francoischalifour pushed a commit that referenced this pull request Oct 1, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.9.0](v1.8.0...v1.9.0)
(2026-10-01)


### Features

* **apps:** package the data app runtime as an npm dependency
([#124](#124))
([bd807c1](bd807c1))


### Bug Fixes

* **release:** include publication helper in recovery checkout
([#123](#123))
([2a7b2dc](2a7b2dc))
* **release:** recover assetless v1.8.0 release
([#121](#121))
([bdf930f](bdf930f))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants