feat(apps): package the data app runtime as an npm dependency - #124
Merged
Merged
Conversation
Pin the starter to @altertable/data-app 0.59.1 and embed only app-owned starter files in npm and native CLI builds. Runtime source, dependencies, and API documentation now belong to the standalone package repository. Migrate checksum-verified legacy apps to registry dependencies, public Bun server exports, explicit styles, and installed package documentation. Validate migrated consumers before removing their runtime and restore both project files and installed dependencies on failure. Preserve unrelated app dependencies and never downgrade a newer installed package. Remove the runtime source watcher and repository runtime checks. Keep app contract and browser boundary checks against the installed public package. Validation: full repository verify gate, 773 CLI tests, 79 black-box tests, 40 desktop/phone browser tests, npm and native smoke checks, and a native migration of a genuine app from the previous starter.
Support only published data app packages. Remove checksum validation, legacy import and documentation rewrites, and migration-only consumer validation and dependency backups. Limit upgrades to package.json and bun.lock, restoring their original contents if resolution fails. Retain peer compatibility checks and avoid downgrading newer installed package versions. Update generated command references, contributor guidance, and upgrade tests to describe the package-only workflow.
Pin the generated starter and browser-test consumer to the published 0.61.0 release and regenerate both Bun lockfiles. Derive compatible ranges in upgrade tests from the starter's tested version so future release bumps do not require fixture edits.
albert20260301
suggested changes
Sep 30, 2026
albert20260301
left a comment
Contributor
There was a problem hiding this comment.
Required: the new authoring-link test fails on this branch because it resolves node_modules/@altertable/data-app/... relative to data-app/starter, where that package is never present. I reproduced it with:
bun test cli/src/commands/app/lib/distribution.test.ts
# AGENTS.md links to missing node_modules/@altertable/data-app/docs/app-authoring.md
@altertable/data-app@0.61.0 does publish the linked docs, so please make this validation exercise the installed/package artifact (or otherwise validate the pinned tarball) instead of a path under the starter source. That is the boundary generated apps actually rely on.
The distribution link test accidentally required dependencies installed under the starter source directory, so isolated runs failed in clean checkouts even though the pinned npm artifact ships the documentation. Keep app-owned link checks in the offline distribution test. Check all generated Markdown links after the existing generated-app frozen install, and assert that its installed package matches the tested starter version. Verified both affected tests with starter node_modules temporarily absent: the original test failed, and the revised tests passed.
redox
approved these changes
Oct 1, 2026
francoischalifour
enabled auto-merge (squash)
October 1, 2026 08:41
francoischalifour
pushed a commit
that referenced
this pull request
Oct 1, 2026
🤖 I have created a release *beep* *boop* --- ## [1.9.0](v1.8.0...v1.9.0) (2026-10-01) ### Features * **apps:** package the data app runtime as an npm dependency ([#124](#124)) ([bd807c1](bd807c1)) ### Bug Fixes * **release:** include publication helper in recovery checkout ([#123](#123)) ([2a7b2dc](2a7b2dc)) * **release:** recover assetless v1.8.0 release ([#121](#121)) ([bdf930f](bdf930f)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The data app runtime is now published independently as
@altertable/data-app. Move the CLI to consuming that package so runtime development and releases live in the Data App repository.@altertable/data-app@0.61.0(currently releasing) with a frozen lockfile.app checkvalidate the installed package and browser/server boundaries.app upgradeto manifest and lockfile updates, preserving unrelated dependencies, checking peers, avoiding downgrades, and restoring both files if resolution fails.Legacy vendored apps are intentionally unsupported. The CLI no longer migrates runtime copies or rewrites app source.
Validation: full repository verification passed, including CLI tests, 79 black-box tests, 40 desktop/phone browser tests, and npm bundle smoke testing. A fresh app created with the native CLI installed the published package and successfully completed a live lakehouse query in the browser.