Skip to content

fix(build): install web deps reliably in build-all.sh - #158

Merged
chinkan merged 1 commit into
mainfrom
fix/build-all-npm-ci
Oct 6, 2026
Merged

chinkan merged 1 commit into
mainfrom
fix/build-all-npm-ci

Conversation

@chinkan

@chinkan chinkan commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Closes #159

Problem

./scripts/build-all.sh --install can fail with sh: 1: vite: not found. The old gate skipped npm ci whenever a web/node_modules directory existed and its mtime was newer than package-lock.json, so a partial, stale, or dev-less node_modules was trusted. On a fresh clone, NODE_ENV=production (or an omit=dev npm config) makes npm ci drop devDependencies, and vite is a devDependency. Reproduced: NODE_ENV=production npm ci && npm run build prints vite: not found.

Change (scripts/build-all.sh only)

  • Fail early with a clear message when node or npm is missing. The message names the missing tool, the required Node version (^20.19 or >=22.12, from vite 8 engines), how to install it, and the --skip-web escape hatch.
  • Run npm ci when web/node_modules/.package-lock.json is missing, older than web/package-lock.json, or node_modules/.bin/vite is absent. npm 7+ rewrites .package-lock.json after every install, so a lock change (for example after git pull) triggers a reinstall. Otherwise skip.
  • npm ci --include=dev, so NODE_ENV=production or omit=dev cannot drop vite.

Verification (cargo stubbed, fresh clone of this branch)

  1. Fresh clone + NODE_ENV=production ./scripts/build-all.sh --install: runs npm ci, then vite build, then cargo install.
  2. Rerun with deps present: skips npm ci, web step about 0.7s (no slowdown).
  3. touch web/package-lock.json: reinstalls.
  4. node_modules without .bin/vite: reinstalls.
  5. PATH without node: ERROR: 'node' not found ..., exit 1. PATH with node but no npm: ERROR: 'npm' not found ....

bash -n clean. No Rust changes.

Gate npm ci on node_modules/.package-lock.json freshness (and vite being
present) instead of the node_modules directory mtime, pass --include=dev so
NODE_ENV=production or an omit=dev npm config cannot drop vite, and fail
with a clear message when node or npm is missing.

chinkan commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

TL ACCEPT at f20e985 (comment — GitHub blocks Approve on same-account PR).

Script-only change matches the locked AC: missing Node/npm fails with a clear message + --skip-web hint; reinstall when .package-lock.json is missing/stale or .bin/vite is absent; npm ci --include=dev covers NODE_ENV=production / omit=dev. Freshness heuristic matches what we locked with Researcher.

Please add Closes #159 to the PR body when you push the link. Merge after Product GO + QA GO + CI green. No tag.

@chinkan
chinkan merged commit 655e6b6 into main Oct 6, 2026
13 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

build-all.sh --install fails with vite: not found when web deps are missing or omit-dev

1 participant