Skip to content

The host runs Composer 0.26.0: one config file, no prisma-composer binary (8.0.0-rc.20) - #330

Merged
wmadden-electric merged 8 commits into
mainfrom
one-config-file/composer-0-26
Oct 5, 2026
Merged

wmadden-electric merged 8 commits into
mainfrom
one-config-file/composer-0-26

Conversation

@wmadden-electric

Copy link
Copy Markdown
Contributor

Slice 3 of the one-config-file project (prisma/orm#30536). Composer 0.26.0 published the merged config (prisma/composer#328) and dropped the prisma-composer binary (prisma/composer#331); this PR makes the host carry it. Merging publishes prisma@8.0.0-rc.20.

From a Composer project outside any workspace, with this branch's prisma and Composer 0.26.0 from the registry:

$ prisma dev module.ts           # with prisma-composer.config.ts left beside prisma.config.ts
CLI.CONFIG_SECTION_INVALID  The 'composer' section of .../prisma.config.ts is invalid.
  CONFIG.FILE_RETIRED  .../prisma-composer.config.ts is no longer read. Composer reads its
  configuration only from the `composer` section of prisma.config.ts. ...
$ prisma --version
8.0.0-rc.20

The decision

@prisma/cli and prisma pin @prisma/composer-cli and @prisma/composer at 0.26.0 and the version advances to 8.0.0-rc.20, so prisma@latest runs Composer's family with the composer section of prisma.config.ts as its configuration. The automatic pin-bump workflow did not fire (Composer's publish could not notify this repository), so this PR carries the bump.

What the bump changes in the host

  • Tests. The config fixture that held composer: { configPath } now proves the retirement: dev --config against it fails with the engine's CLI.CONFIG_SECTION_INVALID headline and Composer's CONFIG.FIELD_RETIRED diagnostic, exit 2, on every platform, since validation now fails before the handler runs. A second fixture holds a valid section built with defineConfig as composer from @prisma/composer/config and proves the handler runs against it.
  • Conformance. The composer-cli engine-pin exception in scripts/conformance.ts is removed, as its own note said this bump would do. The suite reports nothing.
  • The shipped skill. skills/prisma-platform-core-concepts/SKILL.md no longer says prisma-composer.config.ts is mandatory or that dev fails with CONFIG.FILE_MISSING. It describes the composer section and the three retirement codes in the same terms as Composer's own skill, with the fix for each.
  • Isolation. composer-isolation.test.ts passes unchanged: mounting the 0.26.0 family still loads neither Alchemy nor effect on an unrelated command.

Verification

  • Build, typecheck, lint, cli tests (1027), cli-engine tests (1025), test:scripts, check:skill-packaging, manifest-pins, composer-isolation, and check:conformance with zero failing and zero allowed.
  • Manual QA against the published 0.26.0 in a project outside the workspace, recorded in the project folder: --version, deploy --help, dev --help exit 0 and list neither destroy nor log; the retired file gives CONFIG.FILE_RETIRED; the retired field gives CONFIG.FIELD_RETIRED; an effect forced to 4.0.0-rc.118 gives CLI.CONFIG_UNREADABLE naming the missing module while --version still exits 0.
  • prisma dev to ready still needs alchemy as a direct dependency in a plain pnpm project; that is a Composer defect fixed in prisma/composer#332, not a host matter, and will ship in Composer's next release.

Not in this PR

  • New commands. destroy and log remain operations on @prisma/composer/control; their command-line form is a separate grammar project.
  • The prisma/web pages, which land in their own PR after this release is on latest.

Agent: columbo-17

🤖 Generated with Claude Code

wmadden-electric and others added 8 commits October 5, 2026 15:37
Composer 0.26.0 moves its configuration into the composer section of
prisma.config.ts and drops the prisma-composer binary. Until it is on
the registry, both manifests pin the preview of prisma/composer#331.
The preview's composer-cli depends on @prisma/composer by URL, which
pnpm refuses in subdependencies unless blockExoticSubdeps is off.
Both go back to 0.26.0 before this merges.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 peers @prisma/cli-engine 0.6.2, the version the shell
ships, so the tarball check no longer needs to excuse a mismatch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
…es it

A composer section that still names a config file is now refused by
Composer's section validator before any handler runs: the result is
CLI.CONFIG_SECTION_INVALID carrying CONFIG.FIELD_RETIRED, exit 2, on
every platform, so the Windows variant of the test goes away.

A second fixture builds a valid section with defineConfig from
@prisma/composer/config and nodeBuild(), and shows dev accepting it and
reaching its handler. Its state descriptor is written by hand: the
Prisma Cloud control entry would bring the whole cloud target and the
ORM toolchain into the host's dev dependencies.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
prisma init installs this skill into every new project, and it still
said dev and deploy need a separate prisma-composer.config.ts. With
Composer 0.26.0 that file is refused; the skill now shows the composer
section and the three CONFIG codes the way Composer's own skill does.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
The configPath test now checks the headline summary, which names the
section and the file, and the diagnostic's severity. The valid-section
test checks that the handler's failure names the entry the host
passed, so it shows the argv reached composer's dev rather than only
that some composer code came back.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
A new project with no composer section gets CONFIG.SECTION_MISSING and
has no old file to move, so the skill now says to write the section in
that case and to move the old contents only for the other two codes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 is on latest, so both manifests pin it in place of the
pkg.pr.new preview, and the workspace stops allowing URL dependencies
below the top level, which only the preview needed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
Merging publishes prisma@latest pinning Composer 0.26.0, whose
configuration is the composer section of prisma.config.ts.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: a17bab11-2b49-4956-98cb-3317c800ac77
📥 Commits

Reviewing files that changed from the base of the PR and between 5be86dd and 2b26755.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (13)
  • package.json
  • packages/cli-conformance/package.json
  • packages/cli-engine/package.json
  • packages/cli-telemetry/package.json
  • packages/cli/package.json
  • packages/cli/scripts/conformance.ts
  • packages/cli/tests/bin.test.ts
  • packages/cli/tests/fixtures/config/composer-config-path.config.ts
  • packages/cli/tests/fixtures/config/composer-valid.config.ts
  • packages/compute/package.json
  • packages/prisma/package.json
  • packages/tsconfig/package.json
  • skills/prisma-platform-core-concepts/SKILL.md
💤 Files with no reviewable changes (1)
  • packages/cli/scripts/conformance.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Bug Fixes
    • Composer commands now validate configuration consistently: the retired configPath field is rejected with a specific diagnostic, while valid Composer settings proceed to platform or entry-point checks.
  • Documentation
    • Updated setup guidance to use a single prisma.config.ts for ORM, Composer, and Skills settings. Clarified that dev and deploy read the Composer section and documented migration away from separate Composer config files and the retired configPath field.

Walkthrough

Package and workspace versions advance to 8.0.0-rc.20, and Composer CLI dependencies advance to 0.26.0. CLI tests and skill documentation describe a single prisma.config.ts configuration with a composer section. Tests check the retired configPath diagnostic and the result of loading a valid Composer entry.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 2b267

This change updates package versions and Composer configuration guidance and tests. No concrete merge-blocking issue was found, so it appears ready to merge after normal CI checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2b267

The configuration contract changes, but the host retains validation before command execution. No introduced security issue was established. Composer 0.26.0’s internal state-management and recovery behavior could not be independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant exposure is the existing local CLI process consuming project configuration and invoking Composer handlers. The inspected change does not establish a new remote entrypoint or expanded tenant authority. Maximum downstream asset, environment, and data-store exposure cannot be bounded without the target Composer implementation and its configured extensions.

Trust Boundaries and Controls

  • observed — The loader evaluates the selected config through c12 and checks that the resolved file matches the requested real path. Section validation occurs afterward, before handler execution. Thus the validation gate controls command dispatch; it is not a sandbox for configuration evaluation. This ordering predates the PR.

Resilience and Maintainability Implications

  • observed — The host returns before dispatch on configuration errors and centrally settles handler outcomes. These controls support failure containment, but neither they nor the intentionally throwing fixture establish Composer 0.26.0’s persistent-resource behavior after partial failure, interruption, repeated invocation, or concurrent execution. The available installed Composer CLI is the older 0.25.0 release.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the Composer 0.26.0 upgrade and the move to one config file without the prisma-composer binary.
Description check ✅ Passed The description explains the Composer upgrade, config changes, tests, verification, and scope. It is directly related to the changeset.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 3 files. (9 skipped: 9 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 5, 2026

Copy link
Copy Markdown

Open in StackBlitz

npx https://pkg.pr.new/@prisma/cli@330
npx https://pkg.pr.new/@prisma/cli-engine@330

commit: 2b26755

@wmadden-electric
wmadden-electric merged commit 6c41548 into main Oct 5, 2026
16 checks passed
@wmadden-electric
wmadden-electric deleted the one-config-file/composer-0-26 branch October 5, 2026 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant