Skip to content

Fix unmet dependency errors by stripping bundledDependencies in WASM package - #20526

Open
abdelrhmanahmed255 wants to merge 1 commit into
tailwindlabs:mainfrom
abdelrhmanahmed255:fix/issue-19136
Open

abdelrhmanahmed255 wants to merge 1 commit into
tailwindlabs:mainfrom
abdelrhmanahmed255:fix/issue-19136

Conversation

@abdelrhmanahmed255

Copy link
Copy Markdown

Problem

When installing @tailwindcss/postcss in an environment using strict npm (especially npm 11+), users experience ELSPROBLEMS and unmet dependency errors related to the WASM fallback runtime packages (@emnapi/core, @emnapi/wasi-threads, @napi-rs/wasm-runtime, @tybys/wasm-util).

The issue stems from @tailwindcss/oxide-wasm32-wasi listing these packages in both dependencies and bundledDependencies. Because of how pnpm workspaces (which this monorepo uses) handle symlinking, the actual node_modules are not fully packed into the published tarball for bundledDependencies. When end-users install the package using npm, npm expects bundled dependencies to already exist inside the downloaded tarball and skips fetching them from the registry. Since they are missing from the tarball, npm ls surfaces unmet dependency errors and blocks strict installations.

Solution

This PR strips the bundledDependencies array from @tailwindcss/oxide-wasm32-wasi/package.json.

Since these packages are already correctly listed under standard dependencies, removing them from bundledDependencies forces npm, yarn, and pnpm to correctly fetch and resolve them from the registry during installation, completely eliminating the npm ls errors.

Implementation details:

  1. Manually removed bundledDependencies from crates/node/npm/wasm32-wasi/package.json.
  2. Updated crates/node/scripts/move-artifacts.mjs to automatically strip bundledDependencies from the package.json during the postbuild:wasm lifecycle. This ensures that even if @napi-rs/cli automatically injects bundledDependencies during napi build --target wasm32-wasip1-threads, they are stripped immediately before packing/publishing.

Verification

Locally verified that the package.json in npm/wasm32-wasi is correctly mutated post-build and no longer includes bundledDependencies, while preserving all functional dependencies.

@abdelrhmanahmed255
abdelrhmanahmed255 requested a review from a team as a code owner September 27, 2026 13:31
@greptile-apps

greptile-apps Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Medium risk] Modifies package metadata for a WASM build artifact.

The PR appears safe to merge, though an npm tarball-install regression test would help protect the fix.

Reviews (1) · Last reviewed commit: "Strip bundledDependencies from wasm pack..."

Comment on lines +44 to +46
if (wasmPkg.bundledDependencies) {
delete wasmPkg.bundledDependencies
await fs.writeFile(wasmPkgPath, JSON.stringify(wasmPkg, null, 2) + '\n')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Npm fix lacks regression coverage

The existing WASM tests install through pnpm and check that the runtime loads. They do not test the npm installation error this change addresses. A test that packs the built WASM package, installs it with npm, and runs npm ls would catch a release tarball that still causes unmet-dependency errors.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 78fe471d-b087-4cad-b357-336191ee5d02

📥 Commits

Reviewing files that changed from the base of the PR and between fa81d69 and 38cbc2c.

📒 Files selected for processing (2)
  • crates/node/npm/wasm32-wasi/package.json
  • crates/node/scripts/move-artifacts.mjs

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


Walkthrough

The WASI package manifest no longer lists bundledDependencies. After moving WASI artifacts, the script checks whether the manifest exists. If it does and contains that property, the script removes it and rewrites the JSON.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 38cbc

The WASI package retains its regular dependencies, and the build removes the bundle metadata before packaging. No actionable merge risk is established.

Architecture Summary

Architecture risk: 🔵 Low · up to 38cbc

The change affects 1 system.

Changed systems: crates

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — crates (service) was modified; 2 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in crates/node/npm/wasm32-wasi/package.json: Removed bundledDependencies, which explicitly listed the six packages declared as dependencies.
  • observed — Modified behavior in crates/node/scripts/move-artifacts.mjs: After moving the WASI artifacts, the script checks whether the WASI package manifest can be statted. If so, it parses the manifest and, when bundledDependencies is present, deletes that property, rewrites the manifest, and logs the change. The previous code had no manifest check or modification.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: removing bundledDependencies to fix unmet dependency errors in the WASM package.
Description check ✅ Passed The description directly explains the unmet dependency problem, the cause, the package changes, and the verification performed.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant