fix(scripts): disclose browser-bundled packages as shipped
Moving react, shiki, katex and the markdown pipeline to devDependencies took them out of the notices runtime tier, which tiers by declaring section — yet their code is inside lib/client.js and the shell dist. The generator now learns what the browser artifacts carry from the real build configs: each client bundle through its own tsdown config, the shell through apps/web's Vite config, with a recorder that resolves each bare specifier, notes the package behind it, and stops there. About three seconds, and only packages a resolved file backs, so a bundler's virtual module is not mistaken for a shipped one. Net effect on the file: the type-only packages @types/mdast and micromark-util-types move to the development tier, because neither ships code.
This commit is contained in:
@@ -28,7 +28,7 @@ pre-commit:
|
||||
# lefthook only inspects files present on disk — so that one case still
|
||||
# falls through to the freshness assertion in the test lane.
|
||||
- name: third-party notices (staged)
|
||||
glob: '{package.json,*/package.json,*/*/package.json,*/*/*/package.json,*/*/*/*/package.json,pnpm-workspace.yaml,*/*/pnpm-workspace.yaml,pnpm-lock.yaml,vendor/README.md,python/*/pyproject.toml,scripts/gen-third-party-notices.ts,scripts/build-exe-for-python-sdk.ts}'
|
||||
glob: '{package.json,*/package.json,*/*/package.json,*/*/*/package.json,*/*/*/*/package.json,pnpm-workspace.yaml,*/*/pnpm-workspace.yaml,pnpm-lock.yaml,vendor/README.md,python/*/pyproject.toml,scripts/gen-third-party-notices.ts,scripts/browser-bundled-externals.ts,packages/client/tsdown.client.ts,scripts/build-exe-for-python-sdk.ts}'
|
||||
run: node_modules/.bin/tsx scripts/gen-third-party-notices.ts && git add THIRD_PARTY_NOTICES.md
|
||||
|
||||
- name: whitespace (staged)
|
||||
|
||||
Reference in New Issue
Block a user