mirror of
https://github.com/zhu1090093659/dsh-web.git
synced 2026-09-28 14:24:03 +08:00
The root package.json is private and unpublished, so the release bump never moved its version: a git or link install of the repository kept reporting 0.1.1 in the plugin manager long after the family reached 0.4.x. The root alias is part of the released contract, so pin its own version the same way its aggregate dependency is pinned: verify-version now fails the publish when the root version drifts from the tag, and the release bump covers the root manifest beside the family packages.
52 lines
2.6 KiB
JavaScript
52 lines
2.6 KiB
JavaScript
/**
|
|
* The repository root is a thin alias bundle over the published npm aggregate:
|
|
* its patch is the aggregate's generated manifest, while every module the rows
|
|
* reference resolves from the `@linxin666/dsh-web-all` dependency. That
|
|
* dependency must name one exact released version — the version whose package
|
|
* exports match the patch rows in the same commit. A range admits any version
|
|
* in it, so an install that keeps an older lockfile entry mounts rows whose
|
|
* subpaths the installed aggregate does not export: Node throws
|
|
* ERR_PACKAGE_PATH_NOT_EXPORTED for every row and the plugin tree fails to
|
|
* load (issue #1442).
|
|
*
|
|
* The root is private and never published, but it is the manifest a git or
|
|
* link install of the repository reports, so its own version follows the
|
|
* release like every family package.
|
|
*/
|
|
|
|
/** The aggregate dependency the root alias resolves every row's modules from. */
|
|
export const ROOT_AGGREGATE_DEPENDENCY = '@linxin666/dsh-web-all'
|
|
|
|
/** Narrow an untrusted manifest value to a plain record. */
|
|
const record = (value) => value !== null && typeof value === 'object' ? value : undefined
|
|
|
|
/**
|
|
* Check the root alias dependency against the release tag.
|
|
* @param {unknown} rootManifest - parsed repository root package.json.
|
|
* @param {string} version - release tag version, without the leading v.
|
|
* @returns {string | undefined} the mismatch message, or undefined when the
|
|
* root pins exactly the tag version.
|
|
*/
|
|
export function rootAggregatePinMismatch(rootManifest, version) {
|
|
const dependencies = record(rootManifest)?.dependencies
|
|
const spec = record(dependencies)?.[ROOT_AGGREGATE_DEPENDENCY]
|
|
if (spec === version) return undefined
|
|
return `root dependency ${ROOT_AGGREGATE_DEPENDENCY} ${typeof spec === 'string' ? spec : '(missing)'} does not match tag v${version}`
|
|
}
|
|
|
|
/**
|
|
* Check the root alias's own version against the release tag. The root package
|
|
* is private and never published, but a git or link install of the repository
|
|
* reports this version — the plugin manager reads the installed manifest — so
|
|
* it follows the release like every family package.
|
|
* @param {unknown} rootManifest - parsed repository root package.json.
|
|
* @param {string} version - release tag version, without the leading v.
|
|
* @returns {string | undefined} the mismatch message, or undefined when the
|
|
* root carries the tag version.
|
|
*/
|
|
export function rootVersionMismatch(rootManifest, version) {
|
|
const declared = record(rootManifest)?.version
|
|
if (declared === version) return undefined
|
|
return `root version ${typeof declared === 'string' ? declared : '(missing)'} does not match tag v${version}`
|
|
}
|