fix(publish): make the coverage guard's npm-pack inspection script-safe

The prepack guard shelled out to `npm pack --dry-run --ignore-scripts --json`,
but the `--ignore-scripts` flag is not reliably honored by npm pack's
prepare/prepack lifecycle on the CI npm — so build.js ran, polluted the --json
stdout with `[build] …`, and the guard's JSON.parse threw. That broke every
`npm pack` (packaged-install-smoke on ubuntu+windows) and failed the guard's own
real-repo unit test (the only coverage-job failure). Force script-skipping via
the reliable `npm_config_ignore_scripts` env config (also removes the prepack
re-entry/recursion risk) and parse defensively from the JSON-array start.
This commit is contained in:
Gergo Magyar 2026-06-09 13:50:19 +00:00
parent 19e5859e11
commit 5cdd395f7e

View file

@ -93,8 +93,18 @@ function packFileSet(cwd) {
cwd,
encoding: 'utf8',
stdio: ['ignore', 'pipe', 'ignore'],
// The `--ignore-scripts` FLAG is not reliably honored by `npm pack`'s
// prepare/prepack lifecycle on every npm version — when it isn't, build.js
// runs (polluting this --json stdout with `[build] …`) AND, since this guard
// runs in prepack, the inner pack would re-enter the guard (recursion). The
// `npm_config_ignore_scripts` env config IS reliable, so set it too.
env: { ...process.env, npm_config_ignore_scripts: 'true' },
});
const parsed = JSON.parse(out);
// Defensive: if any lifecycle/build output still precedes the JSON array on
// stdout (e.g. `[build] …`), parse from the array start (`[` then `{`) rather
// than the raw stream. `[build]` does NOT match (no `{` after the bracket).
const start = out.search(/\[\s*\{/);
const parsed = JSON.parse(start >= 0 ? out.slice(start) : out);
const files = (parsed[0] && parsed[0].files) || [];
return new Set(files.map((f) => f.path.replace(/\\/g, '/')));
}