GitNexus/gitnexus/scripts/build-web.js
Gergő Magyar a348bc3957
fix(build): build the web UI from prepack, not from every npm ci (#3166)
* fix(build): build the web UI from prepack, not from every npm ci

gitnexus-web is a separate ~650-package tree (React, Vite, LangChain,
Mermaid). Because `prepare` built it, every `npm ci` in gitnexus/ also
installed and Vite-built a second product. On CI that install ran
uncached inside an execSync timeout, so a healthy-but-slow install was
SIGTERM'd mid-flight and surfaced as `spawnSync /bin/sh ETIMEDOUT` --
repeatedly killing node floor compat, a job that only import-links the
CLI dist and never needs the UI.

The UI is only needed inside the published tarball, so build it from
prepack instead. `npm run build` and `prepare` are now CLI-only; pass
--web (or npm run build:web) to include it. Jobs that pack or publish
install gitnexus-web in their own visible step, and the in-script
fallback install is untimed so a slow install can no longer be killed
halfway and reported as a build failure. The tsc/vite timeout default
goes 300s -> 600s so the remaining bounded steps have headroom.

Default build on this machine: 30s, no gitnexus-web work.

* fix(build): enforce web package artifact integrity

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(build): clarify web packaging helpers without changing behavior

Keep the same opt-in, fail-closed, and pack/publish preserve rules while
trimming comments, sharing the test harness, and reading index.html
directly instead of probing it first.

Co-authored-by: Cursor <cursoragent@cursor.com>

* ci: skip prepare on typecheck so a cold shared install cannot cancel the job

quality/typecheck's 10-minute budget was spent on an uncached gitnexus-shared
npm install plus a full prepare tsc that tsc --noEmit does not need.

Co-authored-by: Cursor <cursoragent@cursor.com>

* ci: stop typecheck-web from canceling before the npm cache can save

Hashing gitnexus-shared into the web cache key forced a cold 650-package
install; the 10-minute job then canceled and never wrote a warm cache.

Co-authored-by: Cursor <cursoragent@cursor.com>

* ci: give format the same 10-minute budget as lint

A cold root npm ci already took 4m19s and canceled prettier at the 5-minute
cap. Lint does the same install and needed 7m41s on that run.

Co-authored-by: Cursor <cursoragent@cursor.com>

* ci: stop installing TypeScript 7 just to compile gitnexus-shared

A dedicated npm ci in gitnexus-shared took 7 minutes to add two packages
(TypeScript 7's optional per-platform binaries) and cancelled typecheck,
Windows pack, and coverage shard 1. Compile shared with gitnexus's tsc.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3166)

- Run tsc via execFileSync so the compiler path is never interpolated into a shell.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3166)

- Run tsc as node typescript/bin/tsc so Windows never has to execFile a .cmd shim.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Launch tsc via node and lib/tsc.js on every OS.

The npm .bin/tsc shim is tsc.cmd on Windows, which execFileSync cannot spawn.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): lock eval containment against a dedicated shared npm ci

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-04 13:28:11 +01:00

72 lines
2.6 KiB
JavaScript

import { execSync } from 'node:child_process';
import fs from 'node:fs';
import path from 'node:path';
export function shouldBuildWeb(argv = process.argv, env = process.env) {
return argv.includes('--web') || env.GITNEXUS_BUILD_WEB === '1';
}
export function shouldPreserveWebOutput(env = process.env) {
return (
env.npm_lifecycle_event === 'prepare' &&
(env.npm_command === 'pack' || env.npm_command === 'publish')
);
}
/** Build and copy the web UI when `--web` / GITNEXUS_BUILD_WEB=1 is set. */
export function runWebBuild({
root,
dist,
timeoutMs,
argv = process.argv,
env = process.env,
fsImpl = fs,
exec = execSync,
}) {
const webRoot = path.resolve(root, '..', 'gitnexus-web');
const webDest = path.join(dist, '..', 'web');
if (!shouldBuildWeb(argv, env)) {
if (shouldPreserveWebOutput(env)) {
console.log('[build] preserving prepack web UI during npm prepare');
} else {
fsImpl.rmSync(webDest, { recursive: true, force: true });
console.log(
'[build] skipping web UI and removed stale output ' +
'(pass --web or set GITNEXUS_BUILD_WEB=1 to include it)',
);
}
return { status: 'skipped', webDest };
}
if (!fsImpl.existsSync(path.join(webRoot, 'package.json'))) {
throw new Error(
`[build] web UI requested, but gitnexus-web was not found at ${webRoot}. ` +
'Run this command from the complete monorepo checkout.',
);
}
console.log('[build] building gitnexus-web…');
if (!fsImpl.existsSync(path.join(webRoot, 'node_modules'))) {
// Deliberately untimed: this is a full second install, and killing it
// partway through leaves a broken tree and a misleading ETIMEDOUT.
// CI should install gitnexus-web itself (cached, its own step) so this
// fallback only fires for a local `npm pack` / `npm publish`.
console.log('[build] installing gitnexus-web dependencies (no local node_modules)…');
// String form uses the platform shell (cmd.exe / sh) so `npm` resolves to
// npm.cmd on Windows. execFileSync('npm') / execFileSync('npm.cmd')
// without a shell fails on Windows.
exec('npm ci', { cwd: webRoot, stdio: 'inherit' });
}
exec('npm run build', { cwd: webRoot, stdio: 'inherit', timeout: timeoutMs });
const builtIndex = path.join(webRoot, 'dist', 'index.html');
if (!fsImpl.existsSync(builtIndex)) {
throw new Error(`[build] gitnexus-web build completed without ${builtIndex}`);
}
fsImpl.rmSync(webDest, { recursive: true, force: true });
fsImpl.cpSync(path.join(webRoot, 'dist'), webDest, { recursive: true });
console.log('[build] copied web UI → gitnexus/web/');
return { status: 'built', webDest };
}