From 6517749c40175ff58cf57a462c1be95a6f061b9a Mon Sep 17 00:00:00 2001 From: David Matejka Date: Thu, 10 Sep 2026 11:20:18 +0200 Subject: [PATCH] fix(release): pin the type toolchain the artifact validator installs The consumer harness installs with npm and no lockfile, so every version it does not pin floats. It pinned typescript and the @types it names, but not @types/node: that one arrived through bun-types, which asks for '*'. bun reads '*' as the newest version and npm reads it as the latest dist-tag, so the two managers disagreed and the harness got @types/node 22 under bun-types 1.4. The repository never noticed, because it installs with bun against the lockfile. Only the validator installs the other way, and it broke there alone: an empty file failed to compile against bun-types with four missing Node globals, failing the v0.2.3 publish before anything reached npm. Declare @types/node in the catalog and consume it at the root, so bun pins the version the harness now installs. The resolved version does not change. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01XtPnrL2GXJVhNxFoBDq4yt --- bun.lock | 2 ++ package.json | 4 +++- scripts/npm-publish/pack-and-validate.mjs | 2 ++ 3 files changed, 7 insertions(+), 1 deletion(-) diff --git a/bun.lock b/bun.lock index aa7e63a4..5e0240d4 100644 --- a/bun.lock +++ b/bun.lock @@ -5,6 +5,7 @@ "": { "devDependencies": { "@biomejs/biome": "catalog:build", + "@types/node": "catalog:", "tsc-alias": "^1.8.16", "typescript": "5.9.3", }, @@ -191,6 +192,7 @@ }, "catalog": { "@types/bun": "^1.3.3", + "@types/node": "^25.5.0", }, "catalogs": { "build": { diff --git a/package.json b/package.json index 390ab2dc..2db9a9c2 100644 --- a/package.json +++ b/package.json @@ -12,6 +12,7 @@ }, "devDependencies": { "@biomejs/biome": "catalog:build", + "@types/node": "catalog:", "tsc-alias": "^1.8.16", "typescript": "5.9.3" }, @@ -20,7 +21,8 @@ "packages/*" ], "catalog": { - "@types/bun": "^1.3.3" + "@types/bun": "^1.3.3", + "@types/node": "^25.5.0" }, "catalogs": { "build": { diff --git a/scripts/npm-publish/pack-and-validate.mjs b/scripts/npm-publish/pack-and-validate.mjs index afc3a5b2..6266b4cc 100644 --- a/scripts/npm-publish/pack-and-validate.mjs +++ b/scripts/npm-publish/pack-and-validate.mjs @@ -83,6 +83,8 @@ for (const entry of packed) { devDependencies: { typescript: rootPackage.devDependencies.typescript, '@types/bun': rootPackage.workspaces.catalog['@types/bun'], + // bun-types asks for @types/node '*'; npm reads that as the stale latest tag, bun as the newest. + '@types/node': rootPackage.workspaces.catalog['@types/node'], '@types/react': clientReact?.devDependencies?.['@types/react'], '@types/react-dom': clientReact?.devDependencies?.['@types/react-dom'], },