Shrink npm downloads with CLI-only release archives - #44
Merged
Merged
Conversation
AI assistance: implemented and validated with OpenAI Codex.
sidkmenon
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The npm fetcher downloads the full release archive even though it extracts only
diffr. Publishdiffr-cliarchives and select them when generating new npm pins. Repacking 0.1.4 reduced downloads from 45.8–69.1 MB to 20.6–21.6 MB (55–69%).Existing pins remain compatible with published releases. Full CLI/TUI archives and Homebrew installs remain available; checksums cover both archive types. Release CI smoke-tests the CLI-only archive with an empty PATH.
Whiteboard already uses this fetcher for build and packaging downloads. Adoption requires publishing the next diffr/npm release, then updating Whiteboard’s exact dependency pins and lockfile. The existing 0.1.4 pins are intentionally unchanged because CLI-only assets have not been published for that release.
Validation: 20 package tests, TypeScript check, npm pack dry run, actionlint, real macOS ARM archive packaging and structural NDJSON smoke, checksum/formula generation, and pin-to-fetch/check integration using real archives with the network boundary redirected locally. Cross-platform builds and Homebrew checks run in CI.
AI assistance: implemented and validated with OpenAI Codex.