Skip to content

chore(package): build before packaging so a stale bundle cannot ship - #431

Merged
mtskf merged 2 commits into
mainfrom
chore/package-script-builds-first
Oct 2, 2026
Merged

mtskf merged 2 commits into
mainfrom
chore/package-script-builds-first

Conversation

@mtskf

@mtskf mtskf commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Summary

pnpm package ran only vsce package and the vsix audit. The audit checks that the payload is present, not that it is fresh, so a stale dist/ produced a passing .vsix, and on a clean checkout the command failed outright. The script now runs pnpm build first.

Changes

  • package.json: package is now pnpm build && <previous command>.
  • test/build/package-script-audits-vsix.test.ts: pin that the script starts with the build.
  • README.md, CONTRIBUTING.md: comments next to pnpm package now say it builds.

CI, publish and scripts/deploy.sh build once and call vsce directly, so they are unaffected. vscode:prepublish is deliberately not used: vsce always runs it, which would make those paths build again.

Test Plan

  • New assertion fails without the package.json change and passes with it.
  • Stale dist/extension.cjs plus a modified source file: pnpm package exits 0 and the packaged extension.cjs contains the new source string and not the stale marker.
  • Injected type error: pnpm package exits 2 with TS2322 and no .vsix is produced.
  • lint and unit tests pass.

mtskf added 2 commits October 2, 2026 10:17
pnpm package only ran vsce + the vsix audit, and the audit checks presence, not freshness, so a stale dist/ produced a passing .vsix (and a clean checkout failed outright). Chain pnpm build in front. CI, publish and deploy call vsce directly after their own build, so they are unaffected.
@mtskf
mtskf merged commit f291373 into main Oct 2, 2026
2 checks passed
@mtskf
mtskf deleted the chore/package-script-builds-first branch October 2, 2026 00:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant