Repository navigation
fix: load native ESM configuration and verify fresh package entry points - #733
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 13 minutes. View limit details
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Coverage Report
File Coverage
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
de4ab82 to
ae78e43
Compare
Jamie-BitFlight
left a comment
There was a problem hiding this comment.
Fresh review found one confirmed, low-severity regression-coverage gap in the native-library completion test. The current production return/await chain is correct; the inline finding concerns a test that passes when that contract is deliberately broken. No additional runtime defect was established in the package/configuration change.
Preserve absent, empty, null, and multiline default distinctions in the exact README verifier. Exercise real YAML generation under both formatting settings and require corrupted default projections to fail.
Access nconf through its native default export and preserve configuration precedence. Build before native CLI and library contract tests, retain active coverage output, and run the fresh package suite before external integrations. Capture the complete README when native import resolves so a pending write cannot pass the completion assertion by finishing during process shutdown.
ae78e43 to
5f92784
Compare
## [2.0.5](v2.0.4...v2.0.5) (2026-10-11) ### Bug Fixes * add CLI-only generation error boundary ([#654](#654)) ([#725](#725)) ([6a27eaa](6a27eaa)) * **ci:** honor explicit Node versions before automatic detection ([95a9e68](95a9e68)) * **ci:** honor explicit Node versions in the test matrix ([#735](#735)) ([3f03f0d](3f03f0d)) * complete SVG writes before reporting success ([#717](#717)) ([170e499](170e499)) * consistently interpret GitHub Actions environment flag ([#670](#670)) ([#723](#723)) ([68756ad](68756ad)) * fail generation on formatting and requested save errors ([#654](#654)) ([#718](#718)) ([bb48434](bb48434)) * guard malformed runs metadata and preserve load error causes ([#720](#720)) ([c6caf7a](c6caf7a)) * load native ESM configuration and verify fresh package entry points ([5f92784](5f92784)) * load native ESM configuration and verify fresh package entry points ([#733](#733)) ([55746ed](55746ed)) * pair section log groups and honor Actions mode at output boundaries ([2d45100](2d45100)) * pair section log groups and honor Actions output mode ([#734](#734)) ([ceaa03a](ceaa03a)) * preserve empty metadata descriptions and cover reviewed errors ([3c0a181](3c0a181)) * preserve empty metadata descriptions and verify reviewed error paths ([#732](#732)) ([f8c0f4e](f8c0f4e)) * preserve original file read error as cause ([#722](#722)) ([05553e0](05553e0)) * validate consumed nested metadata descriptions ([#670](#670)) ([#729](#729)) ([330ab9a](330ab9a)) * validate README section configuration at input boundary ([#670](#670)) ([#726](#726)) ([40c9efd](40c9efd)) * verify declared defaults using their rendered projection ([beb2180](beb2180)) * verify empty metadata descriptions through the contract checker ([a5e2d31](a5e2d31))
|
🎉 This PR is included in version 2.0.5 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Why
A fresh build of main cannot load through the public native ESM entry. Node fails during linking because nconf 0.13.0 does not provide the named
Providerexport. The existing bundle test could use stale output and did not establish the library contract.Changes
dist. Deletingoutduring a test-owned build demonstrably removed active coverage records and caused ENOENT.CLI fixtures contain only the binary, without adjacent dependencies. Library fixtures use the public package export and declared dependencies under native Node. Success checks metadata and exact preservation outside README markers.
Dependency and scope
Depends on #732; targets main to run the existing integration trigger. Own commit 5f92784 changes four additional files:
src/inputs.ts, the package integration test,package.jsonand the integration workflow. Other changes are inherited from #732. Merge before #734.Verification
Fresh main passes the isolated CLI cases but fails both native library cases at linking. The corrected build passes all five. Existing configuration tests and scoped checks pass; the old coverage cleanup reproduces ENOENT and the correction completes coverage.
The fresh review found a P3 completion-test weakness: an empty file could satisfy the original immediate assertion while a pending write finished before subprocess exit. A separate independent checker marked the corrected full-byte observation satisfied. With a controlled delay, the real writer's
return→voidmutation fails specifically at the new equality; the old test passes that same mutation. Correct production passes both the delayed-write control and the complete package suite. Inline correction.At head
5f92784434cf65edc441ebf885ada07a134ffbc3, unit/coverage CI passed 706 tests in 24 files in each named lane, plus format/lint/type checks, build and docs. Both external integrations passed the fresh package suite, exact contract and convergence checks. Lint and both CodeQL analyses passed.Actual runtime in both lanes was Node 24.19.0. The Node 26.x label is misleading because the existing setup action ignores its explicit version input. CI correction #735 now verifies the complete inherited stack on actual Node 24.19.0 and Node 26.11.1, with 722 passing tests per lane in run 38102235836. This PR's own runs remain Node 24 evidence. No registry publication/install, Windows or macOS verification is claimed.
No generated bundles or lockfile changes are committed. Follow-up to #725 and the contracts in #670/#654.