Repository navigation
fix(security): move shadcn CLI from dependencies to devDependencies (GH-171) - #10
Merged
Merged
Conversation
The shadcn package is the component-scaffolding CLI (bin: shadcn), never imported at runtime by @trycompai/design-system. Declaring it under dependencies forced every consumer of the published package - including Comp AI's production apps - to install the CLI and its ~35 transitive dependencies (Babel toolchain, msw, ts-morph, @modelcontextprotocol/sdk, browserslist) for zero runtime benefit. Move it to devDependencies so it stays available for local component scaffolding via components.json but no longer ships to consumers. GH-171
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
dennisofficial
marked this pull request as ready for review
September 23, 2026 20:11
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Finding
GH-171 (P3, hardening): the published npm package
@trycompai/design-systemdeclaredshadcn— the shadcn CLI (bin: { shadcn: dist/index.js }), not a runtime library — underdependencies. No source file imports it, so every downstream consumer (including Comp AI's production apps) installed the CLI plus its ~35 transitive dependencies (Babel toolchain, msw, ts-morph,@modelcontextprotocol/sdk, browserslist, …) for zero runtime benefit. Pure install/attack-surface bloat.What changed
packages/design-system/package.json: moved"shadcn": "^3.6.2"fromdependenciestodevDependencies. Kept (not removed) becausecomponents.jsonis the shadcn CLI config — the CLI is still used for local component scaffolding, it just must not ship to consumers.pnpm-lock.yaml/bun.lock: regenerated withpnpm install/bun install. Thebun.lockdiff also absorbs pre-existing drift (stale1.0.8version entry, theapps/design-system-mcp→apps/mcprename, storybook deps) that the stale lockfile had not recorded; the shadcn move itself is thedependencies→devDependenciesrelocation in both lockfiles.Verification
grep -rnE "(from|require\()\s*['\"]shadcn['\"]" packages/design-system/{src,lib,hooks}→ no hits; only remaining repo mentions of "shadcn" arecomponents.json(CLI config), package keywords, and avatar URLs in storybook stories.pnpm run typecheck(turbo): 3/3 tasks pass.pnpm run build(turbo): 3/3 tasks pass, including the storybook static build.pnpm run lint: fails identically on cleanorigin/main(pre-existing prettier drift: 80 files inpackages/design-system, 20 inapps/mcp); the editedpackage.jsonitself is prettier-clean. No new lint issues introduced.shadcnnow resolves under the importer'sdevDependenciesonly, so published-package consumers no longer pull it in.Summary by cubic
Moves the
shadcnCLI from dependencies to devDependencies so consumers of@trycompai/design-systemno longer install the CLI and its ~35 transitive dependencies (Babel toolchain, msw, ts-morph,@modelcontextprotocol/sdk, browserslist). The CLI is still used locally for component scaffolding viacomponents.json.Regenerated
pnpm-lock.yamlandbun.lock. Thebun.lockdiff also absorbs pre-existing drift (version bump,apps/design-system-mcp→apps/mcprename, storybook deps).Written for commit 93f2169. Summary will update on new commits.