Skip to content

fix(security): move shadcn CLI from dependencies to devDependencies (GH-171) - #10

Merged
dennisofficial merged 1 commit into
mainfrom
dennis/p3-fix-sweep
Sep 23, 2026
Merged

dennisofficial merged 1 commit into
mainfrom
dennis/p3-fix-sweep

Conversation

@dennisofficial

@dennisofficial dennisofficial commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Finding

GH-171 (P3, hardening): the published npm package @trycompai/design-system declared shadcn — the shadcn CLI (bin: { shadcn: dist/index.js }), not a runtime library — under dependencies. No source file imports it, so every downstream consumer (including Comp AI's production apps) installed the CLI plus its ~35 transitive dependencies (Babel toolchain, msw, ts-morph, @modelcontextprotocol/sdk, browserslist, …) for zero runtime benefit. Pure install/attack-surface bloat.

What changed

  • packages/design-system/package.json: moved "shadcn": "^3.6.2" from dependencies to devDependencies. Kept (not removed) because components.json is the shadcn CLI config — the CLI is still used for local component scaffolding, it just must not ship to consumers.
  • pnpm-lock.yaml / bun.lock: regenerated with pnpm install / bun install. The bun.lock diff also absorbs pre-existing drift (stale 1.0.8 version entry, the apps/design-system-mcp → apps/mcp rename, storybook deps) that the stale lockfile had not recorded; the shadcn move itself is the dependencies → devDependencies relocation in both lockfiles.

Verification

  • grep -rnE "(from|require\()\s*['\"]shadcn['\"]" packages/design-system/{src,lib,hooks} → no hits; only remaining repo mentions of "shadcn" are components.json (CLI config), package keywords, and avatar URLs in storybook stories.
  • pnpm run typecheck (turbo): 3/3 tasks pass.
  • pnpm run build (turbo): 3/3 tasks pass, including the storybook static build.
  • pnpm run lint: fails identically on clean origin/main (pre-existing prettier drift: 80 files in packages/design-system, 20 in apps/mcp); the edited package.json itself is prettier-clean. No new lint issues introduced.
  • Lockfile diff confirms shadcn now resolves under the importer's devDependencies only, so published-package consumers no longer pull it in.

Summary by cubic

Moves the shadcn CLI from dependencies to devDependencies so consumers of @trycompai/design-system no longer install the CLI and its ~35 transitive dependencies (Babel toolchain, msw, ts-morph, @modelcontextprotocol/sdk, browserslist). The CLI is still used locally for component scaffolding via components.json.

Regenerated pnpm-lock.yaml and bun.lock. The bun.lock diff also absorbs pre-existing drift (version bump, apps/design-system-mcp → apps/mcp rename, storybook deps).

Written for commit 93f2169. Summary will update on new commits.

Review in cubic

The shadcn package is the component-scaffolding CLI (bin: shadcn), never
imported at runtime by @trycompai/design-system. Declaring it under
dependencies forced every consumer of the published package - including
Comp AI's production apps - to install the CLI and its ~35 transitive
dependencies (Babel toolchain, msw, ts-morph, @modelcontextprotocol/sdk,
browserslist) for zero runtime benefit.

Move it to devDependencies so it stays available for local component
scaffolding via components.json but no longer ships to consumers.

GH-171
@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
design-system-storybook Ready Ready Preview Sep 23, 2026 7:01pm UTC

Request Review

@dennisofficial
dennisofficial marked this pull request as ready for review September 23, 2026 20:11
@dennisofficial
dennisofficial merged commit 32dd2b3 into main Sep 23, 2026
5 of 10 checks passed

This branch was successfully deployed

1 active deployment
Preview — 93f21696 Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant