fix(deps): drop stale @aws-sdk/core override + add desktop packaging CI gate (#1885)
## Problem
The Windows desktop installer can't package from `main`.
electron-builder's production-dependency walk rejects the staged deploy
closure:
```
⨯ Production dependency @aws-sdk/core not found for package @aws-sdk/credential-provider-env version=^3.974.27
```
**Root cause:** an incidental `pnpm.overrides` entry — `"@aws-sdk/core":
"3.974.26"` — added without rationale in an unrelated commit
(`91fb53f3c`, "add agent update tool"). The bundled Fusion agent
packages later pulled `@aws-sdk/*` versions requiring `^3.974.27`, but
the exact-version override force-held core at `.26`. Classic
stale-exact-pin trap. It only surfaced at release/local-build time
because **nothing in the merge gate validates the packageable closure**
— electron-builder's walk ran only in `workflow_dispatch`/release
workflows.
## Fix (item 1)
Remove the `@aws-sdk/core` override. The `--legacy` deploy closure then
resolves core to `3.974.27` (satisfies all consumers). The main lockfile
still resolves core to `3.974.26` for its own internally-consistent
graph, so the **published `@runfusion/fusion` closure is unchanged** (no
changeset needed).
**Verified locally:** a fresh `pnpm --filter @fusion/desktop build` +
`electron-builder` passes the dependency walk and produces the installer
with **no manual patching** (previously required hand-editing the
deploy's core version).
## Prevention (items 2 + 3)
New **advisory, path-gated `Desktop packaging`** job in `pr-checks.yml`:
- `pnpm dedupe --check` — early-warning for lockfile version drift
(non-fatal).
- `pnpm --filter @fusion/desktop build` + `electron-builder --dir` —
reproduces the authoritative production-dependency walk (skips
NSIS/signing for speed; the walk that catches skew is
platform-independent, so ubuntu suffices).
- Path-gated to `pnpm-lock.yaml` / `package.json` /
`pnpm-workspace.yaml` / `packages/{desktop,dashboard,engine,core}` /
`plugins/` so it only runs when the closure can change.
So any future dependency skew — for **any** dependency — fails at PR
time instead of at release.
### Why not required / not in `full-suite.yml`
Kept **out of the required set** so the thin merge gate stays exactly
`[Lint, Typecheck, Build, Gate]` and branch protection is untouched (per
the gate's design docs). It reports a status on PRs; promote to
merge-blocking by adding "Desktop packaging" to the repo's required
checks. Placed in `pr-checks.yml` (not `full-suite.yml`) so it runs at
**PR time** rather than only post-merge.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Added an extra, PR-only non-blocking desktop packaging validation when
relevant project files change.
* The check builds the desktop package and verifies production
dependency consistency earlier in the review process.
* Updated dependency override settings by removing an outdated version
pin while keeping other pinned packages unchanged.
* Improved workflow comments to clarify how merge-blocking status checks
are handled.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
79
.github/workflows/desktop-packaging.yml
vendored
Normal file
79
.github/workflows/desktop-packaging.yml
vendored
Normal file
@@ -0,0 +1,79 @@
|
||||
name: Desktop packaging
|
||||
|
||||
# FNXC:CI 2026-07-03-18:20:
|
||||
# Advisory desktop-packaging validation, kept in its OWN workflow so the thin merge gate
|
||||
# (pr-checks.yml) stays exactly [Lint, Typecheck, Build, Gate] — that file's job set maps
|
||||
# 1:1 to the branch-protection required checks, and the CI-shape test enforces the invariant.
|
||||
# electron-builder's production-dependency walk is the ONLY thing that validates the packageable
|
||||
# dependency closure, and it historically ran only in workflow_dispatch / release workflows. So a
|
||||
# lockfile version skew — e.g. a stale `pnpm.overrides` entry force-holding `@aws-sdk/core` at a
|
||||
# version its consumers no longer accepted — sailed through the gate and only detonated at release /
|
||||
# local installer build time (the exact incident this job prevents). Reproduce that walk on PRs that
|
||||
# touch the dependency closure so any future skew fails HERE, for ANY dependency.
|
||||
#
|
||||
# ADVISORY, not in the required set: branch protection is untouched. Promote to merge-blocking by
|
||||
# adding "Desktop packaging" to the repo's required checks. Path-gated + electron-builder --dir
|
||||
# (skips NSIS/signing) keeps it cheap; the dependency walk that catches skew runs regardless of
|
||||
# target platform, so ubuntu suffices.
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
concurrency:
|
||||
group: desktop-packaging-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
# Least-privilege token: only reads the repo (checkout + cache).
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
# FN-4863: Opt JavaScript actions into Node 24 ahead of GitHub's forced cutover on 2026-06-02.
|
||||
env:
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
|
||||
|
||||
jobs:
|
||||
desktop-pack:
|
||||
name: Desktop packaging
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 25
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
# Need history to diff against the PR base for the path gate below.
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Detect dependency / desktop-closure changes
|
||||
id: changes
|
||||
run: |
|
||||
base="${{ github.event.pull_request.base.sha }}"
|
||||
if git diff --name-only "$base"...HEAD \
|
||||
| grep -qE '^(pnpm-lock\.yaml|package\.json|pnpm-workspace\.yaml|packages/(desktop|dashboard|engine|core)/|plugins/)'; then
|
||||
echo "relevant=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "relevant=false" >> "$GITHUB_OUTPUT"
|
||||
echo "No dependency/desktop-closure changes; skipping the packaging walk."
|
||||
fi
|
||||
|
||||
- name: Setup Node.js and pnpm
|
||||
if: steps.changes.outputs.relevant == 'true'
|
||||
uses: ./.github/actions/setup-node-pnpm
|
||||
|
||||
# Early-warning (item 3): a lockfile that can still be deduped often signals the version drift that
|
||||
# later breaks packaging. Non-fatal — surfaces as a warning so it informs without failing on benign
|
||||
# dedupe opportunities.
|
||||
- name: Lockfile dedupe check (early warning)
|
||||
if: steps.changes.outputs.relevant == 'true'
|
||||
run: pnpm dedupe --check || echo "::warning::pnpm dedupe --check found dedupable/inconsistent dependencies; run 'pnpm dedupe' and review."
|
||||
|
||||
- name: Build desktop package (stages the production deploy closure)
|
||||
if: steps.changes.outputs.relevant == 'true'
|
||||
run: pnpm --filter @fusion/desktop build
|
||||
|
||||
# Authoritative check: electron-builder's production-dependency walk over the staged closure.
|
||||
# --dir skips installer/signing but still FAILS if any production dependency's declared version
|
||||
# range is unsatisfied in the closure — which is exactly the aws-sdk skew that broke the release.
|
||||
- name: Validate packageable closure (electron-builder --dir)
|
||||
if: steps.changes.outputs.relevant == 'true'
|
||||
run: pnpm --filter @fusion/desktop exec electron-builder --projectDir deploy --dir --publish never
|
||||
4
.github/workflows/pr-checks.yml
vendored
4
.github/workflows/pr-checks.yml
vendored
@@ -130,3 +130,7 @@ jobs:
|
||||
|
||||
- name: Gate tests (curated engine-core + CI-shape)
|
||||
run: pnpm test:gate
|
||||
|
||||
# Advisory desktop-packaging validation lives in its OWN workflow (desktop-packaging.yml) so this
|
||||
# thin gate stays exactly [Lint, Typecheck, Build, Gate] — the job set here maps 1:1 to the
|
||||
# branch-protection required checks (CI-shape test enforces the invariant).
|
||||
|
||||
@@ -94,7 +94,6 @@
|
||||
"protobufjs"
|
||||
],
|
||||
"overrides": {
|
||||
"@aws-sdk/core": "3.974.26",
|
||||
"@types/node": "^25.5.2",
|
||||
"protobufjs": "^7.5.8"
|
||||
}
|
||||
|
||||
1
pnpm-lock.yaml
generated
1
pnpm-lock.yaml
generated
@@ -5,7 +5,6 @@ settings:
|
||||
excludeLinksFromLockfile: false
|
||||
|
||||
overrides:
|
||||
'@aws-sdk/core': 3.974.26
|
||||
'@types/node': ^25.5.2
|
||||
protobufjs: ^7.5.8
|
||||
|
||||
|
||||
Reference in New Issue
Block a user