fix(deps): drop stale @aws-sdk/core override + add desktop packaging CI gate

The Windows desktop installer failed to package: electron-builder's production-dependency walk rejected
`@aws-sdk/core@3.974.26` because `@aws-sdk/credential-provider-env` (resolved in the `--legacy` deploy
closure) requires `^3.974.27`. Root cause: an incidental `pnpm.overrides` entry pinning
`@aws-sdk/core` to the exact version `3.974.26` (added without rationale in an unrelated commit) which
force-held core below what its consumers now demand — the classic stale-exact-pin trap.

Fixes / prevention:
- Remove the `@aws-sdk/core` override so the deploy closure resolves core to 3.974.27 (satisfies all
  consumers). The main lockfile still resolves core to 3.974.26 for its own consistent graph, so the
  published @runfusion/fusion closure is unchanged (no changeset needed). Verified locally: a fresh
  `@fusion/desktop build` + `electron-builder --dir` now passes the dependency walk with no manual patch.
- Add an advisory, path-gated `Desktop packaging` job to pr-checks.yml that reproduces electron-builder's
  production-dependency walk (`--dir`, no NSIS/signing) plus a `pnpm dedupe --check` early-warning. This
  is the only check that validates the packageable closure, which previously ran only in release/manual
  workflows — so any future dependency skew now fails at PR time, for ANY dependency, instead of at
  release/local-build time. Kept OUT of the required set so the thin merge gate [Lint, Typecheck, Build,
  Gate] and branch protection are untouched; promote to blocking by adding it to required checks.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
gsxdsm
2026-07-03 10:28:54 -07:00
parent a318267976
commit c1fc9a7298
3 changed files with 57 additions and 2 deletions

View File

@@ -130,3 +130,60 @@ jobs:
- name: Gate tests (curated engine-core + CI-shape)
run: pnpm test:gate
# FNXC:CI 2026-07-03-11:10:
# Desktop packaging validation. electron-builder's production-dependency walk is the ONLY thing that
# validates the packageable dependency closure, and it historically ran only in workflow_dispatch /
# release workflows. So a lockfile version skew — e.g. a stale `pnpm.overrides` entry force-holding
# `@aws-sdk/core` at a version its consumers no longer accepted — sailed through the thin gate and only
# detonated at release / local installer build time (the exact incident this job prevents). Reproduce
# that walk on PRs that touch the dependency closure so any future skew fails HERE, for ANY dependency.
#
# ADVISORY, not in the required set: the merge gate stays exactly [Lint, Typecheck, Build, Gate] and
# branch protection is untouched. Promote to merge-blocking by adding "Desktop packaging" to the repo's
# required checks. Path-gated + electron-builder --dir (skips NSIS/signing) keeps it cheap; the
# dependency walk that catches skew runs regardless of target platform, so ubuntu suffices.
desktop-pack:
name: Desktop packaging
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- name: Checkout
uses: actions/checkout@v4
with:
# Need history to diff against the PR base for the path gate below.
fetch-depth: 0
- name: Detect dependency / desktop-closure changes
id: changes
run: |
base="${{ github.event.pull_request.base.sha }}"
if git diff --name-only "$base"...HEAD \
| grep -qE '^(pnpm-lock\.yaml|package\.json|pnpm-workspace\.yaml|packages/(desktop|dashboard|engine|core)/|plugins/)'; then
echo "relevant=true" >> "$GITHUB_OUTPUT"
else
echo "relevant=false" >> "$GITHUB_OUTPUT"
echo "No dependency/desktop-closure changes; skipping the packaging walk."
fi
- name: Setup Node.js and pnpm
if: steps.changes.outputs.relevant == 'true'
uses: ./.github/actions/setup-node-pnpm
# Early-warning (item 3): a lockfile that can still be deduped often signals the version drift that
# later breaks packaging. Non-fatal — surfaces as a warning so it informs without failing on benign
# dedupe opportunities.
- name: Lockfile dedupe check (early warning)
if: steps.changes.outputs.relevant == 'true'
run: pnpm dedupe --check || echo "::warning::pnpm dedupe --check found dedupable/inconsistent dependencies; run 'pnpm dedupe' and review."
- name: Build desktop package (stages the production deploy closure)
if: steps.changes.outputs.relevant == 'true'
run: pnpm --filter @fusion/desktop build
# Authoritative check: electron-builder's production-dependency walk over the staged closure.
# --dir skips installer/signing but still FAILS if any production dependency's declared version
# range is unsatisfied in the closure — which is exactly the aws-sdk skew that broke the release.
- name: Validate packageable closure (electron-builder --dir)
if: steps.changes.outputs.relevant == 'true'
run: pnpm --filter @fusion/desktop exec electron-builder --projectDir deploy --dir --publish never

View File

@@ -94,7 +94,6 @@
"protobufjs"
],
"overrides": {
"@aws-sdk/core": "3.974.26",
"@types/node": "^25.5.2",
"protobufjs": "^7.5.8"
}

1
pnpm-lock.yaml generated
View File

@@ -5,7 +5,6 @@ settings:
excludeLinksFromLockfile: false
overrides:
'@aws-sdk/core': 3.974.26
'@types/node': ^25.5.2
protobufjs: ^7.5.8