Skip to content

Build packages with tsup - #2120

Merged
Mrtenz merged 18 commits into
tsupfrom
mrtenz/tsup
Feb 22, 2024
Merged

Build packages with tsup#2120
Mrtenz merged 18 commits into
tsupfrom
mrtenz/tsup

Conversation

@Mrtenz

Copy link
Copy Markdown
Member

This changes all packages to be built with tsup, instead of SWC. tsup uses esbuild under the hood, so performance should be comparable.

More context here: MetaMask/utils#144.

@socket-security

socket-securityBot commented Jan 22, 2024

Copy link
Copy Markdown

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

PackageNew capabilitiesTransitivesSizePublisher
npm/@esbuild/aix-ppc64@0.19.12None010.4 MBevanw
npm/@esbuild/android-arm@0.19.12None011.5 MBevanw
npm/@esbuild/android-arm64@0.19.12None09.83 MBevanw
npm/@esbuild/android-x64@0.19.12None011.5 MBevanw
npm/@esbuild/darwin-arm64@0.19.12None09.76 MBevanw
npm/@esbuild/darwin-x64@0.19.12None010.2 MBevanw
npm/@esbuild/freebsd-arm64@0.19.12None08.85 MBevanw
npm/@esbuild/freebsd-x64@0.19.12None09.61 MBevanw
npm/@esbuild/linux-arm@0.19.12None09.18 MBevanw
npm/@esbuild/linux-arm64@0.19.12None08.85 MBevanw
npm/@esbuild/linux-ia32@0.19.12None09.14 MBevanw
npm/@esbuild/linux-loong64@0.19.12None09.37 MBevanw
npm/@esbuild/linux-mips64el@0.19.12None010.4 MBevanw
npm/@esbuild/linux-ppc64@0.19.12None09.18 MBevanw
npm/@esbuild/linux-riscv64@0.19.12None09.11 MBevanw
npm/@esbuild/linux-s390x@0.19.12None010 MBevanw
npm/@esbuild/linux-x64@0.19.12None09.6 MBevanw
npm/@esbuild/netbsd-x64@0.19.12None09.59 MBevanw
npm/@esbuild/openbsd-x64@0.19.12None09.62 MBevanw
npm/@esbuild/sunos-x64@0.19.12None09.59 MBevanw
npm/@esbuild/win32-arm64@0.19.12None08.98 MBevanw
npm/@esbuild/win32-ia32@0.19.12None09.45 MBevanw
npm/@esbuild/win32-x64@0.19.12None09.81 MBevanw
npm/@rollup/rollup-android-arm-eabi@4.12.0None01.63 MBlukastaegert
npm/@rollup/rollup-android-arm64@4.12.0None02.49 MBlukastaegert
npm/@rollup/rollup-darwin-arm64@4.12.0None02.41 MBlukastaegert
npm/@rollup/rollup-darwin-x64@4.12.0None02.58 MBlukastaegert
npm/@rollup/rollup-linux-arm-gnueabihf@4.12.0None02.43 MBlukastaegert
npm/@rollup/rollup-linux-arm64-gnu@4.12.0None02.47 MBlukastaegert
npm/@rollup/rollup-linux-arm64-musl@4.12.0None02.37 MBlukastaegert
npm/@rollup/rollup-linux-riscv64-gnu@4.12.0None02.54 MBlukastaegert
npm/@rollup/rollup-linux-x64-gnu@4.12.0None02.73 MBlukastaegert
npm/@rollup/rollup-linux-x64-musl@4.12.0None02.73 MBlukastaegert
npm/@rollup/rollup-win32-arm64-msvc@4.12.0None02.93 MBlukastaegert
npm/@rollup/rollup-win32-ia32-msvc@4.12.0None02.64 MBlukastaegert
npm/@rollup/rollup-win32-x64-msvc@4.12.0None03.44 MBlukastaegert
npm/@sindresorhus/is@5.3.0None058.9 kBsindresorhus
npm/any-promise@1.3.0None022.2 kBkevinbeaty
npm/bundle-require@4.0.2environment, filesystem, unsafe Transitive: network, shell+25224 MBegoist
npm/cac@6.7.14None081.8 kBegoist
npm/chokidar@3.6.0environment, filesystem+14531 kBpaulmillr
npm/esbuild@0.19.12environment, filesystem, network, shell+23224 MBevanw
npm/joycon@3.1.1environment, filesystem014 kBegoist
npm/load-tsconfig@0.2.5None017.1 kBegoist
npm/lodash.sortby@4.7.0None075.8 kBjdalton
npm/mz@2.7.0filesystem, network, shell+452 kBjongleberry
npm/postcss-load-config@4.0.2environment, unsafe Transitive: filesystem, shell+38466 MBai
npm/rollup@4.12.0environment, filesystem+1535.8 MBlukastaegert
npm/sucrase@3.35.0Transitive: environment, filesystem, network, shell, unsafe+383.74 MBalangpierce
npm/thenify-all@1.6.0None+236.7 kBdead_horse
npm/thenify@3.3.1None+130.1 kBdead_horse
npm/tr46@1.0.1None+1356 kBsebmaster
npm/tree-kill@1.2.2shell07.82 kBwmhilton
npm/ts-interface-checker@0.1.13None068 kBdsagal2
npm/tsup@8.0.2environment, eval, filesystem Transitive: network, shell, unsafe+169731 MBegoist
npm/webidl-conversions@4.0.2None019.3 kBdomenic
npm/whatwg-url@7.1.0None+4529 kBdomenic

🚮 Removed packages:npm/@esbuild/android-arm64@0.20.1, npm/@esbuild/android-arm@0.20.1, npm/@esbuild/android-x64@0.20.1, npm/@esbuild/darwin-arm64@0.20.1, npm/@esbuild/darwin-x64@0.20.1, npm/@esbuild/freebsd-arm64@0.20.1, npm/@esbuild/freebsd-x64@0.20.1, npm/@esbuild/linux-arm64@0.20.1, npm/@esbuild/linux-arm@0.20.1, npm/@esbuild/linux-ia32@0.20.1, npm/@esbuild/linux-loong64@0.20.1, npm/@esbuild/linux-mips64el@0.20.1, npm/@esbuild/linux-ppc64@0.20.1, npm/@esbuild/linux-riscv64@0.20.1, npm/@esbuild/linux-s390x@0.20.1, npm/@esbuild/linux-x64@0.20.1, npm/@esbuild/netbsd-x64@0.20.1, npm/@esbuild/openbsd-x64@0.20.1, npm/@esbuild/sunos-x64@0.20.1, npm/@esbuild/win32-arm64@0.20.1, npm/@esbuild/win32-ia32@0.20.1, npm/@esbuild/win32-x64@0.20.1, npm/@mole-inc/bin-wrapper@8.0.1, npm/@sindresorhus/is@4.6.0, npm/@swc/cli@0.1.65, npm/@szmarczak/http-timer@4.0.6, npm/@tokenizer/token@0.3.0, npm/arch@2.2.0, npm/bin-check@4.1.0, npm/bin-version-check@5.1.0, npm/bin-version@6.0.0, npm/cacheable-lookup@5.0.4, npm/cacheable-request@7.0.4, npm/commander@7.2.0, npm/esbuild@0.20.1, npm/executable@4.1.1, npm/ext-list@2.2.2, npm/ext-name@5.0.0, npm/file-type@17.1.6, npm/filename-reserved-regex@3.0.0, npm/filenamify@5.1.1, npm/find-versions@5.1.0, npm/got@11.8.6, npm/http2-wrapper@1.0.3, npm/is-plain-obj@1.1.0, npm/lowercase-keys@2.0.0, npm/normalize-url@6.1.0, npm/os-filter-obj@2.0.0, npm/p-cancelable@2.1.1, npm/p-finally@1.0.0, npm/peek-readable@5.0.0, npm/responselike@2.0.1, npm/semver-regex@4.0.5, npm/semver-truncate@3.0.0, npm/shebang-command@1.2.0, npm/sort-keys-length@1.0.1, npm/sort-keys@1.1.2, npm/strip-eof@1.0.0, npm/strip-outer@2.0.0, npm/strtok3@7.0.0, npm/token-types@5.0.1, npm/trim-repeated@2.0.0

View full report↗︎

@socket-security

socket-securityBot commented Jan 22, 2024

Copy link
Copy Markdown

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/mz@2.7.0, npm/source-map@0.8.0-beta.0, npm/tree-kill@1.2.2

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

    @rygine

    Copy link
    Copy Markdown

    just a general comment on tsup. if the treeshake option is ever used, the source maps will be inaccurate. more info here.

    it can make debugging a huge pain. we've since moved away from tsup in favor of rollup.

    @Mrtenz

    Copy link
    Copy Markdown
    MemberAuthor

    just a general comment on tsup. if the treeshake option is ever used, the source maps will be inaccurate. more info here.

    it can make debugging a huge pain. we've since moved away from tsup in favor of rollup.

    Thanks for the heads up! I'll see how big of a difference treeshake makes in our case. It seems like there's a couple open PRs to fix it as well, so potentially we can patch tsup until one of those is merged.

    @Mrtenz

    Copy link
    Copy Markdown
    MemberAuthor

    @SocketSecurity ignore npm/tree-kill@1.2.2
    @SocketSecurity ignore npm/source-map@0.8.0-beta.0

    Copy link
    Copy Markdown
    MemberAuthor

    Choose a reason for hiding this comment

    The reason will be displayed to describe this comment to others. Learn more.

    tsup moves everything to separate chunk files (when code splitting is enabled), which breaks code relying on relative imports, in our case, the Webpack loader. As a workaround I added this new loader, which executes a function. This works since the worker path points to __filename, so regardless of where the file is placed, it will load properly.

    @codecov

    codecovBot commented Feb 1, 2024

    Copy link
    Copy Markdown

    Codecov Report

    All modified and coverable lines are covered by tests ✅

    Comparison is base (e682522) 96.59% compared to head (1eba380) 96.60%.

    Additional details and impacted files
    @@ Coverage Diff @@## tsup #2120 +/- ##
    =======================================
    Coverage 96.59% 96.60% =======================================
    Files 332 334 +2 Lines 7582 7595 +13 Branches 1175 1175 =======================================
    + Hits 7324 7337 +13 
    Misses 258 258 

    ☔ View full report in Codecov by Sentry.
    📢 Have feedback on the report? Share it here.

    @Mrtenz

    Copy link
    Copy Markdown
    MemberAuthor

    @SocketSecurity ignore npm/mz@2.7.0

    {
    "name": "@metamask/snaps-simulator",
    "version": "2.4.3",
    "private": true,

    Copy link
    Copy Markdown
    MemberAuthor

    Choose a reason for hiding this comment

    The reason will be displayed to describe this comment to others. Learn more.

    Note that I added private: true here. We previously published this to NPM for snaps-jest, but we no longer use it.

    exit 1
    fi

    post-build:

    Copy link
    Copy Markdown
    MemberAuthor

    Choose a reason for hiding this comment

    The reason will be displayed to describe this comment to others. Learn more.

    I've removed all post-tsc scripts for simplicity.

    Comment threadpackages/snaps-controllers/package.json Outdated
    @Mrtenz
    Mrtenz marked this pull request as ready for review February 19, 2024 13:58
    @Mrtenz
    Mrtenz requested a review from a team as a code ownerFebruary 19, 2024 13:58
    Comment threadpackages/snaps-webpack-plugin/package.json
    Comment threadyarn.lock
    languageName: node
    linkType: hard

    "@esbuild/linux-arm64@npm:0.18.20":

    Copy link
    Copy Markdown
    Member

    Choose a reason for hiding this comment

    The reason will be displayed to describe this comment to others. Learn more.

    Can we dedupe our esbuild deps or does that require bumping WDIO again?

    Copy link
    Copy Markdown
    MemberAuthor

    Choose a reason for hiding this comment

    The reason will be displayed to describe this comment to others. Learn more.

    Looks like it requires bumping WDIO yeah.

    Comment threadpackages/snaps-browserify-plugin/package.json Outdated
    Comment threadpackages/snaps-cli/package.json
    @Mrtenz
    Mrtenz changed the base branch from main to tsupFebruary 21, 2024 15:21
    @Mrtenz
    Mrtenz merged commit a785f62 into tsupFeb 22, 2024
    @Mrtenz
    Mrtenz deleted the mrtenz/tsup branch February 22, 2024 09:48
    Mrtenz added a commit that referenced this pull request Feb 22, 2024
    This changes all packages to be built with `tsup`, instead of SWC.
    `tsup` uses `esbuild` under the hood, so performance should be
    comparable.
    More context here: MetaMask/utils#144.
    Mrtenz added a commit that referenced this pull request Feb 23, 2024
    This changes all packages to be built with `tsup`, instead of SWC.
    `tsup` uses `esbuild` under the hood, so performance should be
    comparable.
    More context here: MetaMask/utils#144.
    Mrtenz added a commit that referenced this pull request Feb 26, 2024
    This changes all packages to be built with `tsup`, instead of SWC.
    `tsup` uses `esbuild` under the hood, so performance should be
    comparable.
    More context here: MetaMask/utils#144.
    Mrtenz added a commit that referenced this pull request Feb 26, 2024
    This swaps out the build system for `tsup`, and adds a proper ESM build
    to each package. In addition to that, the following changes have been
    made:
    - All packages with Node.js-specific code have been refactored to make
    them browser compatible. Node.js exports were moved to a separate
    `/node` export, i.e., `@metamask/snaps-utils/node`.
    - This also applies to the React Native webview service in
    `snaps-controllers`, which can now be imported from
    `@metamask/snaps-controllers/react-native`.
    - The `snaps-simulator` package is no longer published to NPM. We were
    previously using it for `snaps-jest`, but it's no longer used now.
    ---
    This pull request consists of the following pull requests:
    - #2120.
    - #2211.
    naugtur pushed a commit that referenced this pull request Mar 28, 2024
    This changes all packages to be built with `tsup`, instead of SWC.
    `tsup` uses `esbuild` under the hood, so performance should be
    comparable.
    More context here: MetaMask/utils#144.
    Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

    Labels

    None yet

    Projects

    None yet

    Development

    Successfully merging this pull request may close these issues.

    3 participants

    @Mrtenz@rygine@FrederikBolding