Skip to content

BREAKING: Use tsup and refactor exports - #2210

Merged
Mrtenz merged 4 commits into
mainfrom
tsup
Feb 26, 2024
Merged

BREAKING: Use tsup and refactor exports#2210
Mrtenz merged 4 commits into
mainfrom
tsup

Conversation

@Mrtenz

@MrtenzMrtenz commented Feb 22, 2024

Copy link
Copy Markdown
Member

This swaps out the build system for tsup, and adds a proper ESM build to each package. In addition to that, the following changes have been made:

  • All packages with Node.js-specific code have been refactored to make them browser compatible. Node.js exports were moved to a separate /node export, i.e., @metamask/snaps-utils/node.
    • This also applies to the React Native webview service in snaps-controllers, which can now be imported from @metamask/snaps-controllers/react-native.
  • The snaps-simulator package is no longer published to NPM. We were previously using it for snaps-jest, but it's no longer used now.

This pull request consists of the following pull requests:

@socket-security

socket-securityBot commented Feb 22, 2024

Copy link
Copy Markdown

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

PackageNew capabilitiesTransitivesSizePublisher
npm/@esbuild/aix-ppc64@0.19.12None010.4 MBevanw
npm/@esbuild/android-arm@0.19.12None011.5 MBevanw
npm/@esbuild/android-arm64@0.19.12None09.83 MBevanw
npm/@esbuild/android-x64@0.19.12None011.5 MBevanw
npm/@esbuild/darwin-arm64@0.19.12None09.76 MBevanw
npm/@esbuild/darwin-x64@0.19.12None010.2 MBevanw
npm/@esbuild/freebsd-arm64@0.19.12None08.85 MBevanw
npm/@esbuild/freebsd-x64@0.19.12None09.61 MBevanw
npm/@esbuild/linux-arm@0.19.12None09.18 MBevanw
npm/@esbuild/linux-arm64@0.19.12None08.85 MBevanw
npm/@esbuild/linux-ia32@0.19.12None09.14 MBevanw
npm/@esbuild/linux-loong64@0.19.12None09.37 MBevanw
npm/@esbuild/linux-mips64el@0.19.12None010.4 MBevanw
npm/@esbuild/linux-ppc64@0.19.12None09.18 MBevanw
npm/@esbuild/linux-riscv64@0.19.12None09.11 MBevanw
npm/@esbuild/linux-s390x@0.19.12None010 MBevanw
npm/@esbuild/linux-x64@0.19.12None09.6 MBevanw
npm/@esbuild/netbsd-x64@0.19.12None09.59 MBevanw
npm/@esbuild/openbsd-x64@0.19.12None09.62 MBevanw
npm/@esbuild/sunos-x64@0.19.12None09.59 MBevanw
npm/@esbuild/win32-arm64@0.19.12None08.98 MBevanw
npm/@esbuild/win32-ia32@0.19.12None09.45 MBevanw
npm/@esbuild/win32-x64@0.19.12None09.81 MBevanw
npm/@rollup/rollup-android-arm-eabi@4.12.0None01.63 MBlukastaegert
npm/@rollup/rollup-android-arm64@4.12.0None02.49 MBlukastaegert
npm/@rollup/rollup-darwin-arm64@4.12.0None02.41 MBlukastaegert
npm/@rollup/rollup-darwin-x64@4.12.0None02.58 MBlukastaegert
npm/@rollup/rollup-linux-arm-gnueabihf@4.12.0None02.43 MBlukastaegert
npm/@rollup/rollup-linux-arm64-gnu@4.12.0None02.47 MBlukastaegert
npm/@rollup/rollup-linux-arm64-musl@4.12.0None02.37 MBlukastaegert
npm/@rollup/rollup-linux-riscv64-gnu@4.12.0None02.54 MBlukastaegert
npm/@rollup/rollup-linux-x64-gnu@4.12.0None02.73 MBlukastaegert
npm/@rollup/rollup-linux-x64-musl@4.12.0None02.73 MBlukastaegert
npm/@rollup/rollup-win32-arm64-msvc@4.12.0None02.93 MBlukastaegert
npm/@rollup/rollup-win32-ia32-msvc@4.12.0None02.64 MBlukastaegert
npm/@rollup/rollup-win32-x64-msvc@4.12.0None03.44 MBlukastaegert
npm/@sindresorhus/is@5.3.0None058.9 kBsindresorhus
npm/any-promise@1.3.0None022.2 kBkevinbeaty
npm/bundle-require@4.0.2environment, filesystem, unsafe Transitive: network, shell+25224 MBegoist
npm/cac@6.7.14None081.8 kBegoist
npm/chokidar@3.6.0environment, filesystem+14531 kBpaulmillr
npm/esbuild@0.19.12environment, filesystem, network, shell+23224 MBevanw
npm/joycon@3.1.1environment, filesystem014 kBegoist
npm/load-tsconfig@0.2.5None017.1 kBegoist
npm/lodash.sortby@4.7.0None075.8 kBjdalton
npm/mz@2.7.0filesystem, network, shell+452 kBjongleberry
npm/postcss-load-config@4.0.2environment, unsafe Transitive: filesystem, shell+38466 MBai
npm/rollup@4.12.0environment, filesystem+1535.8 MBlukastaegert
npm/sucrase@3.35.0Transitive: environment, filesystem, network, shell, unsafe+393.75 MBalangpierce
npm/thenify-all@1.6.0None+236.7 kBdead_horse
npm/thenify@3.3.1None+130.1 kBdead_horse
npm/tr46@1.0.1None+1356 kBsebmaster
npm/tree-kill@1.2.2shell07.82 kBwmhilton
npm/ts-interface-checker@0.1.13None068 kBdsagal2
npm/tsup@8.0.2environment, eval, filesystem Transitive: network, shell, unsafe+170731 MBegoist
npm/webidl-conversions@4.0.2None019.3 kBdomenic
npm/whatwg-url@7.1.0None+4529 kBdomenic

🚮 Removed packages:npm/@esbuild/android-arm64@0.20.1, npm/@esbuild/android-arm@0.20.1, npm/@esbuild/android-x64@0.20.1, npm/@esbuild/darwin-arm64@0.20.1, npm/@esbuild/darwin-x64@0.20.1, npm/@esbuild/freebsd-arm64@0.20.1, npm/@esbuild/freebsd-x64@0.20.1, npm/@esbuild/linux-arm64@0.20.1, npm/@esbuild/linux-arm@0.20.1, npm/@esbuild/linux-ia32@0.20.1, npm/@esbuild/linux-loong64@0.20.1, npm/@esbuild/linux-mips64el@0.20.1, npm/@esbuild/linux-ppc64@0.20.1, npm/@esbuild/linux-riscv64@0.20.1, npm/@esbuild/linux-s390x@0.20.1, npm/@esbuild/linux-x64@0.20.1, npm/@esbuild/netbsd-x64@0.20.1, npm/@esbuild/openbsd-x64@0.20.1, npm/@esbuild/sunos-x64@0.20.1, npm/@esbuild/win32-arm64@0.20.1, npm/@esbuild/win32-ia32@0.20.1, npm/@esbuild/win32-x64@0.20.1, npm/@mole-inc/bin-wrapper@8.0.1, npm/@sindresorhus/is@4.6.0, npm/@swc/cli@0.1.65, npm/@szmarczak/http-timer@4.0.6, npm/@tokenizer/token@0.3.0, npm/arch@2.2.0, npm/bin-check@4.1.0, npm/bin-version-check@5.1.0, npm/bin-version@6.0.0, npm/cacheable-lookup@5.0.4, npm/cacheable-request@7.0.4, npm/commander@7.2.0, npm/esbuild@0.20.1, npm/executable@4.1.1, npm/ext-list@2.2.2, npm/ext-name@5.0.0, npm/file-type@17.1.6, npm/filename-reserved-regex@3.0.0, npm/filenamify@5.1.1, npm/find-versions@5.1.0, npm/got@11.8.6, npm/http2-wrapper@1.0.3, npm/is-plain-obj@1.1.0, npm/lowercase-keys@2.0.0, npm/normalize-url@6.1.0, npm/os-filter-obj@2.0.0, npm/p-cancelable@2.1.1, npm/p-finally@1.0.0, npm/peek-readable@5.0.0, npm/responselike@2.0.1, npm/semver-regex@4.0.5, npm/semver-truncate@3.0.0, npm/shebang-command@1.2.0, npm/sort-keys-length@1.0.1, npm/sort-keys@1.1.2, npm/strip-eof@1.0.0, npm/strip-outer@2.0.0, npm/strtok3@7.0.0, npm/token-types@5.0.1, npm/trim-repeated@2.0.0

View full report↗︎

@socket-security

socket-securityBot commented Feb 22, 2024

Copy link
Copy Markdown

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/mz@2.7.0, npm/source-map@0.8.0-beta.0, npm/tree-kill@1.2.2

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

    @codecov

    codecovBot commented Feb 22, 2024

    Copy link
    Copy Markdown

    Codecov Report

    All modified and coverable lines are covered by tests ✅

    ❗ No coverage uploaded for pull request base (main@33f01f1). Click here to learn what that means.

    Additional details and impacted files
    @@ Coverage Diff @@## main #2210 +/- ##
    =======================================
    Coverage ? 96.60% =======================================
    Files ? 337 Lines ? 7599 Branches ? 1175 =======================================
    Hits ? 7341 Misses ? 258 Partials ? 0 

    ☔ View full report in Codecov by Sentry.
    📢 Have feedback on the report? Share it here.

    @MrtenzMrtenz changed the title Use tsup and refactor exportsBREAKING: Use tsup and refactor exportsFeb 23, 2024
    @Mrtenz
    Mrtenz marked this pull request as ready for review February 23, 2024 12:51
    @Mrtenz
    Mrtenz requested a review from a team as a code ownerFebruary 23, 2024 12:51
    This changes all packages to be built with `tsup`, instead of SWC.
    `tsup` uses `esbuild` under the hood, so performance should be
    comparable.
    More context here: MetaMask/utils#144.
    …js (#2211)
    This refactors all packages to be browser-first: All APIs and packages
    used should be compatible with browsers. This means no use of Node.js
    builtins, or native packages. Node-specific APIs have been moved to a
    separate export `/node` (e.g., `@metamask/snaps-controllers/node`). For
    the `snaps-controllers` package I've also added a `/react-native`
    export, which exports the React Native webview service.
    This also means we can remove the "browser" field from the packages that
    were using it.
    ## Breaking changes
    - Anything that uses Node.js was removed from the default export, and
    needs to be imported from `/node`.
    - The React Native webview service was moved, and needs to be imported
    from `/react-native`.
    @Mrtenz

    Copy link
    Copy Markdown
    MemberAuthor

    @SocketSecurity ignore npm/mz@2.7.0
    @SocketSecurity ignore npm/tree-kill@1.2.2
    @SocketSecurity ignore npm/source-map@0.8.0-beta.0

    // eslint-disable-next-line @typescript-eslint/no-require-imports, @typescript-eslint/no-var-requires
    const { default: baseConfig } = require('../../tsup.config');

    delete baseConfig.entry;

    Copy link
    Copy Markdown
    Member

    Choose a reason for hiding this comment

    The reason will be displayed to describe this comment to others. Learn more.

    Why do we need this?

    Copy link
    Copy Markdown
    MemberAuthor

    Choose a reason for hiding this comment

    The reason will be displayed to describe this comment to others. Learn more.

    deepmerge merges arrays by default, so then tsup would build all TypeScript files. Since we disable splitting here, we only want index.ts to be built.

    @Mrtenz
    Mrtenz merged commit d7488a9 into mainFeb 26, 2024
    @Mrtenz
    Mrtenz deleted the tsup branch February 26, 2024 09:55
    Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

    Labels

    None yet

    Projects

    None yet

    Development

    Successfully merging this pull request may close these issues.

    2 participants

    @Mrtenz@FrederikBolding