') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); finding(fields): `@object-ui/fields` emits `dist/__tests__/numberInputBrowserReadings.d.ts` into its published tarball, so `check:published-dist` is red on the release path · Issue #6861 · objectstack-ai/objectui · GitHub
Skip to content

finding(fields): @object-ui/fields emits dist/__tests__/numberInputBrowserReadings.d.ts into its published tarball, so check:published-dist is red on the release path #6861

Description

@claude

Found by the domain:ui execution seat while implementing objectui#6813 (the permission providers' context-value identity). Not fixed there — that card is scope-locked to packages/permissions, and this is a packages/fields build-config defect.

What the gate reports

pnpm check:published-dist is RED on origin/main (1e14d70ae, the base of #6813's branch). Measured in a clean worktree whose only changes are in packages/permissions, so nothing about this finding is attributable to that branch:

Inspected 39 published package(s) after a 262s build: 5858 tarball file(s), 5702 of them build output, 1 tooling artifact(s) in build output.
1 finding(s) across 1 published package(s):
@object-ui/fields [tooling-in-published-output] packages/fields/dist/__tests__/numberInputBrowserReadings.d.ts

Why it slips through

packages/fields/tsconfig.json excludes tooling from the emitting program by file NAME only:

"include": ["src"],
"exclude": ["node_modules", "dist", "**/*.test.ts", "**/*.test.tsx"]

packages/fields/src/__tests__/numberInputBrowserReadings.ts lives in a __tests__ DIRECTORY but is not named *.test.ts, so the exclude misses it and tsc emits dist/__tests__/numberInputBrowserReadings.d.ts into the tarball a consumer installs.

That is exactly the name-vs-directory mismatch the gate's own message names as having shipped twice before, in objectui#4006 and again in objectui#4836. The comment sitting directly above that exclude line even describes the #4006 fix — it just fixes the name half and not the directory half.

Why it matters more than a nightly red

Per .github/workflows/published-dist-gate.yml, this gate is deliberately NOT a pull_request job (the 2026-08-16 ruling on objectui#4846 rejected a per-PR full-repo build). It runs nightly as an alarm and on the release path: pnpm changeset:publish runs it before a single tarball reaches npm, so a red gate cancels the publish. This will therefore not redden anyone's PR and will block the next release.

Suggested shape

The gate's message states the fix: exclude the tooling DIRECTORIES from the emitting program, not just the *.test.* name. If the file loses type coverage with the emit, name it in the package's tsconfig.test.json — PR #4845 did exactly this for core.bench.ts.

Reproduce

pnpm check:published-dist

Dedupe

/search/issues is unreliable for this seat, so this went through the repo-scoped REST list endpoint plus a local grep: 250 open issues collected, zero hits for published-dist, tooling-in-published, numberInputBrowserReadings, tarball or dist/__tests__. Control terms hit in the same read (permission matched 5 titles, memo matched 1), so the empty result is a real reading and not a broken one.

Unassigned — filed as a finding for triage to route, not claimed.

Generated by Claude Code


Generated by Claude Code

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions