start-plugin-core: sitemap lastmod and pages.json lastBuilt are stamped with the build's wall clock (no SOURCE_DATE_EPOCH support)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript
- Domain
- build-system
Research direction
Start in src/build-sitemap.ts and trace the two places where new Date() is written to sitemap.xml and pages.json. Run the minimal build reproducer with SOURCE_DATE_EPOCH set, then verify that repeated builds produce byte-identical sitemap.xml and pages.json while builds without the variable retain current behavior.
Written by the indexing model from the issue text.
Description
Which project does this relate to?
Start
Describe the bug
@tanstack/start-plugin-core's sitemap builder (src/build-sitemap.ts) writes new Date() into two places on every build:
<lastmod>of every sitemap entry whose route declares nositemap.lastmod— which is every page discovered bycrawlLinks, since crawled pages have no per-page config to set one on;lastBuiltinpages.json.
So building the same sources twice on different days yields different output. That breaks any deploy pipeline that hashes the client dist to decide whether prod is current (ours: a Bazel build whose dist hash is compared against the last deploy; a lint-tool dependency bump re-ran the vite action and every page's lastmod moved to that day, reporting the site as changed when nothing user-visible had). It also makes the sitemap's lastmod meaningless to crawlers: Google documents that it uses lastmod only when it is "consistently and verifiably accurate", and a build date tells them every page changed on every rebuild.
There is no configuration escape hatch: the top-level sitemap options are enabled, host, outputPath only, and the default cannot be reached for crawled pages.
The reproducible-builds convention for exactly this is the SOURCE_DATE_EPOCH environment variable (https://reproducible-builds.org/specs/source-date-epoch/), which build tools consult in place of "now" for embedded timestamps. The plugin does not read it.
Complete minimal reproducer
Any Start app with prerendering, link crawling and sitemap.host set (the SEO guide's example config):
pnpm build && cp dist/client/sitemap.xml /tmp/a.xml
# next day, or with a faked clock:
faketime '+1d' pnpm build && cp dist/client/sitemap.xml /tmp/b.xml
diff /tmp/a.xml /tmp/b.xml # every <lastmod> differs; sources unchanged
Expected: with SOURCE_DATE_EPOCH=1700000000 exported, both builds produce byte-identical sitemap.xml and pages.json. Without it, current behavior is fine to keep.
PR to follow.
- Dominant language
- TypeScript
- Stars
- 15.1k
- Forks
- 1.9k
- Avg merge
- 2d 1h
- Merged PRs (30d)
- 137
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from TanStack/router
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
information needed
Difficulty 1/5 Under an hour Newbie friendliness 90/100
TanStack/router#8464 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
TanStack/router#8407 · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
TanStack/router#8333 · 1 reaction ·
Maintainers usually reply within 1 day
-
lazyRouteComponent reload guard key collides on Safari, capping stale-deploy recovery at one per tabOpen
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
TanStack/router#8331 · 1 comment ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
microsoft/vscode-livepreview#876 ·
Maintainers usually reply within 1 day
-
needs-triage
Difficulty 1/5 Under an hour Newbie friendliness 90/100
JustJarethB/invoicer#54 ·
-
ICP 1.2.0 shows a scheduled task's interval in milliseconds under the label "Interval (In seconds)"OpenNeeds Triage Type/Bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
wso2/product-integrator#2585 ·
Maintainers usually reply within 1 day
-
check:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
design
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
MTES-MCT/monitor-field#119 ·
Maintainers usually reply within 1 day