nodejs_npm --build-in-source silently produces a dependency-less artifact for an npm workspaces monorepo
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 68/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- nodejs, python
- Domain
- build-system, devtools
Research direction
Start with NodejsNpmBuilder and NodejsNpmWorkflow._actions_for_linking_source_dependencies_to_artifacts, then inspect LinkSinglePathAction.execute. Reproduce the npm workspaces build_in_source example and check how the missing packages/fn/node_modules path is handled. Done means hoisted dependencies reach the artifact or the build emits a visible warning instead of succeeding silently.
Written by the indexing model from the issue text.
Description
Description
For an npm workspaces monorepo built with --build-in-source, the NodejsNpmBuilder workflow (the plain one, not NodejsNpmEsbuildBuilder) produces an artifact with no dependencies at all, and reports success.
npm hoists the workspace package's dependencies to the monorepo root, so packages/<fn>/node_modules is never created. NodejsNpmWorkflow._actions_for_linking_source_dependencies_to_artifacts then links source_dir/node_modules into the artifacts directory, and LinkSinglePathAction.execute treats a missing source as nothing to do:
if not source_path.exists():
# Source path doesn't exist, nothing to symlink
LOG.debug("Source path %s does not exist, skipping generating symlink", source_path)
return
The result is a Lambda package that fails at invoke time with Cannot find module, with only a debug-level log at build time.
Steps to reproduce
An npm workspaces monorepo, one function per workspace package:
package.json { "workspaces": ["packages/*"] }
package-lock.json
packages/fn/package.json { "dependencies": { "minimal-request-promise": "^1.3.0" } }
packages/fn/included.js require("minimal-request-promise")
Build packages/fn in source:
LambdaBuilder(language="nodejs", dependency_manager="npm", application_framework=None).build(
source_dir, # <monorepo>/packages/fn
artifacts_dir,
scratch_dir,
os.path.join(source_dir, "package.json"),
runtime="nodejs22.x",
build_in_source=True,
)
Observed result
artifacts dir: ['included.js', 'package.json']
artifacts/node_modules: ABSENT
source packages/fn/node_modules: None <- npm hoisted, nothing to link
monorepo root node_modules: ['.package-lock.json', '@workspaces-monorepo', 'minimal-request-promise']
require.resolve from artifacts dir: UNRESOLVABLE
The build exits successfully.
Expected result
Either the hoisted dependencies reach the artifact, or the build says out loud that it could not find any — a warning rather than a debug log, so the failure surfaces at build time instead of at invoke time.
NodejsNpmEsbuildBuilder is unaffected: esbuild bundles the dependency into the output file, resolving it through the root node_modules.
Additional environment details
- aws-lambda-builders
develop(measured at 587257c) and unchanged by #931 - npm 11.19.0, node 22, Linux; the hoisting behaviour is the same on npm 8/9/10
Raised out of review on #931, which changes which npm command installs those dependencies but not where npm puts them, so the gap predates it and is not made worse by it. Filing it so the workspaces coverage added there does not imply the plain workflow's artifact is covered.
- Dominant language
- Python
- Stars
- 381
- Forks
- 164
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 2
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from aws/aws-lambda-builders
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
aws/aws-lambda-builders#925 · 1 reaction ·
Maintainers usually reply within 2 days
-
Difficulty 4/5 3-5 days Newbie friendliness 64/100
aws/aws-lambda-builders#924 · 1 comment · 1 reaction ·
Maintainers usually reply within 2 days
-
Bug: PythonUvBuilder fails to build app with dependencies on editable installs in the workspaceOpenstage/needs-triage
Difficulty 3/5 1-2 days Newbie friendliness 25/100
aws/aws-lambda-builders#892 ·
Maintainers usually reply within 2 days
-
stage/needs-triage type/feature
Difficulty 4/5 3-5 days Newbie friendliness 38/100
aws/aws-lambda-builders#839 · 2 comments · 1 reaction ·
Maintainers usually reply within 2 days
-
area/build contributors/good-first-issue contributors/welcome type/feature
Difficulty 4/5 3-5 days Newbie friendliness 38/100
aws/aws-lambda-builders#831 · 3 comments ·
Maintainers usually reply within 2 days
All issues in aws/aws-lambda-builders
Similar issues
-
repo-audit
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
scverse/repo-health#20 ·
Maintainers usually reply within 1 day
-
/context/prime scope override double-prefixes an entity-ref project and drops its scoped memoriesOpen
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
phasespace-labs/palinode#232 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
collective/icalendar#1858 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
langflow-ai/langflow#15496 ·
Maintainers usually reply within 1 day