Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

install.sh resolves CLI dependencies at install time, project lockfile and overrides cannot pin them (std-env 4.3.0 404 broke CI)

Abierto
#2,850 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
48/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
javascript, shell
Área
ci-cd, tooling

Línea de trabajo

Start by reading install.sh and tracing how it installs the pinned vite-plus version and resolves its CLI dependencies; compare that behavior with the issue's project lockfile and overrides example. The reproduction links a GitHub Actions run using voidzero-dev/setup-vp@v1. Done means the installer no longer depends on freshly resolved transitive versions that can fail during registry propagation.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Describe the bug

The install.sh installer used by voidzero-dev/setup-vp@v1 resolves the dependencies of the pinned vite-plus version fresh with pnpm at install time instead of installing a locked dependency tree. When any transitive dependency of the CLI publishes a new version that is not yet fully propagated on the npm registry, every CI job that bootstraps Vite+ fails, regardless of what the project itself has locked.

Today (2026-09-29, from about 12:40 UTC for roughly 15 minutes) std-env 4.3.0 was listed in the registry metadata while its tarball still returned 404. The installer resolved [email protected] (a dependency of [email protected]) with std-env ^4.0.0-rc.1, picked 4.3.0 and failed on all four retries across both installer URLs.

The project pins vite-plus to 0.2.6 in package.json and additionally overrides vitest and @vitest/mocker to 4.1.11 via npm overrides with a committed package-lock.json. None of that reaches the global CLI install in ~/.vite-plus: the installer pulls [email protected] with a floating dependency range, so the project's overrides and lockfile cannot protect the CI bootstrap.

Would it be possible for the installer to ship or consume a lockfile for the CLI's dependency tree (pnpm --frozen-lockfile against a lock published with the release), or to install the CLI from a self-contained tarball that does not resolve dependencies at install time? As it stands, any project using setup-vp is exposed to transient publish gaps of every transitive dependency of the CLI.

Reproduction

https://github.com/evcc-io/evcc/actions/runs/36569656072/attempts/1

Steps to reproduce
  • package.json with "vite-plus": "0.2.6" and overrides pinning vitest to 4.1.11
  • workflow step uses: voidzero-dev/setup-vp@v1 with node-version-file and cache: true
  • run while a transitive dependency of [email protected] (here std-env 4.3.0 via [email protected]) has registry metadata but no tarball yet

Reproducing on demand is not possible since it depends on registry propagation timing. Comparing the installer's resolved tree against the project's lockfile shows the mismatch at any time: the project locks vitest 4.1.11, the CLI install resolves vitest 4.1.10 with its own floating ranges.

System Info
GitHub Actions ubuntu-latest, Node.js 26 (from .node-version), vite-plus 0.2.6, setup-vp v1
Used Package Manager

npm (project) / pnpm (used by install.sh for the CLI dependencies)

Logs
Resolved Vite+ version '0.2.6' from package.json
Installing [email protected]...
Setting up VITE+...
info: vite-plus 0.2.6 does not support the split directory layout. Vite+ will install it in ~/.vite-plus.
error: Failed to install dependencies. Log output:
Progress: resolved 179, reused 0, downloaded 85, added 53
 ERR_PNPM_FETCH_404  GET https://registry.npmjs.org/std-env/-/std-env-4.3.0.tgz: Not Found - 404

This error happened while installing the dependencies of [email protected]
 at [email protected]

No authorization header was set for the request.
##[warning]Failed to install Vite+ from https://viteplus.dev/install.sh (exit code 1). Retrying in 2000ms... (attempt 2/4)
...
Error: Failed to install Vite+ after 4 attempts across 2 URL(s): exit code 1
Validations
  • Read the Contributing Guidelines.
  • Check that there isn't already an issue for the same bug.
  • Confirm this is a Vite+ issue and not an upstream issue (Vite, Vitest, tsdown, Rolldown, or Oxc).
  • The provided reproduction is a minimal reproducible example.

🤖 Generated with Claude Code

Lenguaje dominante
Rust
Estrellas
5.8k
Forks
267
Merge medio
20 h 30 min
PR fusionados (30 d)
144

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de voidzero-dev/vite-plus

Todos los issues de voidzero-dev/vite-plus

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.