Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Harper auto-resolution silently tests the published npm package when the consumer doesn't declare harper

オープン
#23 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

@kriszyp がすでに取り組んでいます。

2026年9月23日 から。

  • #34 @kriszyp による — オープン

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
52/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
node.js, typescript

調査の方向性

まず getHarperScript とパッケージマニフェストを見つけ、HARPER_INTEGRATION_TEST_INSTALL_SCRIPT なしで、ドキュメントに記載された統合テストコマンドを再現します。インストール済みの harper パッケージを選択する解決分岐を追跡し、ローカルの dist フォールバックと比較します。未宣言の harper 依存関係によって公開済みパッケージが暗黙的に選択されなくなり、関連する統合動作がカバーされるか、明確に報告されれば完了です。

索引モデルが issue の本文から書いたものです。

説明

What happened

Running npm run test:integration -- integrationTests/server/v1-gateway.test.ts locally in the harper core repo (without HARPER_INTEGRATION_TEST_INSTALL_SCRIPT, which only CI sets) silently ran the suite against [email protected] from the npm registry instead of the repo's freshly built dist/. Every test failed with 404s/401s because the published binary predates the feature under test — nothing indicated the wrong binary was in play, and the misdiagnosis cost hours.

Why

The README documents resolution step 3 as:

Auto-resolved from a harper package installed as a project dependency

and harper is correctly declared as a peerDependency (^5.0.0) — but npm ≥7 auto-installs peerDependencies. A consumer that never declares harper (the core repo itself, or any component repo that forgot) still ends up with [email protected] hoisted into its node_modules, and getHarperScript step 3 resolves it:

$ npm ls harper       # in HarperFast/harper — which declares no harper dep
[email protected]
└─┬ @harperfast/[email protected]
  └── [email protected]    # npm auto-installed to satisfy the peer range

The auto-install defeats the documented "project dependency" intent, and step 4 (cwd/ancestor dist/bin/harper.js — the fallback that would find the local build) is never reached.

Candidate fixes

  1. peerDependenciesMeta: { harper: { optional: true } } (preferred): npm stops auto-installing the peer. Consumers that declare harper resolve exactly as documented; consumers that don't fall through to the cwd/ancestor dist fallback or get the existing clear "Harper CLI script not found" error telling them their options. Behavior change only for repos that were (likely unknowingly) leaning on the auto-installed registry copy.
  2. Prefer cwd/ancestor dist/bin/harper.js over node_modules when both exist (swap steps 3↔4 precedence): fixes the harper source tree, and is a no-op for component repos (whose own dist/ is not a harper build). Slightly riskier for unusual directory layouts.

Note that resolving step 3 "from the project instead of the harness module" does not fix this — npm hoists the auto-installed peer into the consumer's root node_modules, so a cwd-based resolve finds the same wrong copy.

Regardless of direction, observability for the resolution decision is being proposed separately (log the resolved path + warn when node_modules/harper wins while a cwd dist/bin/harper.js exists).

🤖 Filed with Claude Code on behalf of @heskew

主要言語
TypeScript
スター
1
フォーク
0
平均マージ
8日 9分
マージ済み PR(30日)
1

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

HarperFast/integration-testing のほかの issue

HarperFast/integration-testing の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。