Bump oxc-parser to >=0.90.0: 0.76.0 bindings lack build provenance
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 72/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- javascript
- Lĩnh vực
- build-system
Hướng nghiên cứu
Bắt đầu bằng cách xác định khai báo dependency của oxc-parser trong ComponentizeJS và kiểm tra cách phiên bản của nó bị giới hạn. Xác minh việc cập nhật dependency bằng cấu hình cài đặt áp dụng bắt buộc provenance của build; hoàn tất khi componentize-js và quá trình cài đặt jco downstream của nó không còn yêu cầu các ngoại lệ provenance theo từng package.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Would you consider bumping the oxc-parser dependency to >=0.90.0? At 0.76.0 its platform bindings publish without build provenance, which makes anything depending on componentize-js uninstallable under an installer that enforces provenance.
Filed here at the jco maintainers' suggestion — this started as bytecodealliance/jco#1841, and the reply was that the dependency needs updating here first.
The chain is jco@1.27.0 → @bytecodealliance/componentize-js@^0.22.0 → oxc-parser@^0.76.0. All 15 @oxc-parser/binding-* packages at 0.76.0 are missing build provenance attestations, while oxc-parser and @oxc-project/types at the same version have them.
It looks like a gap in one range rather than the norm: @oxc-parser/binding-darwin-arm64 has attestations at 0.13.3, none at 0.76.0, and has them again from 0.90.0 through the current 0.143.0. npm registry signatures are present throughout — build provenance specifically is what is missing.
Installers that enforce provenance and treat a loss of attestation as a downgrade refuse the install outright. It is not host-specific either: the resolver walks every optional binding, so all 15 have to be excluded individually to get past it, including the 13 for platforms a given project will never run.
Bumping to >=0.90.0 would let componentize-js and jco install cleanly under those policies with no per-package exceptions.
- Ngôn ngữ chính
- Rust
- Star
- 392
- Fork
- 54
- Merge trung bình
- 2 ngày 18 giờ
- Pull request đã merge (30 ngày)
- 3
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của bytecodealliance/ComponentizeJS
-
enhancement
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 56/100
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 52/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
bytecodealliance/ComponentizeJS#335 · 3 bình luận ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
Tất cả issue của bytecodealliance/ComponentizeJS
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
Axis areas are always keyboard-focusable (Sense::drag), even with allow_axis_zoom_drag(false) Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
-
bug team:backend track:services-maintenance
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
cowprotocol/services#4950 ·
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
gitbutlerapp/gitbutler#15998 · 1 bình luận ·