Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

nodejs_npm --build-in-source silently produces a dependency-less artifact for an npm workspaces monorepo

未关闭
#933 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 7 天内回复

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
68/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
nodejs, python

调研方向

Start with NodejsNpmBuilder and NodejsNpmWorkflow._actions_for_linking_source_dependencies_to_artifacts, then inspect LinkSinglePathAction.execute. Reproduce the npm workspaces build_in_source example and check how the missing packages/fn/node_modules path is handled. Done means hoisted dependencies reach the artifact or the build emits a visible warning instead of succeeding silently.

由索引模型根据 Issue 内容生成。

描述

Description

For an npm workspaces monorepo built with --build-in-source, the NodejsNpmBuilder workflow (the plain one, not NodejsNpmEsbuildBuilder) produces an artifact with no dependencies at all, and reports success.

npm hoists the workspace package's dependencies to the monorepo root, so packages/<fn>/node_modules is never created. NodejsNpmWorkflow._actions_for_linking_source_dependencies_to_artifacts then links source_dir/node_modules into the artifacts directory, and LinkSinglePathAction.execute treats a missing source as nothing to do:

if not source_path.exists():
    # Source path doesn't exist, nothing to symlink
    LOG.debug("Source path %s does not exist, skipping generating symlink", source_path)
    return

The result is a Lambda package that fails at invoke time with Cannot find module, with only a debug-level log at build time.

Steps to reproduce

An npm workspaces monorepo, one function per workspace package:

package.json            { "workspaces": ["packages/*"] }
package-lock.json
packages/fn/package.json  { "dependencies": { "minimal-request-promise": "^1.3.0" } }
packages/fn/included.js   require("minimal-request-promise")

Build packages/fn in source:

LambdaBuilder(language="nodejs", dependency_manager="npm", application_framework=None).build(
    source_dir,          # <monorepo>/packages/fn
    artifacts_dir,
    scratch_dir,
    os.path.join(source_dir, "package.json"),
    runtime="nodejs22.x",
    build_in_source=True,
)
Observed result
artifacts dir:                  ['included.js', 'package.json']
artifacts/node_modules:         ABSENT
source packages/fn/node_modules: None            <- npm hoisted, nothing to link
monorepo root node_modules:     ['.package-lock.json', '@workspaces-monorepo', 'minimal-request-promise']
require.resolve from artifacts dir: UNRESOLVABLE

The build exits successfully.

Expected result

Either the hoisted dependencies reach the artifact, or the build says out loud that it could not find any — a warning rather than a debug log, so the failure surfaces at build time instead of at invoke time.

NodejsNpmEsbuildBuilder is unaffected: esbuild bundles the dependency into the output file, resolving it through the root node_modules.

Additional environment details
  • aws-lambda-builders develop (measured at 587257c) and unchanged by #931
  • npm 11.19.0, node 22, Linux; the hoisting behaviour is the same on npm 8/9/10

Raised out of review on #931, which changes which npm command installs those dependencies but not where npm puts them, so the gap predates it and is not made worse by it. Filing it so the workspaces coverage added there does not imply the plain workflow's artifact is covered.

主要语言
Python
星标
381
派生
162
平均合并
1 天 1 小时
30 天内合并 PR
2

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

aws/aws-lambda-builders 的其他 Issue

查看 aws/aws-lambda-builders 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。