Skip to content

fix(sdk): declare typescript and undici as runtime dependencies so flows check works on a clean install - #608

Merged
khaliqgant merged 4 commits into
mainfrom
relayflow/flows-software-garden-d0e151d5
Oct 4, 2026
Merged

khaliqgant merged 4 commits into
mainfrom
relayflow/flows-software-garden-d0e151d5

Conversation

@agent-relay-code

@agent-relay-code agent-relay-code Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #605. flows check crashes on a clean install (ERR_MODULE_NOT_FOUND: typescript) because @relayflows/sdk imports typescript at runtime (src/cli/check-activities.ts) but only declared it as a devDependency.

Change

  • packages/sdk/package.json / package-lock.json: move typescript (^5.6.0, range unchanged) to dependencies, and declare undici (^7.29.1), which the SDK already imports at runtime and was likewise only resolving transitively. Lock regenerated without upgrades: TypeScript loses its dev: true marker; there is one undici entry. TypeScript, not acorn, is needed because the activity checker parses TypeScript syntax.

  • packages/sdk/tests/runtime-dependencies.test.ts: AST-scans the built SDK JavaScript for literal imports / re-exports / require calls and fails on any bare package not declared in dependencies/peerDependencies. Computed imports are a documented blind spot.

  • packages/sdk/tests/cli-package-gate.test.ts + scripts/cli-package-gate.mjs: the clean-install regression flows check crashes on a clean install: @relayflows/sdk imports typescript but only dev-depends on it #605 asked for. Packs surface, SDK and relayflows with the existing scripts/pack-release.mjs, installs the real tarballs into a temp dir outside the repo (it rejects any ancestor node_modules and clears NODE_PATH/NODE_OPTIONS), and runs flows check on examples/dependency-upgrade-bot for:

    • a local install, via both npm's linked flows bin and the relayflows wrapper entry point. Both the SDK and relayflows claim the flows bin, so checking only the bin would leave the wrapper unexercised.
    • a global install, which must expose only flows (no tsc/tsserver) and is checked against a consumer project that has no TypeScript of its own.

    It also asserts TypeScript resolves inside the installation. It needs Node >=22.18.0 and built surface/SDK dist, which the CI SDK job already provides. Registry errors fail the test. FLOWS_SKIP_PACKAGE_GATE=1 is an explicit, loudly reported local opt-out.

  • tsconfig.tests.json includes the two new tests.

No workflow files change and no committed evidence ships; an earlier revision's evidence/ transcripts were removed.

Verification

Packaging regression is red on base, green on head. I copied the two new tests and the gate script onto base d1877301 (main, typescript still a devDependency) and ran vitest run tests/runtime-dependencies.test.ts tests/cli-package-gate.test.ts in both trees:

# base d1877301 + new tests  -> exit 1, Tests 2 failed (2)
→ Undeclared runtime dependencies: expected [ 'typescript', 'undici' ] to deeply equal []
Error [ERR_MODULE_NOT_FOUND]: Cannot find package 'typescript' imported from …/flows-cli-package-p2vJWw/local/node_modules/@relayflows/sdk/dist/cli/check-activities.js

# head 812000a3              -> exit 0, Tests 2 passed (2)
CHECK PASSED examples/dependency-upgrade-bot.flow.ts   (x4: local bin, local wrapper, global bin, global wrapper)
CLI_PACKAGE_OK: local and global installs

Full SDK suite: the PR adds no failures. CI's linux-x64-artifact job runs the whole SDK suite, including both new tests, and is green on 812000a3. The first attempt hit two known main flakes, both seen on main: authored-parallel-agents "never starts queued agents once the body has failed" (main run 37137600293) and a named-gate-diagnostics word_count_bounds "could not run wc" spawn error (main run 37103010381). They passed on --failed rerun.

Locally (macOS arm64, Node 26.8.1, bun 1.4.0, a freshly built relayflowd via RELAYFLOWD_BIN, RELAYFLOWS_ALLOW_ANALYZER_SKIP=1), I ran the full suite with an identical command and environment on head and on its base d1877301, one after the other: vitest run --no-file-parallelism, after CI's setup steps (surface build, npm ci, local-surface override, typecheck, build, typecheck:tests).

Test files Tests
base d1877301 8 failed / 239 passed / 1 skipped (248) 52 failed / 3676 passed / 55 skipped
head 812000a3 8 failed / 241 passed / 1 skipped (250) 52 failed / 3678 passed / 55 skipped

The sets of failing tests, by file and full name, are identical (comm: 0 head-only, 0 base-only). The two extra passing files on head are the new tests. The 52 shared failures are environmental on this Mac:

  • hosted-base-snapshot (15), hosted-extension-isolation (12), hosted-extension-protocol (7): "hosted extension isolation requires Linux" (bubblewrap sandbox).
  • authored-node-runtime (14), cli (2), live-kernel (1), authored-parallel-agents (1): local authored-runtime/worker failures that also fail on base and pass in CI on Linux.

Also: npm run typecheck, npm run build and npm run typecheck:tests in packages/sdk exit 0 on head.

Not covered / follow-ups

  • CI path filter. cloud-runtime-artifact.yml triggers the SDK job on packages/sdk/** (among others). A future PR touching only scripts/cli-package-gate.mjs, scripts/pack-release.mjs, packages/surface/**, packages/relayflows/** or the example would not run this gate. Adding those paths is a one-line follow-up that needs a workflow-scoped push; it was left out of this PR.
  • Standalone Bun binaries, Windows packaging, Node <22.18, the broader published engines range and the stale SDK bun.lock are outside this fix.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: bcc2ed15-5412-4f01-ad9a-f3ec0ebc8938

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@agent-relay-code
agent-relay-code Bot marked this pull request as draft October 4, 2026 07:54
@agent-relay-code

Copy link
Copy Markdown
Contributor Author

Relayflow: the adversarial review did not pass. This branch is not approved: the flow stopped here and did not mark it ready to merge.

Review of PR #608

Reviewed head: a56ce509e9524fe98f50e7dabe98059e33ce2f6d; base: c88c3d0.

The runtime dependency fix is correct on inspection, and the requested clean-install regression reproduces the original crash and passes after restoration. No confirmed implementation defect found. Review remains open for verification and reporting issues; review.clean was not created.

Open items

  1. Full-suite verification remains unresolved. The committed suite transcript records cd packages/sdk && ./node_modules/.bin/vitest run exiting 1. Its literal summary is:

     Test Files  41 failed | 202 passed | 3 skipped (246)
          Tests  182 failed | 3530 passed | 30 skipped (3742)
         Errors  81 errors
    

    Failures include missing relayflowd executables, but this review does not establish that every failure is environmental or predates the PR. The PR acknowledges that no baseline was established. Re-run with the required prerequisites, or compare failures against the base under the same environment before declaring the full change verified. I did not repeat that full-suite run; the targeted reruns below do not replace it. CI status at review time is captured in pr.txt.

  2. Correct the PR description's workflow claim. The body says “Workflow path additions are isolated in their own commit, as requested.” The actual PR contains no workflow changes. Remove that sentence or state that these additions were omitted. The current SDK manifest/test changes trigger the existing SDK CI job; a future change solely to scripts/cli-package-gate.mjs or packages/relayflows/** does not match that job's current PR path filter. This is a reporting discrepancy and future coverage limitation, not a failure of this PR's TypeScript regression. The captured body and changed-file list are in pr.txt.

Verification performed in this review

Each linked transcript contains literal commands, captured output and exit statuses.

  • Targeted tests: cd packages/sdk && ./node_modules/.bin/vitest run tests/runtime-dependencies.test.ts tests/cli-package-gate.test.ts — both tests pass. Real surface, SDK and CLI tarballs are installed outside the repo; both local and global checks print CHECK PASSED.
  • Mutation rerun: python3 evidence/cli-runtime-dependencies/mutation.py — moving TypeScript alone back to devDependencies fails both the import scan and the packed CLI (ERR_MODULE_NOT_FOUND from check-activities.js). The driver restores manifest and lock bytes, checks their git diff, then captures both passes. Existing evidence files overwritten by the driver were restored after capturing this separate review transcript.
  • Type checks and publishing tests: both SDK typecheck commands exit 0; node --test scripts/publish.test.mjs passes seven tests.
  • Global resolution probe: an ESM probe next to the globally installed wrapper resolves @relayflows/sdk/cli to the packed SDK under the temporary prefix. This checks that the wrapper is not accidentally exercising a nested registry SDK.

Diff and edge-case assessment

The manifest preserves the TypeScript range, the npm lock removes its dev-only marker, and the added undici declaration matches an existing runtime import. No SDK implementation or workflow changes are included. The test checks both bin owners explicitly, rejects ancestor node_modules, clears Node resolution overrides, omits unrelated optional runtime binaries, and checks that TypeScript does not expose global compiler bins. Network errors fail rather than silently skip; the explicit skip variable reports packaging as unverified. The AST scan documents its computed-import blind spot.

The packaging test requires built surface/SDK artifacts and Node >=22.18.0; existing CI builds those artifacts before running the SDK suite. Standalone binaries, older Node versions and Windows packaging are not established by these Unix-layout checks. Those are coverage limits, not newly demonstrated product regressions.

PR comments

Read all available conversation comments, review records and inline review comments for PR #608. The only conversation comment is CodeRabbit's skipped-review notice; reviews and inline review comments are empty. There are no substantive reviewer findings to resolve. See the exact responses in pr.txt.

No implementation or judging-gate changes were made during this review. Existing untracked testdata/preflight/core and testdata/preflight/package.json were left untouched.

Relayflow and others added 4 commits October 4, 2026 00:58
Session-Id: 570354ad-8fe1-4ec2-b442-d7bea7551ff7
Session-Id: 570354ad-8fe1-4ec2-b442-d7bea7551ff7
Session-Id: 570354ad-8fe1-4ec2-b442-d7bea7551ff7
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Session-Id: 570354ad-8fe1-4ec2-b442-d7bea7551ff7
@khaliqgant

Copy link
Copy Markdown
Member

The review's open items (unverified full suite vs base, committed evidence files, PR description accuracy) are being finished by fleet agent flows-608-finish-dp (dogpatch-mini, Relay channel flows-608-finish). It will not merge; a human merges flows PRs.

@AgentRelayBot
AgentRelayBot force-pushed the relayflow/flows-software-garden-d0e151d5 branch from a56ce50 to 812000a Compare October 4, 2026 08:02
@AgentRelayBot

Copy link
Copy Markdown
Contributor

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 812000a. Configure here.

@AgentRelayBot AgentRelayBot changed the title flows check crashes on a clean install: @relayflows/sdk imports typescript but only dev-depends on it fix(sdk): declare typescript and undici as runtime dependencies so flows check works on a clean install Oct 4, 2026
@AgentRelayBot
AgentRelayBot marked this pull request as ready for review October 4, 2026 10:24
@AgentRelayBot

Copy link
Copy Markdown
Contributor

Addressing the adversarial review's open items (head 812000a3):

  1. Full-suite verification. I ran the full SDK suite with an identical command and environment on head and on base d1877301 (vitest run --no-file-parallelism, real relayflowd, bun 1.4.0). Both runs had 52 failures, and the failing-test sets are identical (0 head-only, 0 base-only). All 52 are macOS-environmental (Linux-only bubblewrap isolation, plus local authored-runtime/worker tests). CI linux-x64-artifact, which runs the whole suite including both new tests, is green on this head. Details are in the PR description.
  2. Workflow claim. Removed. The PR changes no workflow files. The path-filter gap for gate-only changes is listed as a follow-up.
  3. Committed evidence. Removed: evidence/cli-runtime-dependencies/ no longer ships.
  4. Packaging regression. Shown red on base (ERR_MODULE_NOT_FOUND: typescript; the import scan flags typescript and undici) and green on head (4× CHECK PASSED, CLI_PACKAGE_OK).

Cursor Bugbot: no new issues. Leaving the merge to a human.

@khaliqgant
khaliqgant merged commit 345d87f into main Oct 4, 2026
10 of 11 checks passed
@khaliqgant
khaliqgant deleted the relayflow/flows-software-garden-d0e151d5 branch October 4, 2026 10:49
khaliqgant added a commit that referenced this pull request Oct 4, 2026
* ci: run the CLI packaging gate when its own inputs change

#608 added scripts/cli-package-gate.mjs (run by
packages/sdk/tests/cli-package-gate.test.ts) to catch a runtime dependency
missing from the published CLI. The workflows that run that test only
trigger on pull requests touching packages/sdk/** (and their own paths), so
a PR that changes only the gate script or packages/relayflows/** (the
`relayflows` wrapper package, whose dependency on @relayflows/sdk the gate
installs) skipped it. Add both paths to the pull_request filters of
cloud-runtime-artifact.yml and to both filters of surface-package.yml.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ci: list every CLI packaging-gate input in the artifact workflow's filter

Review on #610 (Devin, Codex): the gate also runs scripts/pack-release.mjs,
packs packages/surface/**, and checks
examples/dependency-upgrade-bot/dependency-upgrade-bot.flow.ts, so a PR
touching only one of those still skipped it. And the gate only runs in
cloud-runtime-artifact.yml's full vitest run; surface-package.yml runs
tests/authored-flow.test.ts, so adding the paths there gated nothing.
Put all gate inputs in cloud-runtime-artifact.yml's pull_request filter,
with a comment saying why, and drop the surface-package.yml change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Relayflow Lead <lead@relayflows.local>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

flows check crashes on a clean install: @relayflows/sdk imports typescript but only dev-depends on it

2 participants