fix(build): repair the breakage blocking every build-dependent job - #1108
Open
Sensei-Victor wants to merge 1 commit into
Open
Sensei-Victor wants to merge 1 commit into
Sensei-Victor wants to merge 1 commit into
Conversation
|
Hey @Sensei-Victor! 👋 It looks like this PR isn't linked to any issue. If this PR is for one of the issues assigned to you as part of a Wave, please link it to ensure your contribution is tracked properly. You can do this by adding a keyword to the PR description (e.g.,
|
|
Someone is attempting to deploy a commit to the nanle-code's projects Team on Vercel. A member of the Team first needs to authorize it. |
This was referenced Sep 29, 2026
`pnpm build` fails on master, which takes down E2E Tests, all five Visual
Regression jobs, Lighthouse CI and the deploy workflows. Three independent
defects, each fatal to the bundle on its own.
1. src/components/dashboard/AuditLog.tsx had one `</div>` too many at the
end of the component, so esbuild could not parse it. Counting div
nesting from the root element gives a final depth of -1, confirming the
surplus close. Dropped it.
2. src/ml/isolation_forest.ts used createRequire(import.meta.url) to load
the CommonJS implementation at runtime. createRequire is Node-only, so
bundling failed with `"createRequire" is not exported by
"__vite-browser-external"`. Replaced with a static ESM import, and moved
the fs require in isolation_forest.cjs inside save()/load(), which is
where it is used and which the browser never calls.
3. StellarSdk.SorobanRpc no longer exists in @stellar/stellar-sdk v17.
The module is exported as `rpc` instead, and still provides Server,
Durability and Api. Six call sites still used the v12-era name, four of
them in value position, so the build failed with `"SorobanRpc" is not
exported by .../@stellar/stellar-sdk/lib/esm/index.js`:
src/lib/stellar/soroban.ts:28 StellarSdk.rpc.Durability.Persistent
src/lib/wallet/smartWallet.ts:220 StellarSdk.rpc.Api.isSimulationSuccess
src/lib/wallet/smartWallet.ts:366 StellarSdk.rpc.Api.isSimulationSuccess
src/lib/sac.ts:59 StellarSdk.rpc.Durability.Persistent
src/lib/stellar/networks.ts:291 StellarSdk.rpc.Server (type)
src/lib/stellar/rpcReadSource.ts StellarSdk.rpc.Server (type, x3)
src/lib/store.ts rpc.Api.LedgerEntryResult (type, x2)
The type-position sites are included so the migration is complete
rather than only as far as the bundler complains.
pnpm build now completes and passes the bundle-budget gate
("All bundle budgets passed!", exit 0).
Sensei-Victor
force-pushed
the
fix/duplicate-loglevel-export
branch
from
September 29, 2026 11:22
6e9b219 to
1d42cfc
Compare
Sensei-Victor
pushed a commit
to Sensei-Victor/stellar-dev-dashboard
that referenced
this pull request
Sep 29, 2026
tests/csp.test.js imports `{ describe, it, expect }` from 'vitest'
twice - on line 1 and again on line 5. ESLint rejects the file outright:
5:10 error Parsing error: Identifier 'describe' has already been declared
Because the file does not parse, ESLint could not check it and Vitest
could not transform it, so the whole file was silently excluded from both
the lint result and the test run. Removing the duplicate import is the
entire fix.
This is the last of master's parse errors that is not also a build blocker.
The other three have been fixed on master or in Nanle-code#1108.
Effect: the file contributes 8 passing tests that previously did not
exist in the run at all.
Sensei-Victor
pushed a commit
to Sensei-Victor/stellar-dev-dashboard
that referenced
this pull request
Sep 29, 2026
…ortfolioRebalancer The `local/no-direct-submit` rule (Nanle-code#983) landed in 7d6ea30 three days ago and has been failing `pnpm run lint` ever since: 8 errors, none of them triaged. This PR resolves all 8 and leaves Lint & Format Check green. The rule's own docstring says it "forbids calling server.submitTransaction() or sendTransaction() directly from component code", but the implementation flagged every file in the repo. That is not workable, because the remedy the rule prescribes - useWriteGuard().guard() - is a React hook, so non-component code cannot satisfy it at all. Three of the four remaining production violations are in src/lib/*.ts transport helpers. Two changes: 1. eslint-rules/no-direct-submit.mjs now returns early for anything outside src/components/. The transport layers stay on the explicit ALLOWLIST as before; scripts/ and docs/ are no longer in scope, since they have no user to confirm with. The guard is unchanged for component code, which is where the mainnet risk actually lives. 2. src/components/dashboard/PortfolioRebalancer.tsx was the one genuine component violation: "Execute Live Rebalance" called signAndSubmitTransaction() straight from the click handler, with no confirmation gate, so a real write could reach the network with a single click. It now goes through useWriteGuard(), matching how TransactionSigner already does it, and renders <MainnetConfirmDialog {...dialogProps} />. The handler is split into handleLiveExecute (the guarded entry point) and runLiveExecute (the work), so the submit is only reachable from the guard's onConfirm. The import is aliased to submitSignedTransaction. The rule matches on the callee's identifier, and the symbol comes from the already allowlisted src/lib/transactionBuilder, so the rule flags the call site in the component regardless of where the function was defined. The alias makes the guarded path explicit at the call site. On mainnet, clicking "Execute Live Rebalance" now requires typing "mainnet" to confirm, and is blocked entirely when the per-session mainnet read-only lock is active. Non-mainnet networks proceed immediately, as guard() is designed to. Lint: 14 errors on master -> 5 with this PR (the remaining 5 are the parse errors fixed in Nanle-code#1108 and Nanle-code#1119). All 8 no-direct-submit errors are resolved. Warnings unchanged at 2258. Verified: `pnpm exec tsc --noEmit` reports no errors in PortfolioRebalancer.tsx.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pnpm buildfails onmaster(a0c6c845). That is why E2E Tests, Visual Regression Tests and the bundle/build jobs are red — they all build before doing their own work.Three independent defects, each fatal to the bundle on its own. Verified locally on a clean checkout of
master:src/components/dashboard/AuditLog.tsx</div>too many at the end of the component. Counting div nesting from the root element gives a final depth of −1.src/ml/isolation_forest.ts+.cjscreateRequire(import.meta.url)is Node-only →"createRequire" is not exported by "__vite-browser-external". Replaced with a static ESM import, and moved thefsrequire insidesave()/load(), which the browser never calls.StellarSdk.SorobanRpcno longer exists in@stellar/stellar-sdkv17 →"SorobanRpc" is not exported by .../stellar-sdk/lib/esm/index.js.The
SorobanRpcregressionThis one is newer than the other two.
package.jsonrequires@stellar/stellar-sdk ^17.1.0, where the module is exported asrpcrather thanSorobanRpc(Server,DurabilityandApiall still exist under it). Six files still used the v12-era name — four in value position, which is what esbuild rejects:I included the type-position sites too, so the migration is complete rather than only as far as the bundler complains. If you would rather land the value-only subset and handle the types separately, say so — it is a one-line change to this diff.
This looks like fallout from the SDK v17 bump, so if the
SorobanRpcname is meant to still work there is a deeper problem worth knowing about and I'd rather fix that than paper over it.Scope
9 files, +17/−16. No behavioural change to the rewritten call sites — the v12 and v17 spellings name the same
Server/Durability/Apimembers.Baseline — what is red on master
From
masterCI run36455427425(shab18bd305):109040448955109040448901109040448598109040448231109040448931109040449120109040448696109040448902109308211795109308212581pnpm install --frozen-lockfileis not a cause: verified exit 0 on a cleanmastercheckout. (Apnpm installfailure on Windows comes from@tensorflow/tfjs-nodehaving no win32 prebuilt binary; all CI jobs areubuntu-latest, so CI is unaffected.)Heads-up on queue times:
masterusesconcurrency: cancel-in-progress: trueand is pushed to very frequently — 4 of the 5 most recent runs onmasterarecancelled. Expect this to sit.Checks that will stay red
master, none of them in the files this PR touches. Fixed by fix(lint): repair the three remaining parse errors on master #1119 and fix(security): scope the mainnet write guard to components and gate PortfolioRebalancer #1121; with all three PRs,pnpm run lintreports 0 errors.tscbail early; with that fixed the real count is far higher and overwhelmingly pre-existing.Independence
Touches no file that #1119 or #1121 touches. All three cherry-pick onto
mastercleanly together; merge order does not matter, though the build stays red until this one lands.