Repository navigation
Publish to npm, trim OpenTelemetry to metrics, and fall back to FileDB when LMDB cannot load - #692
Merged
Merged
Conversation
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/vitestThe overall line coverage in commit 60c0a88 in the Show a line coverage summary of the most impacted files.
Updated |
satyakigh
force-pushed
the
npm-publish
branch
from
September 25, 2026 18:42
61d0dc8 to
5924cec
Compare
satyakigh
force-pushed
the
npm-publish
branch
from
September 26, 2026 01:17
ad4e7d4 to
54902b5
Compare
satyakigh
force-pushed
the
npm-publish
branch
from
September 28, 2026 19:51
64486b6 to
f029d42
Compare
satyakigh
added this pull request to stack #701
October 7, 2026 20:03
chrisqm-dev
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Production releases are published to npm as
@aws/cloudformation-languageserver, so standalone editors can install the server without downloading a platform archive:Two runtime changes make that package practical. The OpenTelemetry setup is reduced to the metrics pipeline the server actually uses, which removes most of the installed dependency tree, and the server falls back to the encrypted file store when the
lmdbnative addon cannot be loaded, since npm consumers run on hosts the release matrix does not cover. GitHub Release archives are unchanged apart from their generatedpackage.json; they remain the source forcfn-initand the legacy glibc 2.28 builds, which the npm package does not include.Published package
The production bundle directory is the npm package. The build writes a publish-ready
package.jsoninto it:mainandbinpoint atcfn-lsp-server-standalone.js, which now carries a Node shebang;engines.nodeis>=20; anddependenciesare the 17 packages the compiled bundle loads at runtime, pinned to lockfile versions and derived from the compiled module graph so the list cannot drift from the code. The tarball is platform-independent:node_modules/andbin/cfn-initare excluded, and npm resolves the native prebuilds forlmdband tree-sitter on the consumer's machine. It packs to 73 files and 37 MB compressed, 33 MB of which is the bundled cfn-lint wheels. The root manifest becomesprivate: trueand gains the repository, homepage, and bugs metadata npm displays. The package name already exists on the registry as a0.0.0placeholder, so the first workflow publication becomeslatest.Telemetry
OTELInstrumentationbuilds aMeterProviderwith the same OTLP exporter, export interval, and views as before, plus the singleRuntimeNodeInstrumentationthat was the only enabled one, instead of aNodeSDKcarryingauto-instrumentations-nodewith every other instrumentation switched off. The trace and log SDKs are dropped, andScopedTelemetryloses theTracerit never used. Emitted metrics, resource attributes, and export cadence are unchanged. The lockfile's production closure shrinks from 382 packages to 265 (OpenTelemetry from 80 to 13);THIRD-PARTY-LICENSES.txtand the SBOM are regenerated for the smaller tree.LMDB fallback
lmdbbinds its native addon while the module is evaluated, so a host without a usable prebuild fails on import rather than on the firstopen(). All runtime loading oflmdbgoes throughsrc/datastore/lmdb/LMDBModule.ts, andMultiDataStoreFactoryProviderprobes it before choosing a store: on failure it logs the cause, emitslmdb.unavailableunder theDataStoretelemetry scope, and usesFileStoreFactory. Windows and theFileDbfeature flag still select the file store without probing. Tests cover the fallback, the no-probe path, and the loader against the real module.Release workflow
release.ymlgains two jobs that run for stable tags only, after the long-running soak has exercised the release bundles on Node 18 through 24 across macOS, Linux, and Windows.publish-npmpublishes the linux-x64 bundle through npm trusted publishing (OIDC,release-npmenvironment) withnpm publish --provenance, after confirming the bundle version matches the tag and the tarball contains the required files and no platform-specific ones. It is idempotent: a version already on the registry is skipped.verify-publish-npminstalls the published version into a clean project and confirms the executable is linked, signatures audit clean, and a provenance attestation is attached.