Skip to content

Ship the diffr binary as per-platform npm packages - #88

Merged
thesiti92 merged 1 commit into
mainfrom
npm-platform-packages
Oct 5, 2026
Merged

thesiti92 merged 1 commit into
mainfrom
npm-platform-packages

Conversation

@thesiti92

Copy link
Copy Markdown
Contributor

@dev.fast/diffr only fetched the binary from GitHub releases at run time (diffr-fetch). Whiteboard's headless server on a remote host has to fetch it on attach, which fails on hosts that can reach npm but not github.com. This ships the binary through npm instead, the way esbuild and biome do.

  • Five platform packages, @dev.fast/diffr-{darwin-arm64,darwin-x64,linux-x64,linux-arm64,win32-x64}, each holding only diffr (or diffr.exe) with os/cpu set, and libc: glibc on Linux.
  • @dev.fast/diffr lists them as optionalDependencies at its own version. npm and pnpm install only the one that matches the machine.
  • diffrBinaryPath() returns that binary, or undefined (musl, Windows arm64, --omit=optional). It resolves from the package's own directory, so it still works when a bundler inlines the package (Whiteboard's tsdown build does) and under pnpm's isolated layout.
  • Removes bin/fetch.mjs, pins.json and scripts/pin.mjs. Registry integrity replaces the pinned checksums.
  • scripts/release.py npm stages the platform packages from the diffr-cli archives and adds optionalDependencies to diffr-ts/package.json at publish time. The source keeps none, so bun install --frozen-lockfile does not need versions that are not published yet.
  • release.yml gets an npm job after publish (platform packages first, skipping versions already published so a rerun is safe) and an npm-smoke matrix that installs from the registry on all five runners and checks diffr --version. It publishes with provenance and an NPM_TOKEN secret until trusted publishing is set up; npm trust needs the packages to exist first.
  • diffr-ts/package.json now moves with Cargo.toml in the release bump, enforced by a test, so the separate pin PR goes away.

Testing

  • release.py npm against the real 0.1.10 archives; packed all six tarballs (~16–18 MB each).
  • Installed from those tarballs: npm and pnpm on macOS arm64 install only diffr-darwin-arm64, and diffrBinaryPath() runs diffr 0.1.10. Same through an esbuild bundle under pnpm.
  • Docker: Debian arm64 and amd64 get their glibc package and run it. Alpine gets none and returns undefined.
  • bun test (against a local cargo build --locked) and bun run typecheck pass. actionlint is clean.

AI assistance: written with Claude Code.

@dev.fast/diffr now lists @dev.fast/diffr-{darwin-arm64,darwin-x64,
linux-x64,linux-arm64,win32-x64} as optional dependencies, so npm and
pnpm install the binary for the machine with the package.
diffrBinaryPath() resolves it. This replaces diffr-fetch and pins.json:
installs no longer reach GitHub, and package integrity replaces the
pinned checksums.

The release workflow stages each platform package from the diffr-cli
archive and publishes them, then this package. diffr-ts/package.json
now moves with Cargo.toml in the version bump, so there is no pin PR.

AI assistance: written with Claude Code.
@thesiti92
thesiti92 merged commit 789380d into main Oct 5, 2026
48 of 64 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants