Skip to content

feat(appkit): ship pnpm-patched dependencies inside published tarballs - #635

Open
MarioCadenas wants to merge 2 commits into
mainfrom
fix/bundle-patched-deps
Open

MarioCadenas wants to merge 2 commits into
mainfrom
fix/bundle-patched-deps

Conversation

@MarioCadenas

Copy link
Copy Markdown
Collaborator

What

Ship pnpm-patched dependencies inside the published @databricks/appkit / @databricks/appkit-ui tarballs, so apps that install appkit get the patched code.

A pnpm patch (patchedDependencies in pnpm-workspace.yaml) is applied only at this monorepo's install. It doesn't travel through a consumer's npm install / pnpm install, so without this an app built on a published appkit resolves the unpatched registry copy.

How

  • tools/bundle-patched-deps.ts plans, per tarball, which patched packages the package uses. It reads patchedDependencies and walks the real installed dependency tree: the package's own deps plus the CLI deps merged in from shared, directly or transitively.
  • tools/dist-appkit.ts copies those patched packages into the tarball's node_modules and lists them in bundledDependencies. Each bundled package's own dependencies are added to the tarball's dependencies at their installed versions. Package managers don't install those for a bundled package, and under pnpm a bundled package can only resolve what its parent declares.
  • The build fails instead of quietly shipping an unpatched copy when:
    • a patch entry is stale (the version in use doesn't match the patch);
    • the patch wasn't applied;
    • a bundled package needs a different dependency version than the tarball declares.
  • CI (PR Template Artifact) runs tools/verify-bundled-patches.ts after building the tarballs. It installs each tarball with npm and with pnpm and checks every bundled package resolves to the patched copy.

Adding a patch stays a pnpm-only step (pnpm patch / pnpm patch-commit). The release build picks it up automatically.

Impact

main defines no patches today, so nothing is bundled and the published tarballs are unchanged. The first user is the Reyden attachment patch for @databricks/sdk-statementexecution in #562, which will be rebased onto this PR.

Testing

  • tools/bundle-patched-deps.test.ts: 8 tests on pnpm-shaped fixture trees (direct, transitive, unused, stale entry, unapplied patch, dependency conflict, key parsing, config reading). Tools suite: 70/70.
  • Locally on this branch: pnpm pack:prerelease and the verify step pass, and nothing is bundled.
  • On feat(appkit): migrate analytics to the modular @databricks/sdk-* #562's build (with the statementexecution patch): npm and pnpm consumer installs resolve the patched copy. A deployed Databricks App (Apps runtime, pnpm 11) served Reyden INLINE + ARROW_STREAM straight from the bundled patched attachment, with no EXTERNAL_LINKS fallback.

This pull request and its description were written by Isaac.

@MarioCadenas
MarioCadenas requested a review from a team as a code owner October 7, 2026 13:47
@MarioCadenas
MarioCadenas added this pull request to stack #636 October 7, 2026 13:59
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

🤖 AppKit PR bot

🔬 Run evals

Start an eval for this PR from the evals-monitor app: Go to Evals Monitor →

📦 Try this PR's app template

Scaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh auth login — and the Databricks CLI):

gh run download 37794003562 -R databricks/appkit -n appkit-template-0.87.0-pr.e6e62fc-fix-bundle-patched-deps-635 -D appkit-pr-635 \
  && unzip -o "appkit-pr-635/appkit-template-0.87.0-pr.e6e62fc-fix-bundle-patched-deps-635.zip" -d "appkit-pr-635" \
  && databricks apps init --template "appkit-pr-635"

The template pins @databricks/appkit and @databricks/appkit-ui to tarballs built from this branch, so the scaffolded app runs against this PR's code.

MarioCadenas and others added 2 commits October 8, 2026 16:20
A pnpm patch (patchedDependencies) is applied only at this monorepo's install;
it does not travel through a consumer's npm or pnpm install, so an app built on
a published appkit would resolve the unpatched registry copy.

tools/bundle-patched-deps.ts plans, per tarball, which patched packages the
package uses (directly or transitively, including the CLI deps from shared),
and dist-appkit.ts copies those patched copies into the tarball and lists them
in bundledDependencies. Each bundled package's own dependencies are declared at
their installed versions, since package managers do not install those for a
bundled package. The build fails instead of shipping an unpatched copy when a
patch entry is stale, the patch is not applied, or a bundled package needs a
different dependency version than the tarball declares.

CI now installs the built tarballs with npm and pnpm
(tools/verify-bundled-patches.ts) and checks each bundled package resolves to
the patched copy. With no patches defined (as on main today) nothing is bundled
and the published tarballs are unchanged.

Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Drop the base-branch filter on the pull_request trigger so PRs whose base is
another PR branch (a stack) get CI, not only PRs into main.

Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
@MarioCadenas
MarioCadenas force-pushed the fix/bundle-patched-deps branch from f838d38 to 0ed9738 Compare October 8, 2026 14:37

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant