Repository navigation
feat(appkit): ship pnpm-patched dependencies inside published tarballs - #635
Open
MarioCadenas wants to merge 2 commits into
Open
MarioCadenas wants to merge 2 commits into
MarioCadenas wants to merge 2 commits into
Conversation
Contributor
🤖 AppKit PR bot🔬 Run evalsStart an eval for this PR from the evals-monitor app: Go to Evals Monitor → 📦 Try this PR's app templateScaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh run download 37794003562 -R databricks/appkit -n appkit-template-0.87.0-pr.e6e62fc-fix-bundle-patched-deps-635 -D appkit-pr-635 \
&& unzip -o "appkit-pr-635/appkit-template-0.87.0-pr.e6e62fc-fix-bundle-patched-deps-635.zip" -d "appkit-pr-635" \
&& databricks apps init --template "appkit-pr-635"The template pins |
A pnpm patch (patchedDependencies) is applied only at this monorepo's install; it does not travel through a consumer's npm or pnpm install, so an app built on a published appkit would resolve the unpatched registry copy. tools/bundle-patched-deps.ts plans, per tarball, which patched packages the package uses (directly or transitively, including the CLI deps from shared), and dist-appkit.ts copies those patched copies into the tarball and lists them in bundledDependencies. Each bundled package's own dependencies are declared at their installed versions, since package managers do not install those for a bundled package. The build fails instead of shipping an unpatched copy when a patch entry is stale, the patch is not applied, or a bundled package needs a different dependency version than the tarball declares. CI now installs the built tarballs with npm and pnpm (tools/verify-bundled-patches.ts) and checks each bundled package resolves to the patched copy. With no patches defined (as on main today) nothing is bundled and the published tarballs are unchanged. Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Drop the base-branch filter on the pull_request trigger so PRs whose base is another PR branch (a stack) get CI, not only PRs into main. Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
MarioCadenas
force-pushed
the
fix/bundle-patched-deps
branch
from
October 8, 2026 14:37
f838d38 to
0ed9738
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Ship pnpm-patched dependencies inside the published
@databricks/appkit/@databricks/appkit-uitarballs, so apps that install appkit get the patched code.A pnpm patch (
patchedDependenciesinpnpm-workspace.yaml) is applied only at this monorepo's install. It doesn't travel through a consumer'snpm install/pnpm install, so without this an app built on a published appkit resolves the unpatched registry copy.How
tools/bundle-patched-deps.tsplans, per tarball, which patched packages the package uses. It readspatchedDependenciesand walks the real installed dependency tree: the package's own deps plus the CLI deps merged in fromshared, directly or transitively.tools/dist-appkit.tscopies those patched packages into the tarball'snode_modulesand lists them inbundledDependencies. Each bundled package's own dependencies are added to the tarball'sdependenciesat their installed versions. Package managers don't install those for a bundled package, and under pnpm a bundled package can only resolve what its parent declares.PR Template Artifact) runstools/verify-bundled-patches.tsafter building the tarballs. It installs each tarball with npm and with pnpm and checks every bundled package resolves to the patched copy.Adding a patch stays a pnpm-only step (
pnpm patch/pnpm patch-commit). The release build picks it up automatically.Impact
maindefines no patches today, so nothing is bundled and the published tarballs are unchanged. The first user is the Reydenattachmentpatch for@databricks/sdk-statementexecutionin #562, which will be rebased onto this PR.Testing
tools/bundle-patched-deps.test.ts: 8 tests on pnpm-shaped fixture trees (direct, transitive, unused, stale entry, unapplied patch, dependency conflict, key parsing, config reading). Tools suite: 70/70.pnpm pack:prereleaseand the verify step pass, and nothing is bundled.INLINE + ARROW_STREAMstraight from the bundled patchedattachment, with noEXTERNAL_LINKSfallback.This pull request and its description were written by Isaac.