bytecodealliance / bytecodealliance/ComponentizeJS
Bump oxc-parser to >=0.90.0: 0.76.0 bindings lack build provenance
- 主要語言
- Rust
- 星號
- 391
- 分支
- 53
- 平均合併
- 3 天 5 小時
- 30 天內合併 PR
- 1
描述
Would you consider bumping the `oxc-parser` dependency to `>=0.90.0`? At `0.76.0` its platform bindings publish without build provenance, which makes anything depending on componentize-js uninstallable under an installer that enforces provenance.
Filed here at the jco maintainers' suggestion — this started as [bytecodealliance/jco#1841](https://github.com/bytecodealliance/jco/issues/1841), and the reply was that the dependency needs updating here first.
The chain is `jco@1.27.0` → `@bytecodealliance/componentize-js@^0.22.0` → `oxc-parser@^0.76.0`. All 15 `@oxc-parser/binding-*` packages at `0.76.0` are missing build provenance attestations, while `oxc-parser` and `@oxc-project/types` at the same version have them.
It looks like a gap in one range rather than the norm: `@oxc-parser/binding-darwin-arm64` has attestations at `0.13.3`, none at `0.76.0`, and has them again from `0.90.0` through the current `0.143.0`. npm registry signatures are present throughout — build provenance specifically is what is missing.
Installers that enforce provenance and treat a loss of attestation as a downgrade refuse the install outright. It is not host-specific either: the resolver walks every optional binding, so all 15 have to be excluded individually to get past it, including the 13 for platforms a given project will never run.
Bumping to `>=0.90.0` would let componentize-js and jco install cleanly under those policies with no per-package exceptions.
貢獻指南
這個儲存庫沒有索引到貢獻指南
研究方向
首先定位 ComponentizeJS 中 oxc-parser 的相依性宣告,並檢查其版本受到何種限制。使用強制執行建置來源的安裝設定驗證相依性更新;當 componentize-js 及其下游的 jco 安裝不再需要依套件設定來源例外時,即表示完成。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- javascript
- 領域
- build-system
- Issue 類型
- 缺陷
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 活躍度
- 冷清
- 描述清晰度
- 描述清楚
- 新手友好度
- 72/100