fix(2245): declare gray-matter as runtime dependency (srv boot crash) - #2278
Merged
Merged
Conversation
srv/lib/skill-bundle.js (added in 43ead4c, feat #2245) imports gray-matter at module top-level, but it was only a devDependency. CF installs prod-only, so tutorials-srv crash-loops at boot with ERR_MODULE_NOT_FOUND: Cannot find package 'gray-matter'. Move it to dependencies and mark its transitive subtree non-dev in the lockfile.
The static-guards job had only `contents: read`, unlike every other npm-ci workflow (deploy, cds-build-staging, schema-drift, etc. all declare `packages: read`). The npm cache masked it: on a cache hit the private @sap-tutorials/cds-alert-notification tarball is already local, so no registry read is needed. Any PR that changes package-lock.json busts the cache key, forcing npm ci to re-download it, and the fallback GITHUB_TOKEN 403s without packages: read. Align guards with siblings.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
tutorials-srvcrash-loops at boot on DEV (0/1 instances) with:srv/lib/skill-bundle.js— added in43ead4c0(feat #2245, "compose SKILL.md from tutorial source + stamp") — doesimport matter from 'gray-matter'at module top level, on the srv boot path. Butgray-matterwas declared only in devDependencies. Cloud Foundry installs production dependencies only (npm ci --omit=dev), so the package is absent at runtime and the process exits 1 on every restart.This passed CI/tests because local + test installs include devDependencies (classic "undeclared runtime dep passes tests, crashes CF").
Fix
gray-matterfromdevDependencies→dependenciesinpackage.json.package-lock.json(npm install --package-lock-only): promotes the root entry and removes the"dev": truemarker from gray-matter and its now-prod-reachable transitive subtree (argparse, js-yaml@3, esprima, section-matter, extend-shallow, is-extendable, kind-of, sprintf-js, strip-bom-string).Two-file diff, no code changes.
Scope check
Scanned all bare (non-relative) imports across
srv/**against dev/prod dependency classification.gray-matteris the only newly-introduced dev-only import on the runtime path.vitest/express/happy-dometc. appear only insrv/**/__tests__/;archiver,graphql,@modelcontextprotocol/sdkwere already resolving in prior prod deploys.Verification
The DEV deploy that surfaced this got past HDI/migration (the ChatSettings v19 fix from #2277 held — no column error) and
cf deploy; it failed only because srv crashed at boot. After merge, redeploying DEV should bringtutorials-srvup and let the content-publish + smoke steps complete.