Skip to content

Fix two packaging bugs found while preparing for npm publish - #7

Merged
reshimu merged 2 commits into
mainfrom
npm-publish-packaging-fixes
Jul 28, 2026
Merged

reshimu merged 2 commits into
mainfrom
npm-publish-packaging-fixes

Conversation

@reshimu

@reshimu reshimu commented Jul 28, 2026

Copy link
Copy Markdown
Owner

Summary

Checked publish-readiness before attempting anything and found two real bugs:

  1. react/react-dom/vite/@vitejs/plugin-react/tailwindcss were listed under "dependencies". Since react/react-dom are also correctly declared as peerDependencies, this would have forced a second copy of React into every consumer's install (the classic "duplicate React instance" bug), plus Vite/Tailwind as unnecessary runtime installs for a package with zero actual runtime dependencies. Moved all five to devDependencies.
  2. "files": ["dist"] shipped the entire build output directory, but pnpm build writes both the library (dist/lib/) and this repo's own demo app into the same dist/ folder. Verified via npm pack --dry-run: 82.8 kB packed / 281.8 kB unpacked (including the full 216 kB demo bundle) → after narrowing to "files": ["dist/lib"]: 16.6 kB / 52.0 kB, exactly dist/lib/** + README.md + package.json.

Not attempted: the actual npm publish

  • No npm auth exists on this machine (npm whoami → ENEEDAUTH) — logging in requires Shimon's own credentials/OTP.
  • package.json still has "private": true, left as-is pending Shimon's decision on which npm scope/account to publish under (confirmed via a read-only npm view that the exact name @matrix-ai/ui is unclaimed, but scope ownership is a separate question).
  • See NEXT_TASK.md for the exact options and commands to run once both are resolved.

Test plan

  • pnpm typecheck / pnpm lint / pnpm test (15 files/70 tests, unchanged) / pnpm build / pnpm test:consumer / pnpm test:react-consumer / pnpm test:nextjs-consumer / pnpm check:bundle-size — all pass
  • npm pack --dry-run confirmed before/after tarball contents

🤖 Generated with Claude Code

shimonrosenberg and others added 2 commits July 28, 2026 13:40
Shimon asked to publish @matrix-ai/ui to npm. Checked readiness before
attempting anything and found two genuine bugs:

1. react, react-dom, vite, @vitejs/plugin-react, and tailwindcss were
   listed under "dependencies". react/react-dom were also correctly
   declared as peerDependencies, so leaving them in dependencies too
   would have forced a second copy of React into every consumer's
   install (the classic "duplicate React instance" bug), plus
   Vite/Tailwind as unnecessary runtime installs for a package with
   zero actual runtime dependencies. Moved all five to
   devDependencies.

2. "files": ["dist"] included the entire build output directory, but
   pnpm build writes both the library (dist/lib/) and this repo's own
   demo app (dist/assets/*.js, dist/index.html) into the same dist/
   folder. Verified with npm pack --dry-run: the tarball was 82.8 kB
   packed / 281.8 kB unpacked, including the full 216 kB demo bundle.
   Fixed: "files": ["dist/lib"]. Re-checked: 16.6 kB packed / 52.0 kB
   unpacked, 25 files, exactly dist/lib/** + README.md + package.json.

Re-ran full validation after both fixes: typecheck, lint, test (15
files/70 tests, unchanged), build, test:consumer, test:react-consumer,
test:nextjs-consumer, check:bundle-size all pass.

Did NOT attempt the actual npm publish -- this machine has no npm auth
configured (npm whoami -> ENEEDAUTH), and logging in on Shimon's behalf
isn't something an agent should do regardless of explicit request.
package.json still has "private": true, left as-is pending Shimon's
decision on which npm scope/account to publish under -- confirmed via
a read-only npm view that the exact package name is unclaimed, but
scope ownership is a separate question this session can't resolve. See
NEXT_TASK.md for the exact options and commands to run once both are
decided.
Shimon's answer to the npm-scope question: rename to match this repo's
GitHub org rather than try to claim the @matrix-ai npm org. Updated
package.json, all consumer fixtures, docs, and evergreen sections of
RESTART_PROMPT.md; left dated historical entries in CHANGELOG/ROADMAP/
STATE referencing the old name untouched. Full validation suite and
npm pack --dry-run re-verified green under the new name.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@reshimu
reshimu merged commit c476b6c into main Jul 28, 2026
1 check passed
@reshimu
reshimu deleted the npm-publish-packaging-fixes branch July 28, 2026 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants