Vendor OpenClaw source as Adolf fork baseline
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
This commit is contained in:
373
test/scripts/root-dependency-ownership-audit.test.ts
Normal file
373
test/scripts/root-dependency-ownership-audit.test.ts
Normal file
@@ -0,0 +1,373 @@
|
||||
// Root Dependency Ownership Audit tests cover root dependency ownership audit script behavior.
|
||||
import { mkdirSync, mkdtempSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import path from "node:path";
|
||||
import { afterEach, describe, expect, it } from "vitest";
|
||||
import {
|
||||
classifyRootDependencyOwnership,
|
||||
collectRootDependencyOwnershipAudit,
|
||||
collectRootDependencyOwnershipCheckErrors,
|
||||
collectModuleSpecifiers,
|
||||
} from "../../scripts/root-dependency-ownership-audit.mjs";
|
||||
|
||||
const tempDirs: string[] = [];
|
||||
|
||||
afterEach(() => {
|
||||
for (const dir of tempDirs.splice(0)) {
|
||||
rmSync(dir, { force: true, recursive: true });
|
||||
}
|
||||
});
|
||||
|
||||
function makeTempRepo() {
|
||||
const dir = mkdtempSync(path.join(tmpdir(), "openclaw-root-deps-audit-"));
|
||||
tempDirs.push(dir);
|
||||
return dir;
|
||||
}
|
||||
|
||||
function writeRepoFile(repoRoot: string, relativePath: string, value: string) {
|
||||
const filePath = path.join(repoRoot, relativePath);
|
||||
mkdirSync(path.dirname(filePath), { recursive: true });
|
||||
writeFileSync(filePath, value, "utf8");
|
||||
}
|
||||
|
||||
describe("collectModuleSpecifiers", () => {
|
||||
it("captures require.resolve package lookups used by runtime shims and bundled plugins", () => {
|
||||
expect([
|
||||
...collectModuleSpecifiers(`
|
||||
const require = createRequire(import.meta.url);
|
||||
const runtimeRequire = createRequire(runtimePackagePath);
|
||||
require.resolve("gaxios");
|
||||
runtimeRequire.resolve("openshell/package.json");
|
||||
resolvePackageFileForCommandExplanation("tree-sitter-bash", "tree-sitter-bash.wasm");
|
||||
`),
|
||||
]).toEqual(["gaxios", "openshell/package.json", "tree-sitter-bash"]);
|
||||
});
|
||||
|
||||
it("resolves simple string constants used by lazy runtime imports", () => {
|
||||
expect([
|
||||
...collectModuleSpecifiers(`
|
||||
const READABILITY_MODULE = "@mozilla/readability";
|
||||
const CLAWPDF_MODULE = "clawpdf";
|
||||
const CIAO_MODULE_ID = "@homebridge/ciao";
|
||||
let SQLITE_VEC_MODULE_ID = "sqlite-vec";
|
||||
import(READABILITY_MODULE);
|
||||
import(CLAWPDF_MODULE);
|
||||
require(CIAO_MODULE_ID);
|
||||
require.resolve(SQLITE_VEC_MODULE_ID);
|
||||
`),
|
||||
]).toEqual(["@mozilla/readability", "clawpdf", "@homebridge/ciao", "sqlite-vec"]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("classifyRootDependencyOwnership", () => {
|
||||
it("treats scripts and tests as dev-only candidates", () => {
|
||||
expect(
|
||||
classifyRootDependencyOwnership({
|
||||
sections: ["scripts", "test"],
|
||||
}),
|
||||
).toEqual({
|
||||
category: "script_or_test_only",
|
||||
recommendation: "consider moving from dependencies to devDependencies",
|
||||
});
|
||||
});
|
||||
|
||||
it("treats extension-only deps as localizable", () => {
|
||||
expect(
|
||||
classifyRootDependencyOwnership({
|
||||
depName: "vendor-sdk",
|
||||
sections: ["extensions", "test"],
|
||||
}),
|
||||
).toEqual({
|
||||
category: "extension_only_localizable",
|
||||
recommendation:
|
||||
"remove from root package.json and rely on owning extension manifests plus doctor --fix",
|
||||
});
|
||||
});
|
||||
|
||||
it("allows explicit root-owned internal extension runtime dependencies", () => {
|
||||
expect(
|
||||
classifyRootDependencyOwnership({
|
||||
depName: "playwright-core",
|
||||
sections: ["extensions", "test"],
|
||||
}),
|
||||
).toEqual({
|
||||
category: "root_owned_extension_runtime",
|
||||
recommendation:
|
||||
"keep at root; the internal browser runtime is shipped with core even though downloadable browser-adjacent plugins also declare it",
|
||||
});
|
||||
});
|
||||
|
||||
it("treats src-owned deps as core runtime", () => {
|
||||
expect(
|
||||
classifyRootDependencyOwnership({
|
||||
sections: ["src"],
|
||||
}),
|
||||
).toEqual({
|
||||
category: "core_runtime",
|
||||
recommendation: "keep at root",
|
||||
});
|
||||
});
|
||||
|
||||
it("treats unreferenced deps as removal candidates", () => {
|
||||
expect(
|
||||
classifyRootDependencyOwnership({
|
||||
sections: [],
|
||||
}),
|
||||
).toEqual({
|
||||
category: "unreferenced",
|
||||
recommendation: "investigate removal; no direct source imports found in scanned files",
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("collectRootDependencyOwnershipCheckErrors", () => {
|
||||
it("catches dependencies mirrored at root but only imported by one extension", () => {
|
||||
const repoRoot = makeTempRepo();
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"package.json",
|
||||
JSON.stringify({ dependencies: { "vendor-sdk": "^1.0.0" } }),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/qqbot/package.json",
|
||||
JSON.stringify({ dependencies: { "vendor-sdk": "^1.0.0" } }),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/qqbot/src/setup.ts",
|
||||
'const sdk = await import("vendor-sdk");\n',
|
||||
);
|
||||
|
||||
const records = collectRootDependencyOwnershipAudit({ repoRoot, scanRoots: ["extensions"] });
|
||||
|
||||
expect(collectRootDependencyOwnershipCheckErrors(records)).toEqual([
|
||||
"root dependency 'vendor-sdk' is extension-owned (remove from root package.json and rely on owning extension manifests plus doctor --fix); extension declarations: qqbot:dependencies; sample imports: extensions/qqbot/src/setup.ts",
|
||||
]);
|
||||
});
|
||||
|
||||
it("classifies root dependencies referenced through constant dynamic imports", () => {
|
||||
const repoRoot = makeTempRepo();
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"package.json",
|
||||
JSON.stringify({ dependencies: { clawpdf: "^0.2.0", "sqlite-vec": "0.1.9" } }),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"src/media/pdf-extract.ts",
|
||||
`
|
||||
const CLAWPDF_MODULE = "clawpdf";
|
||||
export async function loadPdf() {
|
||||
return import(CLAWPDF_MODULE);
|
||||
}
|
||||
`,
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"packages/memory-host-sdk/src/host/sqlite-vec.ts",
|
||||
`
|
||||
const SQLITE_VEC_MODULE_ID = "sqlite-vec";
|
||||
export async function loadSqliteVecModule() {
|
||||
return import(SQLITE_VEC_MODULE_ID);
|
||||
}
|
||||
`,
|
||||
);
|
||||
|
||||
const records = collectRootDependencyOwnershipAudit({
|
||||
repoRoot,
|
||||
scanRoots: ["src", "packages"],
|
||||
});
|
||||
|
||||
expect(records).toEqual([
|
||||
{
|
||||
category: "core_runtime",
|
||||
declaredInExtensions: [],
|
||||
depName: "clawpdf",
|
||||
fileCount: 1,
|
||||
internalizedBundledRuntimeOwners: [],
|
||||
recommendation: "keep at root",
|
||||
sampleFiles: ["src/media/pdf-extract.ts"],
|
||||
sections: ["src"],
|
||||
spec: "^0.2.0",
|
||||
},
|
||||
{
|
||||
category: "core_runtime",
|
||||
declaredInExtensions: [],
|
||||
depName: "sqlite-vec",
|
||||
fileCount: 1,
|
||||
internalizedBundledRuntimeOwners: [],
|
||||
recommendation: "keep at root",
|
||||
sampleFiles: ["packages/memory-host-sdk/src/host/sqlite-vec.ts"],
|
||||
sections: ["packages"],
|
||||
spec: "0.1.9",
|
||||
},
|
||||
]);
|
||||
});
|
||||
|
||||
it("fails only extension-owned root dependencies", () => {
|
||||
expect(
|
||||
collectRootDependencyOwnershipCheckErrors([
|
||||
{
|
||||
category: "extension_only_localizable",
|
||||
declaredInExtensions: ["qqbot:dependencies"],
|
||||
depName: "@tencent-connect/qqbot-connector",
|
||||
recommendation:
|
||||
"remove from root package.json and rely on owning extension manifests plus doctor --fix",
|
||||
sampleFiles: ["extensions/qqbot/src/bridge/setup/finalize.ts"],
|
||||
},
|
||||
{
|
||||
category: "unreferenced",
|
||||
declaredInExtensions: [],
|
||||
depName: "@mozilla/readability",
|
||||
recommendation: "investigate removal; no direct source imports found in scanned files",
|
||||
sampleFiles: [],
|
||||
},
|
||||
]),
|
||||
).toEqual([
|
||||
"root dependency '@tencent-connect/qqbot-connector' is extension-owned (remove from root package.json and rely on owning extension manifests plus doctor --fix); extension declarations: qqbot:dependencies; sample imports: extensions/qqbot/src/bridge/setup/finalize.ts",
|
||||
]);
|
||||
});
|
||||
|
||||
it("does not fail explicitly root-owned internal extension runtime dependencies", () => {
|
||||
const repoRoot = makeTempRepo();
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"package.json",
|
||||
JSON.stringify({
|
||||
dependencies: { "@homebridge/ciao": "^1.3.7", "playwright-core": "1.59.1" },
|
||||
}),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/bonjour/package.json",
|
||||
JSON.stringify({ dependencies: { "@homebridge/ciao": "^1.3.7" } }),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/bonjour/src/advertiser.ts",
|
||||
'const CIAO_MODULE_ID = "@homebridge/ciao";\nimport(CIAO_MODULE_ID);\n',
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/browser/package.json",
|
||||
JSON.stringify({ dependencies: { "playwright-core": "1.59.1" } }),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/browser/src/browser/playwright-core.runtime.ts",
|
||||
'const runtime = require("playwright-core");\n',
|
||||
);
|
||||
|
||||
const records = collectRootDependencyOwnershipAudit({ repoRoot, scanRoots: ["extensions"] });
|
||||
|
||||
expect(records).toEqual([
|
||||
{
|
||||
category: "root_owned_extension_runtime",
|
||||
declaredInExtensions: ["bonjour:dependencies"],
|
||||
depName: "@homebridge/ciao",
|
||||
fileCount: 1,
|
||||
internalizedBundledRuntimeOwners: [],
|
||||
recommendation:
|
||||
"keep at root; the Bonjour runtime is shipped with packaged startup surfaces even though the bundled plugin also declares it",
|
||||
sampleFiles: ["extensions/bonjour/src/advertiser.ts"],
|
||||
sections: ["extensions"],
|
||||
spec: "^1.3.7",
|
||||
},
|
||||
{
|
||||
category: "root_owned_extension_runtime",
|
||||
declaredInExtensions: ["browser:dependencies"],
|
||||
depName: "playwright-core",
|
||||
fileCount: 1,
|
||||
internalizedBundledRuntimeOwners: [],
|
||||
recommendation:
|
||||
"keep at root; the internal browser runtime is shipped with core even though downloadable browser-adjacent plugins also declare it",
|
||||
sampleFiles: ["extensions/browser/src/browser/playwright-core.runtime.ts"],
|
||||
sections: ["extensions"],
|
||||
spec: "1.59.1",
|
||||
},
|
||||
]);
|
||||
expect(collectRootDependencyOwnershipCheckErrors(records)).toStrictEqual([]);
|
||||
});
|
||||
|
||||
it("allows runtime deps for bundled plugins that are still packaged in core", () => {
|
||||
const repoRoot = makeTempRepo();
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"package.json",
|
||||
JSON.stringify({
|
||||
dependencies: { "vendor-sdk": "^1.0.0" },
|
||||
files: ["dist/", "!dist/extensions/externalized/**"],
|
||||
}),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/internal/package.json",
|
||||
JSON.stringify({ dependencies: { "vendor-sdk": "^1.0.0" } }),
|
||||
);
|
||||
writeRepoFile(repoRoot, "extensions/internal/openclaw.plugin.json", JSON.stringify({}));
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/internal/src/setup.ts",
|
||||
'const sdk = await import("vendor-sdk");\n',
|
||||
);
|
||||
|
||||
const records = collectRootDependencyOwnershipAudit({ repoRoot, scanRoots: ["extensions"] });
|
||||
|
||||
expect(records).toEqual([
|
||||
{
|
||||
category: "root_owned_extension_runtime",
|
||||
declaredInExtensions: ["internal:dependencies"],
|
||||
depName: "vendor-sdk",
|
||||
fileCount: 1,
|
||||
internalizedBundledRuntimeOwners: ["internal:dependencies"],
|
||||
recommendation:
|
||||
"keep at root while bundled plugin runtime dependencies are internalized; owners: internal:dependencies",
|
||||
sampleFiles: ["extensions/internal/src/setup.ts"],
|
||||
sections: ["extensions"],
|
||||
spec: "^1.0.0",
|
||||
},
|
||||
]);
|
||||
expect(collectRootDependencyOwnershipCheckErrors(records)).toStrictEqual([]);
|
||||
});
|
||||
|
||||
it("keeps excluded bundled plugin deps localizable", () => {
|
||||
const repoRoot = makeTempRepo();
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"package.json",
|
||||
JSON.stringify({
|
||||
dependencies: { "vendor-sdk": "^1.0.0" },
|
||||
files: ["dist/", "!dist/extensions/externalized/**"],
|
||||
}),
|
||||
);
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/externalized/package.json",
|
||||
JSON.stringify({ dependencies: { "vendor-sdk": "^1.0.0" } }),
|
||||
);
|
||||
writeRepoFile(repoRoot, "extensions/externalized/openclaw.plugin.json", JSON.stringify({}));
|
||||
writeRepoFile(
|
||||
repoRoot,
|
||||
"extensions/externalized/src/setup.ts",
|
||||
'const sdk = await import("vendor-sdk");\n',
|
||||
);
|
||||
|
||||
const records = collectRootDependencyOwnershipAudit({ repoRoot, scanRoots: ["extensions"] });
|
||||
|
||||
expect(records).toEqual([
|
||||
{
|
||||
category: "extension_only_localizable",
|
||||
declaredInExtensions: ["externalized:dependencies"],
|
||||
depName: "vendor-sdk",
|
||||
fileCount: 1,
|
||||
internalizedBundledRuntimeOwners: [],
|
||||
recommendation:
|
||||
"remove from root package.json and rely on owning extension manifests plus doctor --fix",
|
||||
sampleFiles: ["extensions/externalized/src/setup.ts"],
|
||||
sections: ["extensions"],
|
||||
spec: "^1.0.0",
|
||||
},
|
||||
]);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user