From 438a8ab1a4cc94e21bb8b520980a7ff643ca2a43 Mon Sep 17 00:00:00 2001 From: Fede Barcelona Date: Mon, 29 Jun 2026 17:42:17 +0200 Subject: [PATCH 1/2] build: bundle extension with esbuild The extension shipped every tsc-emitted file plus the full node_modules tree in the .vsix (198 files, 361KB). Bundling src/extension.ts into a single minified dist/extension.js with esbuild inlines the runtime deps (all pure JS) and drops node_modules from the package: 7 files, 75KB (-79%), with faster activation since the host resolves one module instead of ~190. tsc stays for type-checking (--noEmit) and for compiling tests to out/. Also fixes a pre-existing ordering-dependent flaky test in highlighters (highlightLayer relied on extension.activate() having run in another test file first) by stubbing vulnTreeDataProvider locally. --- .vscode/launch.json | 2 +- .vscodeignore | 11 + esbuild.js | 53 +++ package-lock.json | 485 +++++++++++++++++++++ package.json | 15 +- src/fileScanners/test/highlighters.test.ts | 4 + 6 files changed, 564 insertions(+), 6 deletions(-) create mode 100644 esbuild.js diff --git a/.vscode/launch.json b/.vscode/launch.json index 7a93050..5ac36f1 100755 --- a/.vscode/launch.json +++ b/.vscode/launch.json @@ -13,7 +13,7 @@ "--extensionDevelopmentPath=${workspaceFolder}" ], "outFiles": [ - "${workspaceFolder}/out/**/*.js" + "${workspaceFolder}/dist/**/*.js" ], "preLaunchTask": "${defaultBuildTask}", } diff --git a/.vscodeignore b/.vscodeignore index 72aa0fe..73b0134 100755 --- a/.vscodeignore +++ b/.vscodeignore @@ -1,6 +1,9 @@ .vscode/** .vscode-test/** src/** +out/** +node_modules/** +esbuild.js .gitignore .yarnrc vsc-extension-quickstart.md @@ -9,3 +12,11 @@ vsc-extension-quickstart.md **/*.map **/*.ts **/.vscode-test.* +.github/** +.direnv/** +.envrc +.pre-commit-config.yaml +Justfile +flake.nix +flake.lock +vsix.nix diff --git a/esbuild.js b/esbuild.js new file mode 100644 index 0000000..db3e47f --- /dev/null +++ b/esbuild.js @@ -0,0 +1,53 @@ +const esbuild = require("esbuild"); + +const production = process.argv.includes("--production"); +const watch = process.argv.includes("--watch"); + +/** + * Logs esbuild errors/warnings in a format the VS Code problem matcher understands. + * @type {import('esbuild').Plugin} + */ +const esbuildProblemMatcherPlugin = { + name: "esbuild-problem-matcher", + setup(build) { + build.onStart(() => { + console.log("[watch] build started"); + }); + build.onEnd((result) => { + result.errors.forEach(({ text, location }) => { + console.error(`✘ [ERROR] ${text}`); + if (location) { + console.error(` ${location.file}:${location.line}:${location.column}:`); + } + }); + console.log("[watch] build finished"); + }); + }, +}; + +async function main() { + const ctx = await esbuild.context({ + entryPoints: ["src/extension.ts"], + bundle: true, + format: "cjs", + minify: production, + sourcemap: !production, + sourcesContent: false, + platform: "node", + outfile: "dist/extension.js", + external: ["vscode"], + logLevel: "silent", + plugins: [esbuildProblemMatcherPlugin], + }); + if (watch) { + await ctx.watch(); + } else { + await ctx.rebuild(); + await ctx.dispose(); + } +} + +main().catch((e) => { + console.error(e); + process.exit(1); +}); diff --git a/package-lock.json b/package-lock.json index 9736b79..2d094da 100755 --- a/package-lock.json +++ b/package-lock.json @@ -23,6 +23,7 @@ "@vscode/test-cli": "^0.0.8", "@vscode/test-electron": "^2.3.9", "@vscode/vsce": "^3.9.2", + "esbuild": "^0.28.1", "eslint": "^8.57.0", "ovsx": "^0.10.1", "sinon": "^18.0.0", @@ -283,6 +284,448 @@ "tslib": "^2.4.0" } }, + "node_modules/@esbuild/aix-ppc64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/aix-ppc64/-/aix-ppc64-0.28.1.tgz", + "integrity": "sha512-Svl7tq8k/08+p6CXPpRjQ1fKX+1odH/BQbb48fV6fj3CWHhsoIOoY87w1oHXm0qEpkIK3ZfVgp0hed3XBXzXMQ==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "aix" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/android-arm": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/android-arm/-/android-arm-0.28.1.tgz", + "integrity": "sha512-0k2F129Xdio1TdJfzJ8sy1Q47vUD2NnwdhiAf7drUN1EBTfPf4hsFCtmMgu/6m8JSzsBrlmVjudMBQqOfG8usQ==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/android-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/android-arm64/-/android-arm64-0.28.1.tgz", + "integrity": "sha512-34EGEbCIAgosYz6goLcopX6Mo7NyGv9tfwEM2/7Ce2VcVRk568iSvniGWcUXIy7wEDR1wzolcxcriFVrWYcwBg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/android-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/android-x64/-/android-x64-0.28.1.tgz", + "integrity": "sha512-dbwY7ltSMDWsRatcRpCnES4F+im88OCUgGZjy52shC7GqHRE/cYlxNbB4Z4UpJswpcc4Qxd2oE/ufM0p61IKng==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/darwin-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/darwin-arm64/-/darwin-arm64-0.28.1.tgz", + "integrity": "sha512-TZbWkQY7kvTAXbXUT7uVACR5cMHsDiSz9z7ZKAX/RTq/WJEk3QyRr0wZpNhBDX+/0CtdqUIJlOiodQcta6tY3Q==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/darwin-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/darwin-x64/-/darwin-x64-0.28.1.tgz", + "integrity": "sha512-zfdzgK9ACBNZLI/CyHTOx81SyNbM6YXn7rxSgX97VjyiPl9W1i4Ka4fgKECEoFCKGpvBj5qArWIGgQjOwkgskQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/freebsd-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/freebsd-arm64/-/freebsd-arm64-0.28.1.tgz", + "integrity": "sha512-wG2EA8ENdEI0qhkSZMjfqrdY+ziCYCPMmtZjjIwOmXFjmyzEHn+UUxk5of+SYsjtfs3VpnlC7QLzSI5hY/rOAw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/freebsd-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/freebsd-x64/-/freebsd-x64-0.28.1.tgz", + "integrity": "sha512-i7dZ9vQgnvSCzi/rYCXNgtF/U+eKZNJBzu3eTQbRgHnM7tNSizLOkRFAl3qzVc/Op/u5YkHHa4pf/3DOYHthLQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-arm": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-arm/-/linux-arm-0.28.1.tgz", + "integrity": "sha512-qVXBOHQS+d5Y722GwJzJUtOLlX7km3CraOaGormF1pDtPd2C/l1SHRPgjLunLGe51Sh5YYWKMFDyV4SxgMQYTQ==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-arm64/-/linux-arm64-0.28.1.tgz", + "integrity": "sha512-yHs+0uc8+nvEAfAfxrWQKK5peSNzBc4PegcMO0EJ2hT71uA7vB8Ihg2e77R2P7SG5uYjPbHlLLmve4LLLRCf0g==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-ia32": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-ia32/-/linux-ia32-0.28.1.tgz", + "integrity": "sha512-d1z4ZuP0ajrfz/FhGT4vv278rX8KnPPJx8i5+AtK7TYbx9Le9F1hyzurZpkEyjkGa9dUGhQow4C1NmeGvqxN2w==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-loong64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-loong64/-/linux-loong64-0.28.1.tgz", + "integrity": "sha512-M5sRjUVZrkm1OAPR3dlOYzNmN+loZKGVi1VUQGrwuqLcbR6qeAz+famMhjASeH3YVKvZz+zT1jlh/keC3Rj/lg==", + "cpu": [ + "loong64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-mips64el": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-mips64el/-/linux-mips64el-0.28.1.tgz", + "integrity": "sha512-mRObBZeHh2OxcBFPWE/FjylkRgZdYuiTR3vaTozquCGOH14iP9oN4x4Ge81CoIDYQrXmIxpFumJBu5MtZpnQJQ==", + "cpu": [ + "mips64el" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-ppc64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-ppc64/-/linux-ppc64-0.28.1.tgz", + "integrity": "sha512-slScBsMAb3GFDcdrCgLwZtPYRoH2H/youv10QiZyRjmsP48fznoveWytSgCI/R0ZcUgpc0ZhIUEx6LHts8yrfQ==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-riscv64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-riscv64/-/linux-riscv64-0.28.1.tgz", + "integrity": "sha512-kw0owk1o0GFETUJyW0jc0G4Yzs0BHZn0JDZ8JRT088vjJYX777BAs1fDGxAC+q831qOs2DTC96mNsG2opdfyyQ==", + "cpu": [ + "riscv64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-s390x": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-s390x/-/linux-s390x-0.28.1.tgz", + "integrity": "sha512-/lAIjX8aYFRByhh6L5rYtPEDRqa9de/4V/juOXcta5frjvzXO4/sqEtyytse0g3zZFuWu5cDN0MkLz2qRDD2Ag==", + "cpu": [ + "s390x" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/linux-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/linux-x64/-/linux-x64-0.28.1.tgz", + "integrity": "sha512-u/anNYF2mmVOEDwLtnQ1wOr3EZ9sTNGLWrsYGYwHWzGA3Si84IOkHXlbWTD1NB+9/1lcnweYKO54uhxZydNzfA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/netbsd-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/netbsd-arm64/-/netbsd-arm64-0.28.1.tgz", + "integrity": "sha512-oks0DYbLwWMmaakTsCb+zL4E+aHRVLom9IJZOAthMQEPiQmydXHkziYEsGYRx0uNV/IjEKGAV941JzH02pflqw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "netbsd" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/netbsd-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/netbsd-x64/-/netbsd-x64-0.28.1.tgz", + "integrity": "sha512-aeL6lAnN89Hz43Mlh1G8ARasbuoYvSITDEx0tHh5b7jJnHcssqgjy9Yx430GDpmCa6OyrKoS0aNRjKundRizGg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "netbsd" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/openbsd-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/openbsd-arm64/-/openbsd-arm64-0.28.1.tgz", + "integrity": "sha512-MEFJe5C3R8pwXdZ5Y21oo6m7ePiS0d9pWucn99O/wvyJZChoIQKrQDxKrGeW8F5+T0okTHesAmDeiHDTIq0V/Q==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openbsd" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/openbsd-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/openbsd-x64/-/openbsd-x64-0.28.1.tgz", + "integrity": "sha512-i/ZLIOafE0Z8cI/XANJAixoJL/uRAoS2xOA3rb0xN+KK0K177cMAsQYkzHtBrtMXAKuAc7HGgcWiZ/sRC1Nxgw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openbsd" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/openharmony-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/openharmony-arm64/-/openharmony-arm64-0.28.1.tgz", + "integrity": "sha512-ge+Z7EXFNt2BO1oAMsVpiQ8EwndV9i1xXerAeTIK7AtPs3bKFXQM7nlRxDSIUIMeueR1CNXxqztLzdNeReKBJg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openharmony" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/sunos-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/sunos-x64/-/sunos-x64-0.28.1.tgz", + "integrity": "sha512-BEjgtECkL3vY+SaSQ6nzVfiALUeFxpawyp8Jmf5PtYhf1Ug40N1h/hxlhts+f1FvSvarEigdxS3BlSMI2PJLcQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "sunos" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/win32-arm64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/win32-arm64/-/win32-arm64-0.28.1.tgz", + "integrity": "sha512-lCv9eK/H6ZJWbE7bh2nw54CZ9M2nupBxJcTsdk/QQnWkdSjKGuxmmH8/GWrlT1eMmZfn4dGcCjRte397WqfQXA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/win32-ia32": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/win32-ia32/-/win32-ia32-0.28.1.tgz", + "integrity": "sha512-zvb/mB2bSCoJOpoCBgYKKpX6YM6mJBlBUVUtVj41DlZJVEB6/0CKlRYxP5wWl1C1ILiCoAU5wZZ4q1P3qeS6Eg==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=18" + } + }, + "node_modules/@esbuild/win32-x64": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/@esbuild/win32-x64/-/win32-x64-0.28.1.tgz", + "integrity": "sha512-bm4Mowrv+GXMlpWX++EcXw/iLyd1o3+bJkC2DkWXYVvgZCqD/bSj9ctZeAMC3cIxgjRVR2Dufaiu4YPxr5gW1A==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=18" + } + }, "node_modules/@eslint-community/eslint-utils": { "version": "4.9.1", "resolved": "https://registry.npmjs.org/@eslint-community/eslint-utils/-/eslint-utils-4.9.1.tgz", @@ -2994,6 +3437,48 @@ "node": ">= 0.4" } }, + "node_modules/esbuild": { + "version": "0.28.1", + "resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.28.1.tgz", + "integrity": "sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw==", + "dev": true, + "hasInstallScript": true, + "license": "MIT", + "bin": { + "esbuild": "bin/esbuild" + }, + "engines": { + "node": ">=18" + }, + "optionalDependencies": { + "@esbuild/aix-ppc64": "0.28.1", + "@esbuild/android-arm": "0.28.1", + "@esbuild/android-arm64": "0.28.1", + "@esbuild/android-x64": "0.28.1", + "@esbuild/darwin-arm64": "0.28.1", + "@esbuild/darwin-x64": "0.28.1", + "@esbuild/freebsd-arm64": "0.28.1", + "@esbuild/freebsd-x64": "0.28.1", + "@esbuild/linux-arm": "0.28.1", + "@esbuild/linux-arm64": "0.28.1", + "@esbuild/linux-ia32": "0.28.1", + "@esbuild/linux-loong64": "0.28.1", + "@esbuild/linux-mips64el": "0.28.1", + "@esbuild/linux-ppc64": "0.28.1", + "@esbuild/linux-riscv64": "0.28.1", + "@esbuild/linux-s390x": "0.28.1", + "@esbuild/linux-x64": "0.28.1", + "@esbuild/netbsd-arm64": "0.28.1", + "@esbuild/netbsd-x64": "0.28.1", + "@esbuild/openbsd-arm64": "0.28.1", + "@esbuild/openbsd-x64": "0.28.1", + "@esbuild/openharmony-arm64": "0.28.1", + "@esbuild/sunos-x64": "0.28.1", + "@esbuild/win32-arm64": "0.28.1", + "@esbuild/win32-ia32": "0.28.1", + "@esbuild/win32-x64": "0.28.1" + } + }, "node_modules/escalade": { "version": "3.2.0", "resolved": "https://registry.npmjs.org/escalade/-/escalade-3.2.0.tgz", diff --git a/package.json b/package.json index 4a73b0e..1724afc 100755 --- a/package.json +++ b/package.json @@ -17,7 +17,7 @@ "onLanguage:yaml", "onLanguage:dockercompose" ], - "main": "./out/extension.js", + "main": "./dist/extension.js", "contributes": { "commands": [ { @@ -177,10 +177,14 @@ ] }, "scripts": { - "vscode:prepublish": "npm run compile", - "compile": "tsc -p ./", - "watch": "tsc -watch -p ./", - "pretest": "npm run compile && npm run lint", + "vscode:prepublish": "npm run package", + "compile": "npm run check-types && npm run lint && node esbuild.js", + "watch": "node esbuild.js --watch", + "package": "npm run check-types && npm run lint && node esbuild.js --production", + "check-types": "tsc --noEmit", + "compile-tests": "tsc -p ./ --outDir out", + "watch-tests": "tsc -p ./ -w --outDir out", + "pretest": "npm run compile-tests && npm run compile", "lint": "eslint src --ext ts", "test": "vscode-test" }, @@ -194,6 +198,7 @@ "@vscode/test-cli": "^0.0.8", "@vscode/test-electron": "^2.3.9", "@vscode/vsce": "^3.9.2", + "esbuild": "^0.28.1", "eslint": "^8.57.0", "ovsx": "^0.10.1", "sinon": "^18.0.0", diff --git a/src/fileScanners/test/highlighters.test.ts b/src/fileScanners/test/highlighters.test.ts index 59e0a44..87f3707 100644 --- a/src/fileScanners/test/highlighters.test.ts +++ b/src/fileScanners/test/highlighters.test.ts @@ -4,6 +4,7 @@ import { DockerfileParser, Instruction } from 'dockerfile-ast'; import { addDecorations, clearDecorations, grepString, highlightImage, highlightLayer, restoreDecorations, decorationsMap } from '../highlighters'; import * as highlighters from '../highlighters'; import * as dockerfile from '../Dockerfile/dockerfileScanner'; +import * as extension from '../../extension'; import assert from 'assert'; import sinon from 'sinon'; @@ -15,6 +16,9 @@ suite('Highlighters Tests', () => { setup(async () => { // Create a new text document and set it as the active editor sandbox = sinon.createSandbox(); + // highlightLayer calls vulnTreeDataProvider.updateVulnTree; provide a stub so these + // tests don't depend on extension.activate() having run in another test file first. + (extension as { vulnTreeDataProvider: unknown }).vulnTreeDataProvider = { updateVulnTree: sandbox.stub() }; document = await vscode.workspace.openTextDocument({language : 'dockerfile', content: 'FROM example-image\n\nRUN echo "example"' }); editor = await vscode.window.showTextDocument(document); }); From 6e0c8bcb131b9140d8951d69cf214f6ede06c2b6 Mon Sep 17 00:00:00 2001 From: Fede Barcelona Date: Fri, 3 Jul 2026 11:23:47 +0200 Subject: [PATCH 2/2] build: add justfile and run CI through the flake devShell Introduce a justfile as a thin facade over the package.json scripts plus the nix/OS-specific glue (watch, test, lint, vsix, publish-*, update). The test and release workflows now run inside `nix develop`, so just/node/vsce are pinned by the flake, and the VSIX is built and published with nix (verified byte-identical to `vsce package`, so publishing stays compatible). lint audits dependencies but fails only when a fix is actually available, so unfixable transitive dev vulns don't block commits. Fix .vscodeignore to exclude the lowercase `justfile`, the nix `result` symlink and `*.vsix`, which were leaking into the package. --- .github/workflows/release.yml | 37 +++++++----------- .github/workflows/test.yml | 31 ++++++--------- .vscodeignore | 4 +- Justfile | 32 --------------- flake.nix | 3 +- justfile | 73 +++++++++++++++++++++++++++++++++++ package.json | 2 +- 7 files changed, 106 insertions(+), 76 deletions(-) delete mode 100644 Justfile create mode 100644 justfile diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 702fb7a..d4ddfdd 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -10,7 +10,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: fetch-depth: 2 # We only need the current and the previous commit @@ -30,33 +30,30 @@ jobs: runs-on: ubuntu-latest needs: check-changes if: needs.check-changes.outputs.changes == 'detected' + defaults: + run: + shell: nix develop --command bash -e {0} steps: - name: Checkout code - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - - name: Set up Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 - with: - node-version: 22 - - - name: Install dependencies - run: |- - npm install - npm install -g vsce + - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22 + - uses: DeterminateSystems/magic-nix-cache-action@908b263ff629f4cc17666315b7fd3ec127c6244d # v14 # - name: Run tests - # run: npm test + # run: just test - name: Build VSIX file - run: vsce package -o sysdig-vscode-ext.vsix + run: just vsix - name: Get current version id: version - run: echo "version=$(jq -r '.version' package.json)" >> "$GITHUB_OUTPUT" + shell: bash + run: echo "version=$(jq --raw-output '.version' package.json)" >> "$GITHUB_OUTPUT" - name: Create release id: create_release - uses: actions/create-release@v1 + uses: actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e # v1.1.4 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: @@ -66,7 +63,7 @@ jobs: prerelease: false - name: Upload VSIX file - uses: actions/upload-release-asset@v1 + uses: actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: @@ -76,11 +73,7 @@ jobs: asset_content_type: application/vsix - name: Publish VSIX to the marketplace - env: - VSCE_PAT: ${{ secrets.AZURE_DEVOPS_PAT }} - run: | - vsce publish + run: just publish-vscode-marketplace ${{ secrets.AZURE_DEVOPS_PAT }} - name: Publish VSIX to Open VSX - run: | - npx ovsx publish ./sysdig-vscode-ext.vsix -p ${{ secrets.OVSX_PAT }} + run: just publish-openvsx-registry ${{ secrets.OVSX_PAT }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 94781e1..c8881aa 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -11,22 +11,15 @@ jobs: matrix: os: [macos-latest, ubuntu-latest] runs-on: ${{ matrix.os }} + defaults: + run: + shell: nix develop --command bash -e {0} steps: - name: Checkout - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - - name: Install Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 - with: - node-version: 18.x - - run: npm ci --include=dev - #- run: apt update && apt install -y libgtk2.0-0 libgtk-3-0 libgbm-dev libnotify-dev libnss3 libxss1 libasound2 libxtst6 xauth xvfb - # if: runner.os == 'Linux' - #- run: service dbus start - # if: runner.os == 'Linux' - - run: xvfb-run -a npm test - if: runner.os == 'Linux' - - run: npm test - if: runner.os != 'Linux' + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22 + - uses: DeterminateSystems/magic-nix-cache-action@908b263ff629f4cc17666315b7fd3ec127c6244d # v14 + - run: just test test-nix: strategy: @@ -34,8 +27,8 @@ jobs: os: [macos-latest, ubuntu-latest] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - - uses: DeterminateSystems/nix-installer-action@v1 - - uses: DeterminateSystems/magic-nix-cache-action@v1 - - uses: DeterminateSystems/flake-checker-action@v1 - - run: nix build -L + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22 + - uses: DeterminateSystems/magic-nix-cache-action@908b263ff629f4cc17666315b7fd3ec127c6244d # v14 + - uses: DeterminateSystems/flake-checker-action@3164002371bc90729c68af0e24d5aacf20d7c9f6 # v12 + - run: nix build --print-build-logs diff --git a/.vscodeignore b/.vscodeignore index 73b0134..47c4704 100755 --- a/.vscodeignore +++ b/.vscodeignore @@ -16,7 +16,9 @@ vsc-extension-quickstart.md .direnv/** .envrc .pre-commit-config.yaml -Justfile +justfile flake.nix flake.lock vsix.nix +result +*.vsix diff --git a/Justfile b/Justfile deleted file mode 100644 index 8fe9872..0000000 --- a/Justfile +++ /dev/null @@ -1,32 +0,0 @@ - -[private] -default: - @just -l - -[linux] -test: - xvfb-run -d npm test - -[macos] -test: - npm test - -lint: - npm run lint - npm audit - -update: - nix flake update - nix develop --command pre-commit autoupdate - nix develop --command npm update - nix develop --command just update-scanner-version - nix develop --command pinact run -u --diff - -update-scanner-version: - #!/usr/bin/env bash - set -euo pipefail - echo "Fetching latest sysdig-cli-scanner version…" - latest=$(curl -sfSL https://download.sysdig.com/scanning/sysdig-cli-scanner/latest_version.txt) - echo "Latest: $latest" - sd "(export const SCANNER_VERSION : string = ')[^']+(';)" "\${1}$latest\${2}" src/config/configScanner.ts - echo "Version updated" diff --git a/flake.nix b/flake.nix index bd50c3c..7281c67 100644 --- a/flake.nix +++ b/flake.nix @@ -69,9 +69,10 @@ mkShell { shellHook = '' npm ci - pre-commit install + prek install --overwrite ''; packages = [ + prek just nodejs pinact diff --git a/justfile b/justfile new file mode 100644 index 0000000..66fce78 --- /dev/null +++ b/justfile @@ -0,0 +1,73 @@ + +# Show available recipes +[private] +default: + @just --list + +# Run while debugging; wired as the preLaunchTask for F5 +watch: + npm run watch + +# Build an installable .vsix (VS Code: "Install from VSIX…") into the repo root +vsix: + nix build + install --mode=644 result sysdig-vscode-ext.vsix + rm result + +# Publish the built .vsix to the VS Code Marketplace +publish-vscode-marketplace token: vsix + vsce publish --packagePath sysdig-vscode-ext.vsix --pat {{token}} + +# Publish the built .vsix to the Open VSX registry +publish-openvsx-registry token: vsix + npx ovsx publish sysdig-vscode-ext.vsix --pat {{token}} + +# Clean up +clean: + rm -f sysdig-vscode-ext.vsix + rm -rf out + rm -rf dist + rm -rf node_modules + rm -rf .vscode-test + rm -f result + +# Run tests +[linux] +test: + xvfb-run --auto-display npm test + +# Run tests +[macos] +test: + npm test + +# All static code checks, without running tests +lint: + #!/usr/bin/env bash + set -o errexit -o nounset -o pipefail + npm run check-types + npm run lint + # Audit fails only when at least one vulnerability has a fix available + audit=$(npm audit --json) || true + if node -e 'const v=Object.values(JSON.parse(require("fs").readFileSync(0,"utf8")).vulnerabilities||{}); process.exit(v.some(x=>x.fixAvailable!==false)?0:1)' <<<"$audit"; then + npm audit + exit 1 + fi + +# Bump all pinned dependencies to their latest versions +update: + nix flake update + nix develop --command pre-commit autoupdate + nix develop --command npm update + nix develop --command just update-scanner-version + nix develop --command pinact run --update --diff + +# Bump the inner sysdig-cli-scanner to the latest version +update-scanner-version: + #!/usr/bin/env bash + set -o errexit -o nounset -o pipefail + echo "Fetching latest sysdig-cli-scanner version…" + latest=$(curl --silent --show-error --fail --location https://download.sysdig.com/scanning/sysdig-cli-scanner/latest_version.txt) + echo "Latest: $latest" + sd "(export const SCANNER_VERSION : string = ')[^']+(';)" "\${1}$latest\${2}" src/config/configScanner.ts + echo "Version updated" diff --git a/package.json b/package.json index 1724afc..fa23ff4 100755 --- a/package.json +++ b/package.json @@ -3,7 +3,7 @@ "publisher": "sysdig", "displayName": "Sysdig Scanner", "description": "Sysdig Scanner for Visual Studio Code", - "version": "0.2.16", + "version": "0.2.17", "icon": "img/logo.png", "repository": "https://github.com/sysdiglabs/vscode-extension", "engines": {