mirror of
https://github.com/stablyai/orca.git
synced 2026-10-06 08:02:28 +00:00
* chore(deps): update reviewed desktop dependencies and tooling * chore(deps): update compatible mobile packages and Fastlane * chore(deps): update cloud transports and enforce release age * chore(deps): patch documentation dependencies and record review * chore: remove dependency review reports * test(linear): smoke-load resolved SDK through CommonJS loader * fix(deps): keep native rebuilds from reinstalling addon dependencies * fix(native): invoke installed node-gyp directly for Node rebuilds * test(cloud): exclude observer probes from row-lock timing budget * test(mobile): preserve the CSS writer receiver in viewport spy * test(native): remove obsolete batch-shim fixture exception * Stream native rebuild output through the process wrapper
50 lines
1.7 KiB
JavaScript
50 lines
1.7 KiB
JavaScript
import { spawnSync } from 'node:child_process'
|
|
import process from 'node:process'
|
|
import { resolvePullRequestDiffBase } from './git-pull-request-diff-base.mjs'
|
|
import { resolvePnpmCliInvocation } from './pnpm-cli-invocation.mjs'
|
|
|
|
const requestedBase =
|
|
process.argv.slice(2).find((argument) => argument !== '--') ??
|
|
process.env.ORCA_CODE_QUALITY_BASE ??
|
|
'origin/main'
|
|
const base = resolvePullRequestDiffBase(process.cwd(), requestedBase)
|
|
// Why validate rather than trust: `base` arrives from argv or the environment and
|
|
// below it can reach cmd.exe unquoted, because resolvePnpmCliInvocation still
|
|
// falls back to a shell when it cannot find a directly spawnable pnpm. It accepts
|
|
// SHAs, tags, ref paths and the ^ ~ .. suffixes -- not reflog syntax like HEAD@{1},
|
|
// because braces stay out of anything bound for cmd.exe. The error names the base.
|
|
const GIT_REVISION = /^[A-Za-z0-9._/@^~-]+$/
|
|
if (!GIT_REVISION.test(base)) {
|
|
throw new Error(`Refusing to pass an unsafe diff base to pnpm: ${base}`)
|
|
}
|
|
// Why the shim and not a direct binary: `dlx` fetches react-doctor on demand, so
|
|
// only the pnpm CLI can run it. resolvePnpmCliInvocation prefers whatever
|
|
// npm_execpath exposes -- pnpm 12's own pnpm.exe, spawned with no shell.
|
|
const { command, prefixArgs, shell } = resolvePnpmCliInvocation()
|
|
const result = spawnSync(
|
|
command,
|
|
[
|
|
...prefixArgs,
|
|
'dlx',
|
|
'react-doctor@0.9.14',
|
|
'.',
|
|
'--yes',
|
|
'--scope',
|
|
'lines',
|
|
'--base',
|
|
base,
|
|
'--include-untracked',
|
|
'--no-dead-code',
|
|
'--no-supply-chain',
|
|
'--no-telemetry',
|
|
'--blocking',
|
|
'error'
|
|
],
|
|
{ stdio: 'inherit', shell, windowsHide: true }
|
|
)
|
|
|
|
if (result.error) {
|
|
throw result.error
|
|
}
|
|
process.exit(result.status ?? 1)
|