mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-21 16:02:36 +00:00
DockerfileExtra copied multiplayer/package.json alone and ran `npm install`, so the image shipped whatever npm resolved at build time and the committed multiplayer/package-lock.json described nothing that ran in production: Dependabot alerts on it were meaningless either way. Copy the lockfile and install with `npm ci --omit=dev` so the image is reproducible and the lock is the source of truth for what ships. The lock is refreshed with `npm update <dep>` per direct dependency, which moves each to the newest version inside its existing caret range without touching package.json. That is exactly what a lockfile-less `npm install` resolves today (verified: a fresh `npm install --package-lock-only` from the same package.json produces identical versions), so the image does not regress: ws 8.19.0 -> 8.21.3 (covers the open alerts on ws < 8.21.0) y-websocket 3.0.0 -> 3.1.0 yjs 13.6.29 -> 13.6.32 lib0 0.2.117, y-protocols 1.0.7, isomorphic.js 0.2.5 unchanged package.json has no devDependencies and the lock has no `dev: true` entries, so `--omit=dev` changes nothing today and only guards against future ones. Validation: - `npm ci` on the pre-update lock and `npm ci --omit=dev` on the updated lock both succeed; `node --check server.mjs gateway.mjs` passes. - Smoke start: server.mjs listens on PORT=3999 and logs "Multiplayer server running"; gateway.mjs listens on PORT=3998 and logs its route table. - The same COPY/RUN lines built on node:22-slim with the repo root as build context (the context build-extra-image.yml uses) install the six locked packages and pass `node --check`. A full DockerfileExtra build was skipped: it is a single stage on an uncached multi-GB base image. Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
130 lines
3.8 KiB
JSON
130 lines
3.8 KiB
JSON
{
|
|
"name": "windmill-multiplayer",
|
|
"version": "1.0.0",
|
|
"lockfileVersion": 3,
|
|
"requires": true,
|
|
"packages": {
|
|
"": {
|
|
"name": "windmill-multiplayer",
|
|
"version": "1.0.0",
|
|
"dependencies": {
|
|
"lib0": "^0.2.117",
|
|
"ws": "^8.18.0",
|
|
"y-protocols": "^1.0.7",
|
|
"y-websocket": "^3.0.0",
|
|
"yjs": "^13.6.0"
|
|
}
|
|
},
|
|
"node_modules/isomorphic.js": {
|
|
"version": "0.2.5",
|
|
"resolved": "https://registry.npmjs.org/isomorphic.js/-/isomorphic.js-0.2.5.tgz",
|
|
"integrity": "sha512-PIeMbHqMt4DnUP3MA/Flc0HElYjMXArsw1qwJZcm9sqR8mq3l8NYizFMty0pWwE/tzIGH3EKK5+jes5mAr85yw==",
|
|
"license": "MIT",
|
|
"funding": {
|
|
"type": "GitHub Sponsors ❤",
|
|
"url": "https://github.com/sponsors/dmonad"
|
|
}
|
|
},
|
|
"node_modules/lib0": {
|
|
"version": "0.2.117",
|
|
"resolved": "https://registry.npmjs.org/lib0/-/lib0-0.2.117.tgz",
|
|
"integrity": "sha512-DeXj9X5xDCjgKLU/7RR+/HQEVzuuEUiwldwOGsHK/sfAfELGWEyTcf0x+uOvCvK3O2zPmZePXWL85vtia6GyZw==",
|
|
"license": "MIT",
|
|
"dependencies": {
|
|
"isomorphic.js": "^0.2.4"
|
|
},
|
|
"bin": {
|
|
"0ecdsa-generate-keypair": "bin/0ecdsa-generate-keypair.js",
|
|
"0gentesthtml": "bin/gentesthtml.js",
|
|
"0serve": "bin/0serve.js"
|
|
},
|
|
"engines": {
|
|
"node": ">=16"
|
|
},
|
|
"funding": {
|
|
"type": "GitHub Sponsors ❤",
|
|
"url": "https://github.com/sponsors/dmonad"
|
|
}
|
|
},
|
|
"node_modules/ws": {
|
|
"version": "8.21.3",
|
|
"resolved": "https://registry.npmjs.org/ws/-/ws-8.21.3.tgz",
|
|
"integrity": "sha512-201TZ/kPWxoPr/OKWjquZR1SWKXcvxdH+e1xrx89b3YbmzLMFCLfnaG1HFIgWzJOEWZ7MvpK++odZufgYR50Rw==",
|
|
"license": "MIT",
|
|
"engines": {
|
|
"node": ">=10.0.0"
|
|
},
|
|
"peerDependencies": {
|
|
"bufferutil": "^4.0.1",
|
|
"utf-8-validate": ">=5.0.2"
|
|
},
|
|
"peerDependenciesMeta": {
|
|
"bufferutil": {
|
|
"optional": true
|
|
},
|
|
"utf-8-validate": {
|
|
"optional": true
|
|
}
|
|
}
|
|
},
|
|
"node_modules/y-protocols": {
|
|
"version": "1.0.7",
|
|
"resolved": "https://registry.npmjs.org/y-protocols/-/y-protocols-1.0.7.tgz",
|
|
"integrity": "sha512-YSVsLoXxO67J6eE/nV4AtFtT3QEotZf5sK5BHxFBXso7VDUT3Tx07IfA6hsu5Q5OmBdMkQVmFZ9QOA7fikWvnw==",
|
|
"license": "MIT",
|
|
"dependencies": {
|
|
"lib0": "^0.2.85"
|
|
},
|
|
"engines": {
|
|
"node": ">=16.0.0",
|
|
"npm": ">=8.0.0"
|
|
},
|
|
"funding": {
|
|
"type": "GitHub Sponsors ❤",
|
|
"url": "https://github.com/sponsors/dmonad"
|
|
},
|
|
"peerDependencies": {
|
|
"yjs": "^13.0.0"
|
|
}
|
|
},
|
|
"node_modules/y-websocket": {
|
|
"version": "3.1.0",
|
|
"resolved": "https://registry.npmjs.org/y-websocket/-/y-websocket-3.1.0.tgz",
|
|
"integrity": "sha512-ZNzwH84Ysxv7zjpFNZHjTJvrBZgcAqMljTe+6zrWciAML9LQ18aVylyPNH9faxCXqEOV8I0JY4TGtrIHFX+Xwg==",
|
|
"license": "MIT",
|
|
"dependencies": {
|
|
"lib0": "^0.2.102",
|
|
"y-protocols": "^1.0.5"
|
|
},
|
|
"engines": {
|
|
"node": ">=16.0.0",
|
|
"npm": ">=8.0.0"
|
|
},
|
|
"funding": {
|
|
"type": "GitHub Sponsors ❤",
|
|
"url": "https://github.com/sponsors/dmonad"
|
|
},
|
|
"peerDependencies": {
|
|
"yjs": "^13.5.6"
|
|
}
|
|
},
|
|
"node_modules/yjs": {
|
|
"version": "13.6.32",
|
|
"resolved": "https://registry.npmjs.org/yjs/-/yjs-13.6.32.tgz",
|
|
"integrity": "sha512-lfiJIIC4Xayt5ItynE407ehlE03pCjeOc4hkR4yxxvvNJ4kuiN25B0g+Qp8XagYz361LLL7DCzR5bvFJ81QKtQ==",
|
|
"license": "MIT",
|
|
"dependencies": {
|
|
"lib0": "^0.2.99"
|
|
},
|
|
"engines": {
|
|
"node": ">=16.0.0",
|
|
"npm": ">=8.0.0"
|
|
},
|
|
"funding": {
|
|
"type": "GitHub Sponsors ❤",
|
|
"url": "https://github.com/sponsors/dmonad"
|
|
}
|
|
}
|
|
}
|
|
}
|