Skip to content

fix(pkg): drop the ./ prefix npm strips from bin paths anyway - #313

Merged
ralyodio merged 1 commit into
mainfrom
fix/bin-paths
Aug 6, 2026
Merged

fix(pkg): drop the ./ prefix npm strips from bin paths anyway#313
ralyodio merged 1 commit into
mainfrom
fix/bin-paths

Conversation

@ralyodio

@ralyodio ralyodio commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Every publish logged:

npm warn publish npm auto-corrected some errors in your package.json when publishing.
npm warn publish errors corrected:
npm warn publish "bin[moshcode]" script name bin/moshcode.mjs was invalid and removed
npm warn publish "bin[moshscript]" script name bin/moshscript.mjs was invalid and removed

"invalid and removed" reads as though the CLI shipped without its entry points. It didn't. npm rewrites ./bin/moshcode.mjs to bin/moshcode.mjs and publishes that — 0.24.0, 0.24.2 and 0.24.3 all have working bins, verified against the registry:

$ npm view moshcode@0.24.3 bin
{ "moshcode": "bin/moshcode.mjs", "moshscript": "bin/moshscript.mjs" }

So this changes nothing for anyone installing moshcode. It writes down what npm was already doing, and removes a warning that would cost the next person the same few minutes to dismiss.

npm pkg fix produces exactly this diff and nothing else — I let it make the change rather than guessing at the cause from the wording.

Verification

  • npm publish --dry-run is now warning-free
  • packed the tarball and installed it into a throwaway prefix: both moshcode and moshscript are created and execute (moshcode --version → 0.24.3)
  • resulting bin values are identical to what 0.24.3 already has on the registry, so the published manifest does not change
  • nothing reads package.json's bin field — the ../bin/moshcode.mjs references in src/ and test/ are relative-URL resolutions, unrelated
  • full suite: 1087 passed, 0 failed

No version bump

The published manifest would be byte-identical to 0.24.3's, so there is nothing to release. This rides with the next real release.

🤖 Generated with Claude Code

Every publish logged:

  npm warn publish npm auto-corrected some errors in your package.json
  npm warn publish "bin[moshcode]" script name bin/moshcode.mjs was invalid
                   and removed

which reads as though the CLI shipped without its entry points. It did not:
npm rewrites `./bin/moshcode.mjs` to `bin/moshcode.mjs` and publishes that, so
0.24.0, 0.24.2 and 0.24.3 all have working bins — checked against the registry.

So this changes nothing for anyone installing moshcode. It writes down what npm
was already doing, and removes a warning that would cost the next person the
same few minutes to dismiss. `npm pkg fix` produces exactly this diff and
nothing else.

No version bump: the published manifest is byte-identical to what 0.24.3
already has, so there is nothing to release. It rides with the next one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

92 finding(s)

HIGH/CRITICAL: 50 | MEDIUM: 42

Severity Rule Location
HIGH manifest-typosquat apps/pwa/package.json:19
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
HIGH secret-generic-credential apps/pwa/test/apikey-bearer-scheme.test.mjs:30
HIGH secret-generic-credential apps/pwa/test/apikey-mask.test.mjs:38
HIGH secret-generic-credential apps/pwa/test/apikey-reveal.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/approvals-context.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/approvals-credits.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/approvals-notify.test.mjs:26
HIGH secret-generic-credential apps/pwa/test/approvals-resolve-race.test.mjs:20
HIGH secret-generic-credential apps/pwa/test/auth-form-email.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/auth-form-email.test.mjs:33
HIGH secret-generic-credential apps/pwa/test/auth-page-error.test.mjs:36
HIGH secret-generic-credential apps/pwa/test/cli-device-token.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/cli-pages-balance.test.mjs:32
HIGH secret-generic-credential apps/pwa/test/cli-token.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/credits-pack.test.mjs:51
HIGH secret-generic-credential apps/pwa/test/credits-webhook-event-match.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/credits-webhook.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/csrf-input-escaping.test.mjs:31
HIGH secret-generic-credential apps/pwa/test/csrf-input-escaping.test.mjs:101
HIGH secret-generic-credential apps/pwa/test/logout-csrf.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/moshpit-api-key.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-bulk-claim.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-claim-full-name.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/moshpit-crawlable.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-ending-page.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-pins.test.mjs:22
HIGH secret-generic-credential apps/pwa/test/moshpit-pit-page.test.mjs:33
HIGH secret-generic-credential apps/pwa/test/moshpit-records-page.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-records.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-registry.test.mjs:20
HIGH secret-generic-credential apps/pwa/test/moshpit-related-endings.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-sales.test.mjs:16
HIGH secret-generic-credential apps/pwa/test/moshpit-search.test.mjs:74
HIGH secret-generic-credential apps/pwa/test/moshpit-terms.test.mjs:19
HIGH secret-generic-credential apps/pwa/test/moshpit-tlds-pagination.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/passkey-register-duplicate.test.mjs:38
HIGH secret-generic-credential apps/pwa/test/require-auth-next.test.mjs:31
HIGH secret-generic-credential apps/pwa/test/require-auth-next.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/sessions-output-seq.test.mjs:30
HIGH secret-generic-credential apps/pwa/test/sessions-paste.test.mjs:24
HIGH secret-generic-credential apps/pwa/test/sessions-stream-replay.test.mjs:34
HIGH secret-generic-credential apps/pwa/test/sessions.test.mjs:24
HIGH secret-generic-credential apps/pwa/test/signature.test.mjs:6
HIGH secret-generic-credential test/auth.test.mjs:13
HIGH secret-generic-credential test/auth.test.mjs:148
HIGH secret-generic-credential test/console-cookie-malformed.test.mjs:15
HIGH secret-generic-credential test/console.test.mjs:12
HIGH secret-generic-credential test/mirror.test.mjs:37
HIGH secret-generic-credential test/mirror.test.mjs:77

…and 42 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 5771217 into main Aug 6, 2026
4 checks passed
@ralyodio
ralyodio deleted the fix/bin-paths branch August 6, 2026 09:22
@ralyodio ralyodio mentioned this pull request Aug 6, 2026
ralyodio added a commit that referenced this pull request Aug 6, 2026
Bump to v0.25.0, releasing machine-readable account status via moshcode whoami --json (#302), plus the bin path cleanup (#313) and publish workflow changes (#311, #312).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant