Skip to content

v0.10.0 — Six ecosystem verifiers behind one word

Choose a tag to compare

@phantomghost2023 phantomghost2023 released this 22 Sep 04:13

Six ecosystems, one question

verify: { builtin: … } grows from npm-only to npm, pnpm, venv, gems, gomod, crates — plus auto, which picks from the setup's own evidence (or the one lockfile present) and says which it picked. Every builtin compares an installed tree against its own lockfile by reading directory listings, not by running the package manager's check.

builtin compares answers in
npm package-lock / npm-shrinkwrap (v1 + v3) vs node_modules ~64 ms on 403 packages
pnpm resolved set + pnpm's lockfile copy vs node_modules/.pnpm ms
venv requirements/poetry/Pipfile/uv vs dist-info dirs (both Windows and POSIX layouts) ms
gems Gemfile.lock specs vs vendor/bundle (BUNDLE_PATH honoured) ms
gomod go.mod vs $GOMODCACHE (Go's !-escaped layout) or vendor/modules.txt ms
crates Cargo.lock vs $CARGO_HOME/registry, vendor/ ms

The rule the real repos forced on us

"No" is only said when the declared command can repair it — measured, not assumed: npm ci, pip install -r, bundle install and go mod download all restore damaged trees. pnpm 11 does not (a satisfied install leaves a deleted node_modules/.pnpm/<pkg> and a hand-modified .pnpm/lock.yaml alone, even with --force), and Cargo.lock covers dev-deps a plain build never fetches. There the builtin reports instead of judging, because a verdict it can never change is a rebuild loop forever:

⚙ setup: pnpm install --frozen-lockfile — reused, not re-confirmed: 1/2 package(s) the lockfile
  lists are not in node_modules/.pnpm, e.g. is-number@6.0.0 — not a verdict: a satisfied
  `pnpm install` re-imports only when the lockfile itself changes

Also fixed: a lockfileVersion: 1 npm lock used to declare nothing — which read as a yes for an empty tree — and init's virtualenv command was POSIX-only, so the first verify on Windows wrote a prerequisite that could not run.

Proven against real trees on one machine: npm 11, pnpm 11, a python -m venv, bundler 2.6.9, go 1.25, cargo 1.90 — each installed, damaged, and re-verified.

Full details: CHANGELOG · field notes