0.2.0 (2026-09-30)
⚠ BREAKING CHANGES
-
the ./build-info subpath and readBuildInfo() are
removed; import BUILD_INFO from the package entry instead. -
feat!: lint in a host-supplied worker through an injected file system
The extension is moving to lint documents of any URI scheme by reading
them through vscode.workspace.fs, and later to run on the web, so the
package can no longer reach for node:fs or hand back a synchronous
runner that blocks the caller.
createShellCheck({ module, createWorker }) now owns one Worker at a
time and runs lints through it in FIFO order. Each lint may carry a
ShellCheckFileSystem (async stat, readFile, readDirectory) that is
mounted read-only at guest /. The guest's synchronous WASI calls reach
it through a SharedArrayBuffer bridge: the Worker posts a request and
waits in Atomics.wait while the caller's thread runs the async call,
with payloads over 1 MiB sent in chunks and answers cached for the rest
of the lint. .. is folded lexically and may not leave /; symlink
containment is now the file system's job. An AbortSignal drops a queued
lint or terminates the Worker of the running one; a lost Worker is
replaced on the next lint. The Worker side ships as ./worker
(startWorker), and no shipped module imports a Node built-in.
-
the
./nodeentry (loadModule, createReadOnlyPreopen,
wasmPath) and the synchronous run() export are removed. Use
createShellCheck() with a Worker whose entry calls startWorker(), and
pass the files ShellCheck may read as LintRequest.fs. LintResult carries
stdout and stderr as strings. -
test: benchmark lint latency against 0.1.1 and native ShellCheck
The bridge adds a round trip to the caller's thread for every file
ShellCheck touches, so the redesign has to show it costs no more than
10% over the 0.1.1 node:fs runner. npm run bench installs 0.1.1 into
.cache/bench, runs both in worker_threads Workers on generated 23, 307
and 1503-line scripts with a .shellcheckrc and a sourced file, and
reports native ShellCheck and a +RTS -A64m run as data points.
- ci(release): publish prereleases under the next dist-tag
A version with a prerelease suffix (0.2.0-next.0) would otherwise become
latest on npm and a regular GitHub Release. Publish it with
--tag next and mark its GitHub Release as a prerelease; stable
versions publish as before.
- docs: document the worker API and record the file-system decision
Rewrite the README around createShellCheck, the Worker entry and the
ShellCheckFileSystem contract, including the web requirement of
cross-origin isolation for SharedArrayBuffer. Add ADR 0006 (the package
is file-system agnostic), amend ADR 0005 now that the Worker and bridge
live in the package while policy stays in the host, and note in ADR
0003 that the evidence against a reactor build measured a third-party
build rather than the reactor model.
- chore: release 0.2.0-next.0
- the ./build-info.json subpath export is removed; use
readBuildInfo() from ./build-info or ./node instead.
Features
- add an mit client entry and a prebuilt browser worker (#23) (4361f7d)
- expose build info through readBuildInfo() (#18) (72391de)
- lint through an injected file system in a host-supplied worker (#21) (30d7241)