Repository navigation
The host runs Composer 0.26.0: one config file, no prisma-composer binary (8.0.0-rc.20) - #330
Conversation
Composer 0.26.0 moves its configuration into the composer section of prisma.config.ts and drops the prisma-composer binary. Until it is on the registry, both manifests pin the preview of prisma/composer#331. The preview's composer-cli depends on @prisma/composer by URL, which pnpm refuses in subdependencies unless blockExoticSubdeps is off. Both go back to 0.26.0 before this merges. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 peers @prisma/cli-engine 0.6.2, the version the shell ships, so the tarball check no longer needs to excuse a mismatch. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
…es it A composer section that still names a config file is now refused by Composer's section validator before any handler runs: the result is CLI.CONFIG_SECTION_INVALID carrying CONFIG.FIELD_RETIRED, exit 2, on every platform, so the Windows variant of the test goes away. A second fixture builds a valid section with defineConfig from @prisma/composer/config and nodeBuild(), and shows dev accepting it and reaching its handler. Its state descriptor is written by hand: the Prisma Cloud control entry would bring the whole cloud target and the ORM toolchain into the host's dev dependencies. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
prisma init installs this skill into every new project, and it still said dev and deploy need a separate prisma-composer.config.ts. With Composer 0.26.0 that file is refused; the skill now shows the composer section and the three CONFIG codes the way Composer's own skill does. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
The configPath test now checks the headline summary, which names the section and the file, and the diagnostic's severity. The valid-section test checks that the handler's failure names the entry the host passed, so it shows the argv reached composer's dev rather than only that some composer code came back. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
A new project with no composer section gets CONFIG.SECTION_MISSING and has no old file to move, so the skill now says to write the section in that case and to move the old contents only for the other two codes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
Composer 0.26.0 is on latest, so both manifests pin it in place of the pkg.pr.new preview, and the workspace stops allowing URL dependencies below the top level, which only the preview needed. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
Merging publishes prisma@latest pinning Composer 0.26.0, whose configuration is the composer section of prisma.config.ts. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (13)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughPackage and workspace versions advance to 8.0.0-rc.20, and Composer CLI dependencies advance to 0.26.0. CLI tests and skill documentation describe a single Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to This change updates package versions and Composer configuration guidance and tests. No concrete merge-blocking issue was found, so it appears ready to merge after normal CI checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The configuration contract changes, but the host retains validation before command execution. No introduced security issue was established. Composer 0.26.0’s internal state-management and recovery behavior could not be independently verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
commit: |
Slice 3 of the one-config-file project (prisma/orm#30536). Composer 0.26.0 published the merged config (prisma/composer#328) and dropped the
prisma-composerbinary (prisma/composer#331); this PR makes the host carry it. Merging publishesprisma@8.0.0-rc.20.From a Composer project outside any workspace, with this branch's
prismaand Composer 0.26.0 from the registry:The decision
@prisma/cliandprismapin@prisma/composer-cliand@prisma/composerat 0.26.0 and the version advances to 8.0.0-rc.20, soprisma@latestruns Composer's family with thecomposersection ofprisma.config.tsas its configuration. The automatic pin-bump workflow did not fire (Composer's publish could not notify this repository), so this PR carries the bump.What the bump changes in the host
composer: { configPath }now proves the retirement:dev --configagainst it fails with the engine'sCLI.CONFIG_SECTION_INVALIDheadline and Composer'sCONFIG.FIELD_RETIREDdiagnostic, exit 2, on every platform, since validation now fails before the handler runs. A second fixture holds a valid section built withdefineConfig as composerfrom@prisma/composer/configand proves the handler runs against it.scripts/conformance.tsis removed, as its own note said this bump would do. The suite reports nothing.skills/prisma-platform-core-concepts/SKILL.mdno longer saysprisma-composer.config.tsis mandatory or thatdevfails withCONFIG.FILE_MISSING. It describes thecomposersection and the three retirement codes in the same terms as Composer's own skill, with the fix for each.composer-isolation.test.tspasses unchanged: mounting the 0.26.0 family still loads neither Alchemy noreffecton an unrelated command.Verification
test:scripts,check:skill-packaging,manifest-pins,composer-isolation, andcheck:conformancewith zero failing and zero allowed.--version,deploy --help,dev --helpexit 0 and list neitherdestroynorlog; the retired file givesCONFIG.FILE_RETIRED; the retired field givesCONFIG.FIELD_RETIRED; aneffectforced to 4.0.0-rc.118 givesCLI.CONFIG_UNREADABLEnaming the missing module while--versionstill exits 0.prisma devto ready still needsalchemyas a direct dependency in a plain pnpm project; that is a Composer defect fixed in prisma/composer#332, not a host matter, and will ship in Composer's next release.Not in this PR
destroyandlogremain operations on@prisma/composer/control; their command-line form is a separate grammar project.latest.Agent: columbo-17
🤖 Generated with Claude Code