fix(deps): match tauri-plugin-updater to its npm package, and check it in CI - #747
Merged
Merged
Conversation
…t in CI #740 moved @tauri-apps/plugin-updater to 2.12.0 while the tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to start when a Tauri npm package and its crate disagree on major.minor ("Found version mismatched Tauri packages"), so main could not build a release. Nothing on a PR runs `tauri build`; only the release workflow does, so CI stayed green. Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day rule). The lockfile moves that one package and nothing else; tauri stays at 2.11.5. scripts/check-tauri-versions.sh applies the CLI's rule without a build: @tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It runs in the Version Consistency job, which already triggers on either lockfile, and in `just lint`. Against main's lockfiles it reports the updater pair; with this change all four pairs agree. scripts/test-check-tauri-versions.sh covers matching pairs, a plugin a minor ahead, api-vs-tauri, patch-only differences, packages with no crate, crate-name prefixes, nested npm copies, and no pairs at all. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Main can't build a release right now. This PR fixes that and adds the CI check that would have caught it.
What broke
#740 moved
@tauri-apps/plugin-updaterto 2.12.0, but thetauri-plugin-updatercrate stayed at 2.11.0.tauri buildrefuses to start when a Tauri npm package and its crate are on different major.minor releases. Reproduced on main:CI stayed green because no PR job runs
tauri build; onlyrelease.ymldoes.Fix
tauri-plugin-updatercrate goes from 2.11.0 to 2.12.0, published 2026-09-20, which passes the seven-day rule.tauristays at 2.11.5.cargo update --precisepulled in Tauri 2.12 and about 150 other packages, so I resolved this one with a temporary exact pin, then put the requirement back to"2.12.0"like the other plugin entries.The CI check
scripts/check-tauri-versions.shapplies the Tauri CLI's rule without running a build:@tauri-apps/apipairs with thetauricrate, and@tauri-apps/plugin-<x>pairs withtauri-plugin-<x>.package-lock.jsonandsrc-tauri/Cargo.lock, which are what the CLI compares.@tauri-apps/cli, are skipped.It runs in the Version Consistency job, whose filters already trigger on either lockfile, and in
just lint. Its tests,scripts/test-check-tauri-versions.sh(8 cases), run in Lint (workflows) andjust lint-workflows.Verification
npx tauri build --debug --no-bundlegets past the mismatch check and runs the build. Before this change it stopped with the error above.cargo clippy --all-targets --all-features -D warningson the full workspace is clean, andcargo test -p sqlpilot --libpasses 61/61 with updater 2.12.actionlint(with shellcheck),shellcheck -S infoon both scripts,dprint checkandcheck-documented-commands.share clean.Follow-up
The open npm group update, #745, would bump
@tauri-apps/apito 2.12,plugin-processandplugin-shellto 2.4, andplugin-updaterto 2.13, with no crate bumps to match. With this check in place, #745 will now fail CI until the matching crates are bumped.🤖 Generated with Claude Code
https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
Generated by Claude Code