Skip to content

fix(deps): match tauri-plugin-updater to its npm package, and check it in CI - #747

Merged
EVWorth merged 1 commit into
mainfrom
claude/zen-babbage-6vq06i
Oct 5, 2026
Merged

EVWorth merged 1 commit into
mainfrom
claude/zen-babbage-6vq06i

Conversation

@EVWorth

@EVWorth EVWorth commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Main can't build a release right now. This PR fixes that and adds the CI check that would have caught it.

What broke

#740 moved @tauri-apps/plugin-updater to 2.12.0, but the tauri-plugin-updater crate stayed at 2.11.0. tauri build refuses to start when a Tauri npm package and its crate are on different major.minor releases. Reproduced on main:

Error Found version mismatched Tauri packages. Make sure the NPM package and Rust crate versions are on the same major/minor releases:
tauri-plugin-updater (v2.11.0) : @tauri-apps/plugin-updater (v2.12.0)

CI stayed green because no PR job runs tauri build; only release.yml does.

Fix

  • The tauri-plugin-updater crate goes from 2.11.0 to 2.12.0, published 2026-09-20, which passes the seven-day rule.
  • The lockfile moves only that one package; tauri stays at 2.11.5.
  • A plain cargo update --precise pulled in Tauri 2.12 and about 150 other packages, so I resolved this one with a temporary exact pin, then put the requirement back to "2.12.0" like the other plugin entries.

The CI check

scripts/check-tauri-versions.sh applies the Tauri CLI's rule without running a build:

  • @tauri-apps/api pairs with the tauri crate, and @tauri-apps/plugin-<x> pairs with tauri-plugin-<x>.
  • Versions come from package-lock.json and src-tauri/Cargo.lock, which are what the CLI compares.
  • Packages with no counterpart, such as @tauri-apps/cli, are skipped.
  • It fails, rather than passing, if it finds no pairs at all.

It runs in the Version Consistency job, whose filters already trigger on either lockfile, and in just lint. Its tests, scripts/test-check-tauri-versions.sh (8 cases), run in Lint (workflows) and just lint-workflows.

Verification

  • Against main's lockfiles, the script reports the updater pair and exits 1. With this change, all 4 pairs agree.
  • npx tauri build --debug --no-bundle gets past the mismatch check and runs the build. Before this change it stopped with the error above.
  • cargo clippy --all-targets --all-features -D warnings on the full workspace is clean, and cargo test -p sqlpilot --lib passes 61/61 with updater 2.12.
  • Test script 8/8. actionlint (with shellcheck), shellcheck -S info on both scripts, dprint check and check-documented-commands.sh are clean.

Follow-up

The open npm group update, #745, would bump @tauri-apps/api to 2.12, plugin-process and plugin-shell to 2.4, and plugin-updater to 2.13, with no crate bumps to match. With this check in place, #745 will now fail CI until the matching crates are bumped.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg


Generated by Claude Code

…t in CI

#740 moved @tauri-apps/plugin-updater to 2.12.0 while the
tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to
start when a Tauri npm package and its crate disagree on major.minor
("Found version mismatched Tauri packages"), so main could not build a
release. Nothing on a PR runs `tauri build`; only the release workflow
does, so CI stayed green.

Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day
rule). The lockfile moves that one package and nothing else; tauri
stays at 2.11.5.

scripts/check-tauri-versions.sh applies the CLI's rule without a build:
@tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with
tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It
runs in the Version Consistency job, which already triggers on either
lockfile, and in `just lint`. Against main's lockfiles it reports the
updater pair; with this change all four pairs agree.
scripts/test-check-tauri-versions.sh covers matching pairs, a plugin
a minor ahead, api-vs-tauri, patch-only differences, packages with no
crate, crate-name prefixes, nested npm copies, and no pairs at all.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
@EVWorth
EVWorth merged commit 766f516 into main Oct 5, 2026
12 checks passed
@EVWorth
EVWorth deleted the claude/zen-babbage-6vq06i branch October 5, 2026 03:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants