Skip to content

feat(cli): add prisma contract print, so development builds publish again - #316

Open
wmadden-electric wants to merge 1 commit into
mainfrom
claude/mount-contract-print
Open

wmadden-electric wants to merge 1 commit into
mainfrom
claude/mount-contract-print

Conversation

@wmadden-electric

Copy link
Copy Markdown
Contributor

At a glance

Every push to main publishes a development build of the CLI. The last one failed (run 36391300856) in the step "Check the dev version":

FAIL tests/mount-coverage.test.ts > prisma mount coverage > mounts every command in the orm family
AssertionError: expected [ 'contract print' ] to deeply equal []

With this change that check passes, and the command is part of the CLI:

prisma contract → Author your data contract: the PSL source of your data model. Emit, infer, format, print

│  emit    Emit your contract artifacts
│  infer   Infer a PSL contract from the live database schema
│  format  Format your PSL contract source
│  print   Print the configured contract as Prisma 8 PSL

The decision

The CLI now depends on @prisma/orm-toolchain 8.0.0-rc.13 and mounts its new command at prisma contract print.

Why publishing failed

The prisma CLI does not define the ORM commands itself. They come from the package @prisma/orm-toolchain, which exports them as a list called a command family. packages/cli/src/cli.ts names each command in that list and the path it is mounted at. A test, packages/cli/tests/mount-coverage.test.ts, fails when the family has a command that the CLI does not mount, so that a command cannot go missing without anyone noticing.

The CLI is built on two channels. A release uses the released ORM version that is committed in the manifests. A development build replaces that version with the newest development build of the ORM, only for that run.

prisma/orm#30315 added the command contract print to the ORM on 2026-09-27. It writes the contract that prisma.config.ts loads as Prisma 8 PSL (Prisma Schema Language), to a file with --output or to standard output. The ORM's development builds had the command from that day. Its newest release, 8.0.0-rc.12, did not. So the development build of the CLI met a family command it did not mount, and the check stopped the publish. The release channel was not affected.

The CLI could not mount the command while it depended on 8.0.0-rc.12: the command was absent there, and prisma contract --help crashed on the missing entry. The ORM has now released 8.0.0-rc.13, which has the command.

What changes

  • packages/cli/package.json, packages/prisma/package.json, and pnpm-lock.yaml move @prisma/orm-toolchain from 8.0.0-rc.12 to 8.0.0-rc.13, written by scripts/update-product-versions.mjs --channel release. The automatic version update workflow had not yet opened a pull request for this version.
  • packages/cli/src/cli.ts mounts contract print and names it in the contract group's help text.
  • packages/cli/tests/mount-coverage.test.ts lists the new path.
  • packages/cli/tests/e2e-coverage.test.ts records the command with the same reason as every other ORM command: it does not call the management API, and its end-to-end tests live in the ORM repository.
  • packages/cli/tests/orm-mount.test.ts checks that prisma contract print --help renders through the CLI.

contract print is the only difference between the command lists of 8.0.0-rc.12 and 8.0.0-rc.13. No command was renamed or removed, and no other test needed a change.

What was checked

On the release channel, with the committed versions: pnpm build, pnpm typecheck, pnpm lint, pnpm test --concurrency=1 (engine 962 passed, CLI 1022 passed and 2 skipped, prisma 3 passed), pnpm test:scripts, pnpm check:grammar (11 passed), pnpm check:error-reference (all 130 codes listed), pnpm check:skill-packaging, and pnpm check:conformance. All passed.

On the development channel, following the steps in .github/workflows/publish.yml: stamp a development version, run scripts/update-product-versions.mjs --channel dev (which selected @prisma/orm-toolchain 8.0.0-rc.13-dev.1), refresh the lockfile, pnpm build, then with PUBLISH_CHANNEL=dev: pnpm check:grammar (11 passed), pnpm test:scripts, and pnpm check:conformance ("5 subject(s) checked, nothing to report"). All passed. Before this change the same steps reproduced the failure above.

What this does not do

  • It does not change packages/cli-engine. 8.0.0-rc.13 declares the same engine version, 0.6.1, as the CLI uses.
  • It does not fix the End-to-end (real API) failure on the same commit (run 36391300855). That run failed because the management API answered Internal Server Error to service version start.
  • The next command the ORM adds will stop development builds in the same way until the ORM releases it and the CLI mounts it.

Alternatives considered

  • A rule for commands that exist only in development builds, such as mounting a command only when the installed family has it. This would keep development builds publishing between ORM releases. It was not chosen because the mount coverage test would need a different expected list for each channel, which weakens the check that exists to catch a missing command.

🤖 Generated with Claude Code

…0.0-rc.13

The ORM command family gained contract print in prisma/orm#30315. Development builds of the family carried it before any release did, so the dev publish failed the mount coverage check. This moves the pin to the release that has the command and mounts it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: willbot <w.a.madden+machine@gmail.com>
Signed-off-by: Will Madden <madden@prisma.io>
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 7971cbf4-f852-4aa8-b372-88f236af3571

📥 Commits

Reviewing files that changed from the base of the PR and between ef3695d and 9ccd938.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (6)
  • packages/cli/package.json
  • packages/cli/src/cli.ts
  • packages/cli/tests/e2e-coverage.test.ts
  • packages/cli/tests/mount-coverage.test.ts
  • packages/cli/tests/orm-mount.test.ts
  • packages/prisma/package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • New Features
    • Added the contract print command to the ORM CLI. It prints the contract loaded as PSL and is now listed alongside the other contract commands.
  • Documentation
    • Updated CLI help to show the mounted contract print spelling and exclude retired ORM spellings. The contract command overview now describes the output produced by print.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 9ccd9

The CLI now mounts the configured-contract printer from the aligned rc.13 dependency. No concrete merge-blocking risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 9ccd9

The new command uses the existing CLI command framework, and the inspected implementation includes checks against overwriting contract inputs and uses an atomic file replacement. No security bypass was established. Risk remains because the command adds a file-writing path and the dependency upgrade was not fully compared with the prior version.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly observed new sink is the invoking process’s standard output or a file path selected with --output, under that process’s filesystem permissions. The mount itself adds no direct platform API or credential operation.

Trust Boundaries and Controls

  • observed — The handler declares an ORM configuration need and rejects a missing contract source. Its output-path checks account for identified source inputs and generated artifacts, but they do not constitute a general filesystem sandbox.

Resilience and Maintainability Implications

  • observed — Temporary-file publication protects the previous destination from a partial write before rename and includes temporary-file cleanup. The inspected code does not establish serialization of concurrent invocations targeting the same file.

Hardening Proposals

  • proposed — If automation can supply untrusted output paths, constrain the destination to an intended workspace and run the CLI with only the filesystem permissions that job needs.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the CLI change and the addition of prisma contract print. It also states the development-build publishing outcome.
Description check ✅ Passed The description directly explains the development-build failure, the ORM toolchain upgrade, the CLI mount, the test changes, and the validation performed.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 4…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Sep 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

npx https://pkg.pr.new/@prisma/cli@316
npx https://pkg.pr.new/@prisma/cli-engine@316

commit: 9ccd938

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant