feat(cli): add prisma contract print, so development builds publish again - #316
wmadden-electric wants to merge 1 commit into
Conversation
…0.0-rc.13 The ORM command family gained contract print in prisma/orm#30315. Development builds of the family carried it before any release did, so the dev publish failed the mount coverage check. This moves the pin to the release that has the command and mounts it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: willbot <w.a.madden+machine@gmail.com> Signed-off-by: Will Madden <madden@prisma.io>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The CLI now mounts the configured-contract printer from the aligned rc.13 dependency. No concrete merge-blocking risk remains. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new command uses the existing CLI command framework, and the inspected implementation includes checks against overwriting contract inputs and uses an atomic file replacement. No security bypass was established. Risk remains because the command adds a file-writing path and the dependency upgrade was not fully compared with the prior version. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
commit: |
At a glance
Every push to
mainpublishes a development build of the CLI. The last one failed (run 36391300856) in the step "Check the dev version":With this change that check passes, and the command is part of the CLI:
The decision
The CLI now depends on
@prisma/orm-toolchain8.0.0-rc.13and mounts its new command atprisma contract print.Why publishing failed
The
prismaCLI does not define the ORM commands itself. They come from the package@prisma/orm-toolchain, which exports them as a list called a command family.packages/cli/src/cli.tsnames each command in that list and the path it is mounted at. A test,packages/cli/tests/mount-coverage.test.ts, fails when the family has a command that the CLI does not mount, so that a command cannot go missing without anyone noticing.The CLI is built on two channels. A release uses the released ORM version that is committed in the manifests. A development build replaces that version with the newest development build of the ORM, only for that run.
prisma/orm#30315 added the command
contract printto the ORM on 2026-09-27. It writes the contract thatprisma.config.tsloads as Prisma 8 PSL (Prisma Schema Language), to a file with--outputor to standard output. The ORM's development builds had the command from that day. Its newest release,8.0.0-rc.12, did not. So the development build of the CLI met a family command it did not mount, and the check stopped the publish. The release channel was not affected.The CLI could not mount the command while it depended on
8.0.0-rc.12: the command was absent there, andprisma contract --helpcrashed on the missing entry. The ORM has now released8.0.0-rc.13, which has the command.What changes
packages/cli/package.json,packages/prisma/package.json, andpnpm-lock.yamlmove@prisma/orm-toolchainfrom8.0.0-rc.12to8.0.0-rc.13, written byscripts/update-product-versions.mjs --channel release. The automatic version update workflow had not yet opened a pull request for this version.packages/cli/src/cli.tsmountscontract printand names it in thecontractgroup's help text.packages/cli/tests/mount-coverage.test.tslists the new path.packages/cli/tests/e2e-coverage.test.tsrecords the command with the same reason as every other ORM command: it does not call the management API, and its end-to-end tests live in the ORM repository.packages/cli/tests/orm-mount.test.tschecks thatprisma contract print --helprenders through the CLI.contract printis the only difference between the command lists of8.0.0-rc.12and8.0.0-rc.13. No command was renamed or removed, and no other test needed a change.What was checked
On the release channel, with the committed versions:
pnpm build,pnpm typecheck,pnpm lint,pnpm test --concurrency=1(engine 962 passed, CLI 1022 passed and 2 skipped,prisma3 passed),pnpm test:scripts,pnpm check:grammar(11 passed),pnpm check:error-reference(all 130 codes listed),pnpm check:skill-packaging, andpnpm check:conformance. All passed.On the development channel, following the steps in
.github/workflows/publish.yml: stamp a development version, runscripts/update-product-versions.mjs --channel dev(which selected@prisma/orm-toolchain8.0.0-rc.13-dev.1), refresh the lockfile,pnpm build, then withPUBLISH_CHANNEL=dev:pnpm check:grammar(11 passed),pnpm test:scripts, andpnpm check:conformance("5 subject(s) checked, nothing to report"). All passed. Before this change the same steps reproduced the failure above.What this does not do
packages/cli-engine.8.0.0-rc.13declares the same engine version, 0.6.1, as the CLI uses.End-to-end (real API)failure on the same commit (run 36391300855). That run failed because the management API answeredInternal Server Errortoservice version start.Alternatives considered
🤖 Generated with Claude Code