Repository navigation
Conversation
✅ Deploy Preview for viteplus-preview canceled.
|
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f8c77a4a09
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
e27a3c5 to
b3ef6bd
Compare
7df44ae to
4e2cfc0
Compare
4e2cfc0 to
1e3becc
Compare
fengmk2
left a comment
There was a problem hiding this comment.
Please address the credential-key expansion gap and the cache upgrade regression described in the inline comments.
Expand npm credential keys before normalization, isolate the latest-version cache from legacy files, redact optional Vitest transform hints, and forward workspace cwd through the package-manager NAPI download entrypoint. Add regression coverage for each path.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 34d57c4a2b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
liangmiQwQ
left a comment
There was a problem hiding this comment.
Direction and division of responsibilities LGTM 💯
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7c035baad8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| // A default global npmrc cannot be located reliably before npm exists. | ||
| // Honor an explicitly configured one, then layer user and project config. | ||
| if let Some(path) = env_value("globalconfig") { |
There was a problem hiding this comment.
Load globalconfig selected by the user npmrc
When $HOME/.npmrc contains globalconfig=/corp/npmrc, this lookup checks only the environment before the user file is parsed, and the later globalconfig value is never consumed as a path. The upstream npm configuration loader explicitly states that globalconfig set by the userconfig file is used to load global configs; as written, registry credentials kept in that corporate config are skipped, so a workspace pointing at the private registry receives a 401 (or falls back to the public registry). Resolve the global config path after reading the user layer while preserving global config's lower value precedence.
Useful? React with 👍 / 👎.
Vite+ previously ignored
.npmrccredentials when bootstrapping a package manager, causing downloads from authenticated private registries to fail with401.Load registry settings and scoped credentials from explicit global config, user config, workspace config, and
npm_config_*environment variables, in that precedence order. Support bearer and Basic authentication, npm-style variable expansion, and common.npmrcencoding and quoting conventions.Match credentials to the request host, port, and path, and recheck them on redirects. Keep authenticated metadata out of the shared latest-version cache.
Closes #2603