Files
OpenHands/scripts/vercel-install.sh
T
Robert Brennanandopenhands 8b7ed9de2f fix(vercel): force HTTPS for typescript-client git dep on Vercel (#391)
npm normalizes the `github:OpenHands/typescript-client#sha` shorthand
(and even an explicit `git+https://github.com/...` URL) to
`git+ssh://git@github.com/...` whenever it rewrites package-lock.json
during a plain `npm install`. Vercel's build environment has no GitHub
SSH key, so an ssh-pinned lockfile causes Vercel to fall back to a stale
cached copy of the package whose dist/clients.js predates the addition
of ConversationClient, FileClient, and SharedClient. Rolldown then
fails the build with:

  [MISSING_EXPORT] ConversationClient is not exported by
  node_modules/@openhands/typescript-client/dist/clients.js

PR #382 fixed this once by hand-editing the lockfile, but the very next
local `npm install` (e.g. PR #387 bumping React Query hooks) silently
rewrote the resolved URL back to ssh and the bug returned.

This change makes the Vercel build self-healing:

* package.json now pins the dep as an explicit `git+https://` URL so
  the intent is documented in one place.
* package-lock.json's top-level dep spec matches that URL; the nested
  `node_modules/@openhands/typescript-client` entry already resolved
  to https, so this brings both halves of the lockfile in sync.
* vercel.json sets `installCommand` to `bash scripts/vercel-install.sh`,
  which:
    - rewrites any leftover `git+ssh://git@github.com/` resolved URLs
      back to https (handles future regressions),
    - configures `git config --global url."https://github.com/".insteadOf`
      for both `ssh://git@github.com/` and `git@github.com:` (handles
      anything npm has already normalized in cache),
    - then runs `npm ci` for a strict, lockfile-driven install.

Locally verified:

* `bash scripts/vercel-install.sh` produces a clean install with the
  https-resolved typescript-client.
* `npm run build` and `npm run lint` both succeed after the install.
* Re-running `npm install` rewrites `resolved` back to `git+ssh` as
  expected — the install script normalizes it again on every Vercel
  build, so the lockfile drift no longer breaks deploys.

Refs: #384 (Vercel preview build fails: MISSING_EXPORT for SharedClient
/ ConversationClient / FileClient).

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-12 14:08:50 -07:00

34 lines
1.5 KiB
Bash
Executable File

#!/usr/bin/env bash
# Custom Vercel install command.
#
# npm normalizes any GitHub URL it finds in package.json (including
# `git+https://github.com/...` and the `github:owner/repo` shorthand) to
# `git+ssh://git@github.com/...` when it writes package-lock.json. Vercel's
# build environment has no SSH key for GitHub, so npm cannot clone the
# `@openhands/typescript-client` git dependency and silently falls back to a
# stale cached copy — producing the dreaded
# `[MISSING_EXPORT] ConversationClient is not exported by
# node_modules/@openhands/typescript-client/dist/clients.js` at bundle time.
#
# Two defensive measures here:
# 1. Rewrite any `git+ssh://git@github.com/` URLs in package-lock.json
# to `git+https://github.com/` before invoking npm so the lockfile
# Vercel actually consumes is HTTPS-only, regardless of which lockfile
# shape happened to be committed.
# 2. Configure git globally to translate the matching ssh forms into
# https — this catches anything npm has already cached as an ssh URL
# and any future git deps that hit the same bug.
#
# See https://github.com/OpenHands/agent-canvas/issues/384 for the original
# bug report.
set -euo pipefail
if [ -f package-lock.json ]; then
sed -i 's|git+ssh://git@github.com/|git+https://github.com/|g' package-lock.json
fi
git config --global url."https://github.com/".insteadOf "ssh://git@github.com/"
git config --global url."https://github.com/".insteadOf "git@github.com:"
npm ci