Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion ansible/roles/developer-typescript/meta/main.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
# Developer-TypeScript depends on developer-node — Node.js + npm/pnpm are
# prerequisites for installing typescript/tsx/ts-node.
# prerequisites for installing typescript/tsx.

dependencies:
- role: developer-node
2 changes: 1 addition & 1 deletion ansible/roles/developer-typescript/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
# the dependency so `--tags developer-typescript` automatically pulls in
# developer-node first.

- name: Install TypeScript and tsx/ts-node
- name: Install TypeScript and tsx
ansible.builtin.include_tasks:
file: typescript.yml
apply:
Expand Down
6 changes: 3 additions & 3 deletions ansible/roles/developer-typescript/tasks/typescript.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
---
# TypeScript toolchain — installs typescript + tsx + ts-node globally via pnpm.
# TypeScript toolchain — installs typescript + tsx globally via pnpm.
# Node.js and pnpm come from the core `developer` role now; developer-node is
# still the declared dependency (meta/main.yml) and pulls that role in.

- name: Install TypeScript and runners (typescript, tsx, ts-node)
- name: Install TypeScript and the tsx runner
ansible.builtin.command:
cmd: pnpm install -g typescript tsx ts-node
cmd: pnpm install -g typescript tsx
# Same prerequisite as developer-node: pnpm will not do a global install
# unless PNPM_HOME is set and its bin directory is on PATH. pnpm_env comes
# from the core role, which installs pnpm in the first place.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -404,7 +404,7 @@ fi

# --- npm and pnpm global tools ---------------------------------------------
# semantic-release, maid and wrangler are npm globals. eslint, prettier,
# typescript, tsx and ts-node are pnpm globals, which `npm update -g` never
# typescript and tsx are pnpm globals, which `npm update -g` never
# sees. pnpm itself is corepack's, so it is re-activated at latest first.
section "npm global tools"
if have npm; then
Expand Down
4 changes: 2 additions & 2 deletions ansible/roles/developer/files/update/hyperi-update-macos.sh
Original file line number Diff line number Diff line change
Expand Up @@ -299,8 +299,8 @@ else
fi

# --- npm and pnpm global tools ---------------------------------------------
# semantic-release and maid are npm globals. eslint, prettier, typescript, tsx
# and ts-node are pnpm globals, which `npm update -g` never sees. pnpm itself is
# semantic-release and maid are npm globals. eslint, prettier, typescript and
# tsx are pnpm globals, which `npm update -g` never sees. pnpm itself is
# corepack's, so it is re-activated at latest first.
section "npm global tools"
if have npm; then
Expand Down
29 changes: 29 additions & 0 deletions ansible/roles/developer/tasks/removals.yml
Original file line number Diff line number Diff line change
Expand Up @@ -705,6 +705,35 @@
when: ansible_facts['distribution'] == 'Ubuntu'
failed_when: false

# ts-node crashes on TypeScript 7, which removed the compiler API it calls, and
# has had no release since 2023-12. tsx runs the same files.
- name: Check for pnpm before removing a pnpm global (Linux)
ansible.builtin.command:
cmd: pnpm --version
environment: "{{ pnpm_env }}"
become: true
become_user: "{{ actual_user }}"
register: developer_rm_pnpm_present
changed_when: false
failed_when: false
check_mode: false
when: ansible_facts['distribution'] in ['Fedora', 'Ubuntu']

- name: Remove the retired ts-node pnpm global (Linux)
ansible.builtin.command:
cmd: pnpm remove -g ts-node
environment: "{{ pnpm_env }}"
become: true
become_user: "{{ actual_user }}"
register: developer_rm_ts_node
changed_when: developer_rm_ts_node.rc == 0
failed_when:
- developer_rm_ts_node.rc != 0
- "'GLOBAL_PKG_NOT_FOUND' not in (developer_rm_ts_node.stdout ~ developer_rm_ts_node.stderr)"
when:
- ansible_facts['distribution'] in ['Fedora', 'Ubuntu']
- developer_rm_pnpm_present.rc | default(1) == 0

# macOS is deliberately absent. These came from brew, and `brew uninstall` on a
# Mac hits tools the developer may well have installed themselves for their own
# reasons -- on a personal machine, undeclared state is theirs, not ours. The
Expand Down
4 changes: 2 additions & 2 deletions docs/install-matrix.md
Original file line number Diff line number Diff line change
Expand Up @@ -283,7 +283,7 @@ table used to say the opposite.

| Tool(s) | Platforms | Method |
|---|---|---|
| typescript, tsx, ts-node | all | pnpm global |
| typescript, tsx | all | pnpm global |

#### developer-c

Expand Down Expand Up @@ -630,7 +630,7 @@ security, so it holds the version it shipped with for the life of the release
(see the ladder note above). A vendor repo, a snap and Fedora's own packages
all track upstream properly.

**Tier 2 - language-manager tools.** Tools installed by uv / cargo / go / npm / pnpm have no OS channel, so `hyperi-update` refreshes them through each manager: `uv tool upgrade --all`, `rustup update` and `cargo install-update -a --locked`, `go install ...@latest` for the tools in `~/go/bin` (only when the module or the Go toolchain moved), `npm update -g`, and `pnpm update -g --latest`. The pnpm globals (eslint, prettier, typescript, tsx, ts-node) are installed unpinned, so `--latest` moves them to what a fresh converge would install, majors included. `uv python upgrade` moves each uv-managed Python to its newest patch without adding a python or python3 shim, and leaves the superseded patch installed, because uv has no command that removes only those. E.g. ruff, ty, semgrep, pip-audit, cargo-audit, cargo-hack, typos, govulncheck, maid.
**Tier 2 - language-manager tools.** Tools installed by uv / cargo / go / npm / pnpm have no OS channel, so `hyperi-update` refreshes them through each manager: `uv tool upgrade --all`, `rustup update` and `cargo install-update -a --locked`, `go install ...@latest` for the tools in `~/go/bin` (only when the module or the Go toolchain moved), `npm update -g`, and `pnpm update -g --latest`. The pnpm globals (eslint, prettier, typescript, tsx) are installed unpinned, so `--latest` moves them to what a fresh converge would install, majors included. `uv python upgrade` moves each uv-managed Python to its newest patch without adding a python or python3 shim, and leaves the superseded patch installed, because uv has no command that removes only those. E.g. ruff, ty, semgrep, pip-audit, cargo-audit, cargo-hack, typos, govulncheck, maid.

**Tier 3 - static binaries.** A handful ship only as a release binary with no repo, snap, or language manager: kind, argocd, kubeconform, kube-linter, terraform-docs, golangci-lint, lazygit, actionlint, osv-scanner, aws-vault, git-scrub, sccache, fnm, hadolint, tea and macbash on both distros, k9s, kustomize, yq, gitleaks and act on Ubuntu, and sd, kubectx and kubens on Fedora. `hyperi-update` re-fetches each one only where the role put it in `/usr/local/bin` on that distro, so the binary cannot shadow a packaged copy. Each download must match the sha256 GitHub publishes for the asset, or the release's checksum file where there is no digest (tea and macbash publish a `.sha256` beside the asset), and is renamed into place so the working copy is never half-written. Each GitHub release is the newest at least 7 days old, as in the roles, which write their age and exempt orgs to `/etc/default/hyperi-update`. `HYPERI_RELEASE_MIN_AGE_DAYS` in the environment overrides that file and `--min-age DAYS` overrides both. With no release old enough the installed copy stays and the summary lists it. A stamp in `/var/lib/hyperi-update` stops an unmoved release being downloaded again, and the GitHub API is asked with the last ETag, so with a token set an unchanged release costs no rate limit (an anonymous 304 still counts). When the API refuses, the release document from the last run stands in. On Ubuntu, uv and uvx in `~/.local/bin` are refreshed the same way as the invoking user.

Expand Down
2 changes: 1 addition & 1 deletion install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -169,7 +169,7 @@ Languages (developer-<lang>; --languages [list] or developer-languages for all):
developer-python mypy (opt-in; ruff/ty ship in the base astral suite)
developer-node eslint + prettier (Node itself is in the base -- it is
core tooling, needed by semantic-release and CI)
developer-typescript typescript + tsx + ts-node (pulls developer-node)
developer-typescript typescript + tsx (pulls developer-node)
developer-c C/C++ build tools

Infrastructure (infrastructure):
Expand Down
Loading