Repository navigation
fix(javascript): vendor the pinned js-debug release without a GitHub API call (#867, #813) - #868
Merged
Conversation
…API call (#867, #813) build-js-debug.js asked api.github.com for the release's asset list before downloading, and that lookup is subject to the unauthenticated REST quota (60/h per IP). Shared CI runners and `docker build` (which carries no token) run out of it: the COBOL Host job's postinstall vendoring and the daily canary's image build both failed with 403. vendor-manifest.json pins the tag AND the asset name, so the pinned build now downloads straight from <upstream>/releases/download/<tag>/<asset> — served by github.com, outside the API quota, the way vendor-codelldb.js already does. 'latest' and version overrides still go through the API, and a direct download that fails (an upstream re-release under another name) falls back to it. The cobol-host job's install step also carries GITHUB_TOKEN, like the other jobs' vendor step. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
debugmcpdev
added a commit
that referenced
this pull request
Oct 7, 2026
…tays EBUSY (#866) (#873) The "reports the exit code under noDebug" case removed its temp directory in a finally with rmSync's 10 x 200 ms retry, and on windows-latest that was twice not enough (run 37406647101 for PR #862, run 37653235241 for PR #868): Delve holds the exited debuggee's image until its own exit, which the session's close does not wait for, and the EBUSY failed a test whose debugging part had passed — taking the Windows job with it. A cleanup EBUSY/EPERM is now logged and the directory left under the temp dir for the OS, the way mcp-server-self-debug.test.ts already treats its inner dir; any other error still throws. Co-authored-by: JF <john.franklin@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Vendoring the pinned js-debug release asked
api.github.com/repos/microsoft/vscode-js-debug/releases/tags/v1.112.0for the release's asset list before downloading. That lookup is subject to the unauthenticated REST quota (60 requests/hour per IP), which a shared CI runner or adocker build(no token inside the image build) has often used up:docker build guard (ubuntu-latest)leg failed onRUN pnpm run buildwithAPI rate limit exceeded for 20.168.125.113(run 37488947248). The CodeLLDB vendor in the same build succeeded seconds earlier — it downloads fromreleases/download/, not the API.COBOL Hostjob's barepnpm install(postinstall vendoring, no token) flaked the same way.packages/adapter-javascript/vendor-manifest.jsonalready pins the tag and the asset name, so the pinned build now downloads straight from<upstream>/releases/download/<tag>/<asset>— served by github.com (a redirect to the release CDN), outside the API quota. No token is needed for a pinned build anywhere: CI, Docker builds,release.yml's build-push-action, local installs.How
scripts/lib/js-debug-helpers.js: purepinnedAssetCandidate(pin, version)→ the direct URL (via the existingselectBestAssetpreference) when the requested version is the pin and the pin names an archive;nullforlatest, a version override, or a pin without assets. Typed in the sibling.d.ts.scripts/build-js-debug.js: tries the pinned candidate first; a failed direct download (an upstream re-release under another name) logs a warning and falls back to the API path exactly as before. The sha256 integrity gate is unchanged and still runs on the downloaded archive.ci.ymlcobol-host: the install step carriesGITHUB_TOKENlike the other jobs' vendor step, so alatest/override build there is off the unauthenticated quota too (ci: COBOL Host job vendors adapters without a token and flakes on the GitHub API rate limit #813's suggested fix, now belt-and-braces).Verified (Windows 11, no
GH_TOKEN/GITHUB_TOKENin the environment)JS_DEBUG_VERSION=latest JS_DEBUG_ALLOW_UNPINNED=true→ "Fetching GitHub release 'latest' …" — the API path is taken as before (vendored v1.140.0, then re-vendored the pin).JS_DEBUG_VERSION=v1.111.0(not a js-debug tag) → API path, 404 reported as before.build-js-debug.helpers.test.ts;npm run typecheck:all,npm run lint,pnpm changelog:checkclean.Fixes #867
Fixes #813
🤖 Generated with Claude Code