Skip to content

fix(javascript): vendor the pinned js-debug release without a GitHub API call (#867, #813) - #868

Merged
debugmcpdev merged 1 commit into
mainfrom
fix/867-813-pinned-vendor-direct-download
Oct 7, 2026
Merged

debugmcpdev merged 1 commit into
mainfrom
fix/867-813-pinned-vendor-direct-download

Conversation

@debugmcpdev

Copy link
Copy Markdown
Collaborator

What

Vendoring the pinned js-debug release asked api.github.com/repos/microsoft/vscode-js-debug/releases/tags/v1.112.0 for the release's asset list before downloading. That lookup is subject to the unauthenticated REST quota (60 requests/hour per IP), which a shared CI runner or a docker build (no token inside the image build) has often used up:

packages/adapter-javascript/vendor-manifest.json already pins the tag and the asset name, so the pinned build now downloads straight from <upstream>/releases/download/<tag>/<asset> — served by github.com (a redirect to the release CDN), outside the API quota. No token is needed for a pinned build anywhere: CI, Docker builds, release.yml's build-push-action, local installs.

How

  • scripts/lib/js-debug-helpers.js: pure pinnedAssetCandidate(pin, version) → the direct URL (via the existing selectBestAsset preference) when the requested version is the pin and the pin names an archive; null for latest, a version override, or a pin without assets. Typed in the sibling .d.ts.
  • scripts/build-js-debug.js: tries the pinned candidate first; a failed direct download (an upstream re-release under another name) logs a warning and falls back to the API path exactly as before. The sha256 integrity gate is unchanged and still runs on the downloaded archive.
  • ci.yml cobol-host: the install step carries GITHUB_TOKEN like the other jobs' vendor step, so a latest/override build there is off the unauthenticated quota too (ci: COBOL Host job vendors adapters without a token and flakes on the GitHub API rate limit #813's suggested fix, now belt-and-braces).

Verified (Windows 11, no GH_TOKEN/GITHUB_TOKEN in the environment)

JS_DEBUG_FORCE_REBUILD=true pnpm -F @debugmcp/adapter-javascript run build:adapter
[js-debug vendor] Pinned release v1.112.0: downloading js-debug-dap-v1.112.0.tar.gz directly (no GitHub API call) ...
[js-debug vendor] Integrity check passed: js-debug-dap-v1.112.0.tar.gz matches pinned sha256.
[js-debug vendor] Success: vendored vsDebugServer.js (818088 bytes)
 - sha256: 1a375a9370e46e786c4095b2a0d2fd74fe54b29564dba7f1e2fe34605104d258   (= vendor-manifest derived pin)
  • JS_DEBUG_VERSION=latest JS_DEBUG_ALLOW_UNPINNED=true → "Fetching GitHub release 'latest' …" — the API path is taken as before (vendored v1.140.0, then re-vendored the pin).
  • JS_DEBUG_VERSION=v1.111.0 (not a js-debug tag) → API path, 404 reported as before.
  • 6 new unit cases in build-js-debug.helpers.test.ts; npm run typecheck:all, npm run lint, pnpm changelog:check clean.

Fixes #867
Fixes #813

🤖 Generated with Claude Code

…API call (#867, #813)

build-js-debug.js asked api.github.com for the release's asset list before
downloading, and that lookup is subject to the unauthenticated REST quota
(60/h per IP). Shared CI runners and `docker build` (which carries no token)
run out of it: the COBOL Host job's postinstall vendoring and the daily
canary's image build both failed with 403.

vendor-manifest.json pins the tag AND the asset name, so the pinned build now
downloads straight from <upstream>/releases/download/<tag>/<asset> — served
by github.com, outside the API quota, the way vendor-codelldb.js already
does. 'latest' and version overrides still go through the API, and a direct
download that fails (an upstream re-release under another name) falls back
to it. The cobol-host job's install step also carries GITHUB_TOKEN, like the
other jobs' vendor step.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@debugmcpdev
debugmcpdev merged commit 6cb0c52 into main Oct 7, 2026
9 of 11 checks passed
@debugmcpdev
debugmcpdev deleted the fix/867-813-pinned-vendor-direct-download branch October 7, 2026 16:46
debugmcpdev added a commit that referenced this pull request Oct 7, 2026
…tays EBUSY (#866) (#873)

The "reports the exit code under noDebug" case removed its temp directory
in a finally with rmSync's 10 x 200 ms retry, and on windows-latest that
was twice not enough (run 37406647101 for PR #862, run 37653235241 for
PR #868): Delve holds the exited debuggee's image until its own exit,
which the session's close does not wait for, and the EBUSY failed a test
whose debugging part had passed — taking the Windows job with it.

A cleanup EBUSY/EPERM is now logged and the directory left under the temp
dir for the OS, the way mcp-server-self-debug.test.ts already treats its
inner dir; any other error still throws.

Co-authored-by: JF <john.franklin@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Canary failure: published-artifact smoke (2026-10-06) ci: COBOL Host job vendors adapters without a token and flakes on the GitHub API rate limit

2 participants