Repository navigation
Reserve @taffyjs scope for published packages - #19
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
This pull request tightens npm package naming hygiene by reserving the @taffyjs/* scope for artifacts that are intended to be published independently, and renames the build-only wasm32-wasip1 napi-rs staging package to an unscoped name. This aligns internal build staging identities with the repository’s intended distribution boundaries without changing public consumer imports.
Changes:
- Switched the wasm32-wasip1 staging package reference from
@taffyjs/binding-wasm32-wasip1totaffyjs-binding-wasm32-wasip1in the wasm runtime-file generation pipeline. - Updated the
@taffyjs/wasmpackage’s napi-rspackageNametotaffyjs-bindingand strengthened package-content assertions to ensure no binding-wasm dependency leakage. - Recorded the new “scope reserved for published packages” decision in PCR tooling records and updated wasm package documentation accordingly (including removal of a now-stale whole-file vouch stamp).
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| tools/taffy-wasm/generate-inline-wasm-runtime-files.ts | Updates the exact-loader transformation inputs and forbidden-string guards to reflect the unscoped wasm32-wasip1 staging package name. |
| tests/taffyjs-wasm/tests/package-contents.ts | Adjusts package-content assertions to validate the updated napi packageName and ensure no binding-wasm dependencies are present. |
| packages/taffyjs-wasm/package.json | Changes napi-rs packageName to taffyjs-binding to drive unscoped build-only target package naming. |
| .agents/docs/tooling-decisions.md | Adds a new tooling decision explicitly reserving @taffyjs scope for separately published packages. |
| .agents/docs/taffyjs-wasm-package.md | Updates the wasm package design record to reference the unscoped staging package name and removes the stale whole-file vouch stamp. |
| .agents/docs/README.md | Updates the PCR map descriptions to reflect current vouch status and the expanded tooling decisions scope. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
hyfdev
added a commit
that referenced
this pull request
Aug 16, 2026
hyfdev
added a commit
that referenced
this pull request
Aug 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@taffyjsnpm scope for packages that are intended to be published separately@taffyjs/binding-wasm32-wasip1to unscopedtaffyjs-binding-wasm32-wasip1Why
The Wasm target package exists only as a build staging input and is never published. It should not use the organization scope. Public packages and native platform optional dependencies remain scoped because they are separately distributed npm artifacts.
Impact
Public
@taffyjs/nodeand@taffyjs/wasmnames, native platform package names, and consumer imports are unchanged. Only the internal generated Wasm target identity changes.The Wasm design record previously had a whole-file vouch. Because this change updates covered wording, the stamp was removed rather than being carried forward without explicit re-vouching.
Validation
vp fmt --checkvp lint --deny-warningsvp run checkvp run check:wasmvp run tests-taffy-wasm#check:packagetaffyjs-binding-wasm32-wasip1