Fix CORS issue for SPDX licenses - #438
Conversation
official SPDX GitHub repo
SPDXType.init() now throws when license details cannot be fetched, letting the caller fall back to another renderer rather than rendering a degraded view with a 'Network Issue' item. Removes handleInitError, addBasicErrorInfo and addNetworkIssueInfo, and adds an isResolvable() override so a failed probe/init is not cached in IndexedDB.
Update SPDXType unit test to assert init() rejects on fetch failure and add isResolvable() coverage. Add a Parser unit test verifying that an uncertain renderer whose API check fails (e.g. SPDX network failure) yields to another renderer instead of being selected.
🎨 Chromatic Visual Tests🔍 Visual changes detected ReviewChromatic provides automated visual testing and review for component changes. |
Test ResultsCoverage Summary
Coverage & Quality Reports📊 Codecov Report For more details, check the workflow run |
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #438 +/- ##
==========================================
+ Coverage 80.65% 80.69% +0.04%
==========================================
Files 57 57
Lines 3809 3787 -22
Branches 1154 1168 +14
==========================================
- Hits 3072 3056 -16
+ Misses 733 727 -6
Partials 4 4
🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical parser fallback, Angular compatibility, and integration test issues remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 3
Open (10)
Avoid unrelated Angular peer requirement breaking change · New Handle SPDX resolution failures in ordered parser mode · New Test SPDX identifier through the public data getter · New Make requestTimeout configurable or document it as fixed · New Exclude live SPDX tests from the default unit suite · New Synchronize root release metadata to version 0.4.5 · New Synchronize Angular package release metadata to 0.4.5 · New Synchronize React package release metadata to 0.4.5 · New Synchronize package release metadata to version 0.4.5 · New Synchronize Vue package release metadata to 0.4.5 · New
What changed in this PR
This PR switches SPDX license fetching from a CORS proxy to the official SPDX GitHub repository and updates related tests, documentation, dependencies, and generated files.
Changes:
- Uses raw GitHub SPDX JSON with fallback handling.
- Adds unit, integration, and Playwright coverage.
- Updates package versions, Angular tooling, and formatting configuration.
| File | Summary |
|---|---|
README.md |
Documents SPDX fetching; requestTimeout is currently not configurable. |
packages/vue-library/package.json |
Updates package metadata; release metadata remains at 0.4.4. |
packages/stencil-library/web-types.json |
Updates generated package metadata. |
packages/stencil-library/src/utils/__tests__/Parser.unit.ts |
Tests renderer fallback behavior. |
packages/stencil-library/src/rendererModules/SPDXType/SPDXType.tsx |
Uses raw SPDX data; ordered resolution can abort fallback on errors, and failed fallbacks may be cached. |
packages/stencil-library/src/rendererModules/SPDXType/SPDX.mdx |
Documents the new SPDX source. |
packages/stencil-library/src/rendererModules/SPDXType/__tests__/SPDXType.unit.ts |
Adds SPDX fetch and failure tests. |
packages/stencil-library/src/rendererModules/SPDXType/__tests__/SPDXType.integration.unit.ts |
Live tests run in the default suite and access a private member, causing type-check failure. |
packages/stencil-library/src/components/pid-tooltip/readme.md |
Formatting update. |
packages/stencil-library/src/components/pid-component/__tests__/spdx.e2e.playwright.ts |
Assertion does not distinguish resolved output from fallback output. |
packages/stencil-library/src/components/pid-component/__tests__/spdx.e2e.html |
Adds the SPDX browser-test fixture. |
packages/stencil-library/src/components/pid-collapsible/readme.md |
Formatting update. |
packages/stencil-library/src/components.d.ts |
Updates generated component declarations. |
packages/stencil-library/package.json |
Adds integration testing and updates dependencies; release metadata remains at 0.4.4. |
packages/stencil-library/.prettierignore |
Ignores generated files. |
packages/react-library/package.json |
Updates package metadata; release metadata remains at 0.4.4. |
packages/nextjs-app/package.json |
Updates demo dependencies and versions. |
packages/angular-library/package.json |
Updates dependencies; release metadata is stale and the peer range introduces an unrelated Angular compatibility break. |
packages/angular-library/lib/stencil-generated/angular-component-lib/boolean-attribute.ts |
Adds an unused helper under generated output. |
package.json |
Bumps workspace version; synchronized release metadata remains at 0.4.4. |
.prettierrc.json |
Updates Prettier configuration. |
.prettierignore |
Ignores generated wrapper output. |
.pre-commit-config.yaml |
Excludes generated files from whitespace checks. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🎨 Chromatic Visual Tests✅ No visual changes ReviewChromatic provides automated visual testing and review for component changes. |
Test ResultsCoverage Summary
Coverage & Quality Reports📊 Codecov Report For more details, check the workflow run |
🎨 Chromatic Visual Tests✅ No visual changes ReviewChromatic provides automated visual testing and review for component changes. |
Test ResultsCoverage Summary
Coverage & Quality Reports📊 Codecov Report For more details, check the workflow run |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved configuration, fallback, test-targeting, and test-validity issues remain.
Review effort: Lite
Findings: 3
Open (11)
Test SPDX identifier through the public data getter Handle SPDX resolution failures in ordered parser mode Avoid unrelated Angular peer requirement breaking change Duplicate integration script overwrites Stencil test command · New Exclude live SPDX tests from the default unit suite Make requestTimeout configurable or document it as fixed Synchronize Vue package release metadata to 0.4.5 Synchronize package release metadata to version 0.4.5 Synchronize React package release metadata to 0.4.5 Synchronize Angular package release metadata to 0.4.5 Synchronize root release metadata to version 0.4.5
These Angular packages are only used by the Angular Storybook/demo setup, so they should not be published as runtime dependencies of the wrapper. Also syncs the package-lock (workspace version 0.5.0 and stale spec updates).
…ions Allow a single wrapper version to be consumed by the currently supported framework versions: Angular 20/21/22 and React 18/19 (Vue already peers ^3.0.0). The ranges are validated by a clean-room consumer matrix (see CI workflow).
The package.json had two conflicting 'test:integration' entries after the integration suite moved to vitest; keep the vitest configuration and drop the stale stencil-test one.
Run 'tsc -p <pkg> --noEmit' for the stencil, react, vue and angular packages as part of CI via a new 'npm run typecheck' (lerna) script, so type errors are caught before the test stage. The stencil-library tsconfig is adjusted (strict:false, skipLibCheck, lib es2021, drop baseUrl) so its tsc check passes under the package's own typescript 7.0.2 devDependency.
The wrappers are compiled with the latest toolchain but published with peer ranges spanning the supported framework versions (Angular 20/21/22, React 18/19, Vue 3). A new script packs the stencil library + wrapper from the current tree, installs them into a throw-away consumer project together with a specific framework version, and type-checks a consumer sample using the public API. A GitHub Actions matrix runs it for every peer-range leg so the ranges are continuously validated instead of assumed. All 6 legs pass locally.
…rk-wrappers Refactor/dedemo framework wrappers
🎨 Chromatic Visual Tests✅ No visual changes ReviewChromatic provides automated visual testing and review for component changes. |
Test ResultsCoverage Summary
Coverage & Quality Reports📊 Codecov Report For more details, check the workflow run |
🎨 Chromatic Visual Tests✅ No visual changes ReviewChromatic provides automated visual testing and review for component changes. |
🎨 Chromatic Visual Tests✅ No visual changes ReviewChromatic provides automated visual testing and review for component changes. |
Test ResultsCoverage Summary
Coverage & Quality Reports📊 Codecov Report For more details, check the workflow run |
Test ResultsCoverage Summary
Coverage & Quality Reports📊 Codecov Report For more details, check the workflow run |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Six moderate issues remain unresolved, including fallback behavior, test configuration, network-dependent CI, and ineffective timeout documentation.
Review effort: Lite
Findings: 1
Open (2)
Resolved since last review (10)
Test SPDX identifier through the public data getter Avoid unrelated Angular peer requirement breaking change Duplicate integration script overwrites Stencil test command Exclude live SPDX tests from the default unit suite Make requestTimeout configurable or document it as fixed Synchronize Vue package release metadata to 0.4.5 Synchronize package release metadata to version 0.4.5 Synchronize React package release metadata to 0.4.5 Synchronize Angular package release metadata to 0.4.5 Synchronize root release metadata to version 0.4.5



This PR changes the way how SPDX licenses are fetched. Instead of using the SPDX.org website with corsproxy.io, we use the official SPDX GitHub repository.