Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
c919e89
feat(runtime): reject incompatible runtime image reuse
ScriptedAlchemy Sep 18, 2026
9045eb7
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 18, 2026
fbbfe82
test(runtime): stop minifying selector bundles
ScriptedAlchemy Sep 21, 2026
8006b8c
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 24, 2026
516abbf
fix(runtime): check runtime families before instances register
ScriptedAlchemy Sep 24, 2026
d33a2ea
fix(inject-external-runtime-core-plugin): keep legacy provider behavior
ScriptedAlchemy Sep 24, 2026
9f23ffa
docs(changeset): state that runtime image checks are inert without me…
ScriptedAlchemy Sep 24, 2026
21be2ab
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 24, 2026
974733c
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 24, 2026
de8653e
fix(runtime-core): compare runtime capabilities in both directions
ScriptedAlchemy Sep 24, 2026
0c093af
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 24, 2026
0804ec8
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 24, 2026
5eacc26
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 24, 2026
97b45f0
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 25, 2026
e6e9143
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 25, 2026
f86060f
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 25, 2026
f7076fb
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 25, 2026
f32aae6
Merge branch 'rfc5036/03-runtime-selectors' into rfc5036/04-runtime-i…
ScriptedAlchemy Sep 25, 2026
32ff9f7
Merge branch 'update/rfc5036-03' into update/rfc5036-04
ScriptedAlchemy Oct 3, 2026
ee92053
fix(runtime-core): isolate remote entry evaluators
ScriptedAlchemy Oct 3, 2026
7c463f7
fix(runtime-plugin): require image checker only for tagged runtimes
ScriptedAlchemy Oct 3, 2026
97c0f0e
Merge branch 'update/rfc5036-03' into update/rfc5036-04
ScriptedAlchemy Oct 3, 2026
4ec8f15
Merge updated RFC5036 parent update/rfc5036-03
ScriptedAlchemy Oct 3, 2026
89e57fd
fix(runtime-core): reject malformed image-backed Node entry exports
ScriptedAlchemy Oct 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/external-runtime-minimum-contract.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@module-federation/inject-external-runtime-core-plugin': patch
---

Keep legacy providers compatible with older runtime cores and report a minimum-contract error before publishing or reusing runtime-image metadata when the core cannot check image compatibility.
5 changes: 5 additions & 0 deletions .changeset/quiet-node-payload.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@module-federation/runtime-core': patch
---

Reject malformed image-backed Node entry exports instead of falling back to a mutable global container from another evaluator.
5 changes: 5 additions & 0 deletions .changeset/rfc5036-entry-evaluator-isolation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@module-federation/runtime-core': patch
---

Isolate image-backed remote entry caches for host-specific evaluators and URL transforms while preserving default loader deduplication and legacy reuse.
16 changes: 16 additions & 0 deletions .changeset/runtime-image-compatibility.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
'@module-federation/enhanced': minor
'@module-federation/runtime': minor
'@module-federation/runtime-core': minor
'@module-federation/inject-external-runtime-core-plugin': patch
---

Carry runtime-image metadata on runtime instances, the external runtime-core
provider, and remote-entry cache entries. When both sides carry metadata, a
known family, target, capability, or entry-loader mismatch fails before the
instance runs plugins, before the external core is reused, and before a cached
remote entry is reused.

Every check is inert without metadata. Builds that do not use
`module-federation:*` conditions keep today's behavior, and the remote-entry
cache key stays `name` plus `entry`.
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ import {
normalizeRuntimeInitOptionsWithOutShared,
createHash,
normalizeToPosixPath,
type NormalizedRuntimeInitOptionsWithOutShared,
} from './utils';
import {
expectedEntry,
Expand Down Expand Up @@ -118,6 +119,7 @@ class FederationRuntimePlugin {
bundlerRuntimePath: string;
runtimePath: string;
runtimeToolsPath: string;
runtimeInitOptions?: NormalizedRuntimeInitOptionsWithOutShared;
federationRuntimeDependency?: FederationRuntimeDependency; // Add this line

constructor(options?: moduleFederationPlugin.ModuleFederationPluginOptions) {
Expand Down Expand Up @@ -345,6 +347,7 @@ class FederationRuntimePlugin {
const initOptionsWithoutShared = normalizeRuntimeInitOptionsWithOutShared(
this.options,
);
this.runtimeInitOptions = initOptionsWithoutShared;
const federationGlobal = getFederationGlobalScope(
RuntimeGlobals || ({} as typeof RuntimeGlobals),
);
Expand Down Expand Up @@ -422,6 +425,33 @@ class FederationRuntimePlugin {
this.runtimeToolsPath =
expectedEntry(image, '@module-federation/runtime-tools$') ??
image.family.members['runtime-tools'].entry;
if (
image.mode === 'conditions' &&
selection.profile &&
this.runtimeInitOptions
) {
const capabilities = [
'remote',
'shared',
'snapshotPlugins',
'containerEntry',
] as const;
this.runtimeInitOptions.runtimeImage = {
contract: 1,
compatibilityId: image.family.compatibilityId,
required: capabilities.filter(
(capability) => selection.profile?.[capability] === 'required',
),
forbidden: capabilities.filter(
(capability) => selection.profile?.[capability] === 'forbidden',
),
available: capabilities.filter(
(capability) => selection.profile?.[capability] !== 'forbidden',
),
target: selection.profile.target,
entryLoadingIdentity: image.entryLoadingIdentity,
};
}
this.setRuntimeAlias(compiler);
this.entryFilePath = this.getFilePath(compiler);
}
Expand Down
9 changes: 9 additions & 0 deletions packages/enhanced/src/lib/container/runtime/utils.ts
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,15 @@ export interface NormalizedRuntimeInitOptionsWithOutShared {
remotes: Array<
Remotes[0] & { externalType: moduleFederationPlugin.ExternalsType }
>;
runtimeImage?: {
contract: 1;
compatibilityId: string;
required: string[];
forbidden: string[];
available: string[];
target: string;
entryLoadingIdentity: string;
};
}

const extractUrlAndGlobal = require(
Expand Down
Loading
Loading