Skip to content

feat: exclude @vaadin packages from the minimum frontend package age (#25620) (CP: 25.3) - #25702

Merged
vaadin-bot merged 1 commit into
25.3from
cherry-pick-25620-to-25.3-1789380237224
Sep 14, 2026
Merged

vaadin-bot merged 1 commit into
25.3from
cherry-pick-25620-to-25.3-1789380237224

Conversation

@vaadin-bot

Copy link
Copy Markdown
Collaborator

This PR cherry-picks changes from the original PR #25620 to branch 25.3.

Original PR description

Summary

The minimum frontend package age blocks packages that were published very recently. Because the @vaadin packages are pinned to the platform version, a build started right after a Vaadin release had no older version to fall back to and failed. Vaadin now tells the package manager to exempt @vaadin/* from that check, and warns when the package manager cannot do it.

What changed

Behavior change: every build that runs with a minimum frontend package age now gets extra install arguments, and some builds get a new warning. Nothing is added when no age applies.

  • npm 11.17.0 and newer: --min-release-age-exclude=@vaadin/* is passed. It exempts the matching packages from both --min-release-age and --before.
  • pnpm 10.17.0 and newer: --config.minimum-release-age-exclude=@vaadin/* is passed. When there is a single pattern it is passed twice, because pnpm reads the setting as a list only when the argument occurs more than once, and pnpm 11 excludes every package when the value is a plain string.
  • Patterns already configured in .npmrc / pnpm config are kept. A command line value replaces the configured list instead of adding to it, so Vaadin reads the configured patterns and passes them along with @vaadin/*. Without this, a project that excludes its own scope silently lost that exclusion.
  • bun, older npm, older pnpm: nothing can be passed, so the build is warned that an install during the first day after a Vaadin release may fail. The warning names the remedy for the package manager in use — upgrade npm to 11.17.0 (first shipped with Node.js 24.19.0), upgrade pnpm to 10.17.0, or, for bun, list the @vaadin packages one by one in minimumReleaseAgeExcludes in a bunfig.toml, since bun matches exact names only.
  • bun without a warning: the project bunfig.toml is now read, and the warning is skipped when a @vaadin package is an actual value of minimumReleaseAgeExcludes. A commented-out line or an unrelated mention is not enough.
  • minimumFrontendPackageAgeDays = 0: Vaadin still passes no age argument, but an age that npm or pnpm resolves from its own configuration still applies to the install. That age is now reported as applying, so the @vaadin packages are excluded from it instead of being blocked silently. When the package manager itself resolves an age of 0, nothing applies and nothing is excluded or warned about.
  • Reading a list-valued setting no longer splits list entries on commas. Only a comma-separated string value is split, because a list entry is complete on its own and may contain a comma of its own in a brace expansion such as @acme/{ui,core}.
  • Javadoc for minimumFrontendPackageAgeDays in Options, InitParameters, BuildFrontendMojo and BuildDevBundleMojo now documents the exclusion and the required npm/Node.js/pnpm versions.

No public or protected API changed. The new methods and the internal resolveMinimumFrontendPackageAge rename are package-private.

Use case

A team builds their app with bun, and CI runs a few minutes after a Vaadin release. The install fails because the freshly published @vaadin packages are younger than the minimum age, and bun cannot take an exclusion from the command line. The build log now tells them what to do: add the packages they depend on to a bunfig.toml next to package.json.

[install]
minimumReleaseAgeExcludes = ["@vaadin/react-components"]

After that the install succeeds, and Vaadin stops printing the warning on every build.

Test summary

# Status What the test verifies Why it matters
1 ✅ npm gets --min-release-age-exclude=@vaadin/* and no warning Core fix: a build right after a release must not be blocked
2 ✅ pnpm gets --config.minimum-release-age-exclude=@vaadin/* twice A single occurrence makes pnpm 11 exclude every package, turning the age check off
3 ✅ Patterns configured in the package manager are passed along with @vaadin/* A command line value replaces them, so a project would silently lose its own exclusion
4 ✅ A real pnpm install command contains the exclude argument Pins that the argument actually reaches the install, not just the resolver
5 ✅ npm/pnpm too old or bun: no argument, and a warning naming the version or the bunfig setting The only signal a user gets when the exclusion is impossible
6 ✅ A bunfig.toml listing a @vaadin package silences the warning; other packages or a comment do not A bun project that fixed it must not be nagged; a fake match must not hide a real problem
7 ✅ With Vaadin configured to 0 and no package manager age: no argument, no exclusion, no warning A project that opted out must stay fully opted out
8 ✅ With Vaadin configured to 0 but npm configured with 7 days: the age applies, so @vaadin/* is excluded The silently blocking case this PR fixes
9 ✅ A package manager age of 0 counts as no age at all Avoids arguments and warnings when nothing is blocked
10 ✅ List settings are read from an array and from a comma-separated string; a brace expansion in a list is kept whole; a null/empty key gives an empty list Splitting @acme/{ui,core} would produce two broken patterns
11 ❗ gap npmSupportsMinReleaseAgeExclude / pnpmSupportsMinimumReleaseAgeExclude comparing a real reported version against 11.17.0 / 10.17.0 A wrong threshold would pass an unknown argument to an old tool; callers only mock these
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npm_excludesVaadinPackages — 1
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_pnpm_excludesVaadinPackagesAsAList — 2
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_configuredPatterns_areKept — 3
  • TaskRunPnpmInstallTest.runPnpmInstall_excludesVaadinPackagesFromTheMinimumAge — 4
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npmTooOld_warnsInsteadOfExcluding — 5
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_pnpmTooOld_warnsInsteadOfExcluding — 5
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bun_warnsInsteadOfExcluding — 5
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bunfigListsThePackages_noWarning — 6
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bunfigListsOtherPackages_warns — 6
  • TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_zeroConfigured_noArgumentAndNoAge — 7, 9
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_noAgeApplies_noArgumentOrWarning — 7
  • TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_zeroConfiguredWithNpmrcValue_ageStillApplies — 8
  • TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npmrcValue_isStillExcludedFrom — 8
  • TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_npmrcValueOfZero_noAgeApplies — 9
  • FrontendToolsTest.getConfiguredSettingValues_listAndCommaSeparatedValue_areRead — 10
  • FrontendToolsTest.getConfiguredSettingValues_braceExpansionInAList_isKeptTogether — 10
  • FrontendToolsTest.getConfiguredSettingValues_keyWithoutValue_isEmpty — 10

Left untested on purpose: the exact wording of the warning (only the key facts are asserted), and the unreadable-bunfig.toml path, which just falls back to warning.

…25620)

## Summary

The minimum frontend package age blocks packages that were published
very recently. Because the `@vaadin` packages are pinned to the platform
version, a build started right after a Vaadin release had no older
version to fall back to and failed. Vaadin now tells the package manager
to exempt `@vaadin/*` from that check, and warns when the package
manager cannot do it.

## What changed

**Behavior change:** every build that runs with a minimum frontend
package age now gets extra install arguments, and some builds get a new
warning. Nothing is added when no age applies.

- **npm 11.17.0 and newer:** `--min-release-age-exclude=@vaadin/*` is
passed. It exempts the matching packages from both `--min-release-age`
and `--before`.
- **pnpm 10.17.0 and newer:**
`--config.minimum-release-age-exclude=@vaadin/*` is passed. When there
is a single pattern it is passed twice, because pnpm reads the setting
as a list only when the argument occurs more than once, and pnpm 11
excludes *every* package when the value is a plain string.
- **Patterns already configured in `.npmrc` / pnpm config are kept.** A
command line value replaces the configured list instead of adding to it,
so Vaadin reads the configured patterns and passes them along with
`@vaadin/*`. Without this, a project that excludes its own scope
silently lost that exclusion.
- **bun, older npm, older pnpm:** nothing can be passed, so the build is
warned that an install during the first day after a Vaadin release may
fail. The warning names the remedy for the package manager in use —
upgrade npm to 11.17.0 (first shipped with Node.js 24.19.0), upgrade
pnpm to 10.17.0, or, for bun, list the `@vaadin` packages one by one in
`minimumReleaseAgeExcludes` in a `bunfig.toml`, since bun matches exact
names only.
- **bun without a warning:** the project `bunfig.toml` is now read, and
the warning is skipped when a `@vaadin` package is an actual value of
`minimumReleaseAgeExcludes`. A commented-out line or an unrelated
mention is not enough.
- **`minimumFrontendPackageAgeDays = 0`:** Vaadin still passes no age
argument, but an age that npm or pnpm resolves from its own
configuration still applies to the install. That age is now reported as
applying, so the `@vaadin` packages are excluded from it instead of
being blocked silently. When the package manager itself resolves an age
of `0`, nothing applies and nothing is excluded or warned about.
- Reading a list-valued setting no longer splits list entries on commas.
Only a comma-separated string value is split, because a list entry is
complete on its own and may contain a comma of its own in a brace
expansion such as `@acme/{ui,core}`.
- Javadoc for `minimumFrontendPackageAgeDays` in `Options`,
`InitParameters`, `BuildFrontendMojo` and `BuildDevBundleMojo` now
documents the exclusion and the required npm/Node.js/pnpm versions.

No public or protected API changed. The new methods and the internal
`resolveMinimumFrontendPackageAge` rename are package-private.

## Use case

A team builds their app with bun, and CI runs a few minutes after a
Vaadin release. The install fails because the freshly published
`@vaadin` packages are younger than the minimum age, and bun cannot take
an exclusion from the command line. The build log now tells them what to
do: add the packages they depend on to a `bunfig.toml` next to
`package.json`.

```toml
[install]
minimumReleaseAgeExcludes = ["@vaadin/react-components"]
```

After that the install succeeds, and Vaadin stops printing the warning
on every build.

## Test summary

| # | Status | What the test verifies | Why it matters |
|---|--------|------------------------|----------------|
| 1 | ✅ | npm gets `--min-release-age-exclude=@vaadin/*` and no warning
| Core fix: a build right after a release must not be blocked |
| 2 | ✅ | pnpm gets `--config.minimum-release-age-exclude=@vaadin/*`
twice | A single occurrence makes pnpm 11 exclude every package, turning
the age check off |
| 3 | ✅ | Patterns configured in the package manager are passed along
with `@vaadin/*` | A command line value replaces them, so a project
would silently lose its own exclusion |
| 4 | ✅ | A real pnpm install command contains the exclude argument |
Pins that the argument actually reaches the install, not just the
resolver |
| 5 | ✅ | npm/pnpm too old or bun: no argument, and a warning naming the
version or the bunfig setting | The only signal a user gets when the
exclusion is impossible |
| 6 | ✅ | A `bunfig.toml` listing a `@vaadin` package silences the
warning; other packages or a comment do not | A bun project that fixed
it must not be nagged; a fake match must not hide a real problem |
| 7 | ✅ | With Vaadin configured to `0` and no package manager age: no
argument, no exclusion, no warning | A project that opted out must stay
fully opted out |
| 8 | ✅ | With Vaadin configured to `0` but npm configured with 7 days:
the age applies, so `@vaadin/*` is excluded | The silently blocking case
this PR fixes |
| 9 | ✅ | A package manager age of `0` counts as no age at all | Avoids
arguments and warnings when nothing is blocked |
| 10 | ✅ | List settings are read from an array and from a
comma-separated string; a brace expansion in a list is kept whole; a
null/empty key gives an empty list | Splitting `@acme/{ui,core}` would
produce two broken patterns |
| 11 | ❗ **gap** | `npmSupportsMinReleaseAgeExclude` /
`pnpmSupportsMinimumReleaseAgeExclude` comparing a real reported version
against 11.17.0 / 10.17.0 | A wrong threshold would pass an unknown
argument to an old tool; callers only mock these |

-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npm_excludesVaadinPackages`
— 1
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_pnpm_excludesVaadinPackagesAsAList`
— 2
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_configuredPatterns_areKept`
— 3
-
`TaskRunPnpmInstallTest.runPnpmInstall_excludesVaadinPackagesFromTheMinimumAge`
— 4
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npmTooOld_warnsInsteadOfExcluding`
— 5
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_pnpmTooOld_warnsInsteadOfExcluding`
— 5
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bun_warnsInsteadOfExcluding`
— 5
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bunfigListsThePackages_noWarning`
— 6
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bunfigListsOtherPackages_warns`
— 6
-
`TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_zeroConfigured_noArgumentAndNoAge`
— 7, 9
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_noAgeApplies_noArgumentOrWarning`
— 7
-
`TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_zeroConfiguredWithNpmrcValue_ageStillApplies`
— 8
-
`TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npmrcValue_isStillExcludedFrom`
— 8
-
`TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_npmrcValueOfZero_noAgeApplies`
— 9
-
`FrontendToolsTest.getConfiguredSettingValues_listAndCommaSeparatedValue_areRead`
— 10
-
`FrontendToolsTest.getConfiguredSettingValues_braceExpansionInAList_isKeptTogether`
— 10
- `FrontendToolsTest.getConfiguredSettingValues_keyWithoutValue_isEmpty`
— 10

Left untested on purpose: the exact wording of the warning (only the key
facts are asserted), and the unreadable-`bunfig.toml` path, which just
falls back to warning.

---------

Co-authored-by: totally-not-ai[bot] <290682512+totally-not-ai[bot]@users.noreply.github.com>
Co-authored-by: Artur Signell <artur@vaadin.com>
@vaadin-bot

Copy link
Copy Markdown
Collaborator Author

This PR is eligible for auto-merging policy, so it has been approved automatically. If there are pending conditions, auto merge (with 'squash' method) has been enabled for this PR [Message is sent from bot]

@vaadin-bot
vaadin-bot enabled auto-merge (squash) September 14, 2026 10:16
@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown
Contributor

Test Results

 1 439 files  ±0   1 523 suites  ±0   1h 31m 49s ⏱️ + 1m 17s
12 046 tests ±0  11 978 ✅ ±0  68 💤 ±0  0 ❌ ±0 
12 364 runs  ±0  12 296 ✅ ±0  68 💤 ±0  0 ❌ ±0 

Results for commit bdee890. ± Comparison against base commit c6a545d.

@vaadin-bot
vaadin-bot merged commit 361f4ae into 25.3 Sep 14, 2026
42 checks passed
@vaadin-bot
vaadin-bot deleted the cherry-pick-25620-to-25.3-1789380237224 branch September 14, 2026 10:23
sissbruecker pushed a commit to vaadin/flow-components that referenced this pull request Sep 15, 2026
Removes the `@NpmPackage` 24h gate workflow
(`.github/workflows/npm-package-gate.yml`) from 25.3. Same change as
#10118 on `main`.

## Why

The gate blocked every PR that added an `@NpmPackage` version for 24
hours, because `vaadin.npm.minimumFrontendPackageAgeDays` defaults to
`1` and a freshly published `@vaadin` package would otherwise break the
snapshot builds of downstream projects.

vaadin/flow#25620 ("exclude `@vaadin` packages from the minimum frontend
package age") removes that reason: the minimum age no longer applies to
`@vaadin` packages.

## ⚠️ Merge order

The cherry-pick of that fix to flow 25.3 — vaadin/flow#25702 — **is
still open at the time of writing**. Please merge this PR only after
vaadin/flow#25702 has landed, otherwise 25.3 loses the gate while flow
25.3 still enforces the minimum age for `@vaadin` packages.

## Scope

The gate is intentionally kept on **25.2**, which does not get the
exclusion.

## Risk

Low, CI-only. The webjar/`@NpmPackage` update PRs (e.g. `chore: Update
NpmPackages Webjars versions (25.3)`) stop being blocked and
auto-approved after 24h — they now follow the normal review and merge
flow. Nothing in the build or in any component changes. Reverting is a
single-file revert.

## How to test

Open or push a PR against 25.3 that adds an `@NpmPackage` version and
check that no `CHANGES_REQUESTED` review from the review bot appears and
no "NpmPackage 24h gate" workflow run is started.

Co-authored-by: totally-not-ai[bot] <290682512+totally-not-ai[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants