feat: exclude @vaadin packages from the minimum frontend package age (#25620) (CP: 25.3) - #25702
Merged
Merged
Conversation
…25620) ## Summary The minimum frontend package age blocks packages that were published very recently. Because the `@vaadin` packages are pinned to the platform version, a build started right after a Vaadin release had no older version to fall back to and failed. Vaadin now tells the package manager to exempt `@vaadin/*` from that check, and warns when the package manager cannot do it. ## What changed **Behavior change:** every build that runs with a minimum frontend package age now gets extra install arguments, and some builds get a new warning. Nothing is added when no age applies. - **npm 11.17.0 and newer:** `--min-release-age-exclude=@vaadin/*` is passed. It exempts the matching packages from both `--min-release-age` and `--before`. - **pnpm 10.17.0 and newer:** `--config.minimum-release-age-exclude=@vaadin/*` is passed. When there is a single pattern it is passed twice, because pnpm reads the setting as a list only when the argument occurs more than once, and pnpm 11 excludes *every* package when the value is a plain string. - **Patterns already configured in `.npmrc` / pnpm config are kept.** A command line value replaces the configured list instead of adding to it, so Vaadin reads the configured patterns and passes them along with `@vaadin/*`. Without this, a project that excludes its own scope silently lost that exclusion. - **bun, older npm, older pnpm:** nothing can be passed, so the build is warned that an install during the first day after a Vaadin release may fail. The warning names the remedy for the package manager in use — upgrade npm to 11.17.0 (first shipped with Node.js 24.19.0), upgrade pnpm to 10.17.0, or, for bun, list the `@vaadin` packages one by one in `minimumReleaseAgeExcludes` in a `bunfig.toml`, since bun matches exact names only. - **bun without a warning:** the project `bunfig.toml` is now read, and the warning is skipped when a `@vaadin` package is an actual value of `minimumReleaseAgeExcludes`. A commented-out line or an unrelated mention is not enough. - **`minimumFrontendPackageAgeDays = 0`:** Vaadin still passes no age argument, but an age that npm or pnpm resolves from its own configuration still applies to the install. That age is now reported as applying, so the `@vaadin` packages are excluded from it instead of being blocked silently. When the package manager itself resolves an age of `0`, nothing applies and nothing is excluded or warned about. - Reading a list-valued setting no longer splits list entries on commas. Only a comma-separated string value is split, because a list entry is complete on its own and may contain a comma of its own in a brace expansion such as `@acme/{ui,core}`. - Javadoc for `minimumFrontendPackageAgeDays` in `Options`, `InitParameters`, `BuildFrontendMojo` and `BuildDevBundleMojo` now documents the exclusion and the required npm/Node.js/pnpm versions. No public or protected API changed. The new methods and the internal `resolveMinimumFrontendPackageAge` rename are package-private. ## Use case A team builds their app with bun, and CI runs a few minutes after a Vaadin release. The install fails because the freshly published `@vaadin` packages are younger than the minimum age, and bun cannot take an exclusion from the command line. The build log now tells them what to do: add the packages they depend on to a `bunfig.toml` next to `package.json`. ```toml [install] minimumReleaseAgeExcludes = ["@vaadin/react-components"] ``` After that the install succeeds, and Vaadin stops printing the warning on every build. ## Test summary | # | Status | What the test verifies | Why it matters | |---|--------|------------------------|----------------| | 1 | ✅ | npm gets `--min-release-age-exclude=@vaadin/*` and no warning | Core fix: a build right after a release must not be blocked | | 2 | ✅ | pnpm gets `--config.minimum-release-age-exclude=@vaadin/*` twice | A single occurrence makes pnpm 11 exclude every package, turning the age check off | | 3 | ✅ | Patterns configured in the package manager are passed along with `@vaadin/*` | A command line value replaces them, so a project would silently lose its own exclusion | | 4 | ✅ | A real pnpm install command contains the exclude argument | Pins that the argument actually reaches the install, not just the resolver | | 5 | ✅ | npm/pnpm too old or bun: no argument, and a warning naming the version or the bunfig setting | The only signal a user gets when the exclusion is impossible | | 6 | ✅ | A `bunfig.toml` listing a `@vaadin` package silences the warning; other packages or a comment do not | A bun project that fixed it must not be nagged; a fake match must not hide a real problem | | 7 | ✅ | With Vaadin configured to `0` and no package manager age: no argument, no exclusion, no warning | A project that opted out must stay fully opted out | | 8 | ✅ | With Vaadin configured to `0` but npm configured with 7 days: the age applies, so `@vaadin/*` is excluded | The silently blocking case this PR fixes | | 9 | ✅ | A package manager age of `0` counts as no age at all | Avoids arguments and warnings when nothing is blocked | | 10 | ✅ | List settings are read from an array and from a comma-separated string; a brace expansion in a list is kept whole; a null/empty key gives an empty list | Splitting `@acme/{ui,core}` would produce two broken patterns | | 11 | ❗ **gap** | `npmSupportsMinReleaseAgeExclude` / `pnpmSupportsMinimumReleaseAgeExclude` comparing a real reported version against 11.17.0 / 10.17.0 | A wrong threshold would pass an unknown argument to an old tool; callers only mock these | - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npm_excludesVaadinPackages` — 1 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_pnpm_excludesVaadinPackagesAsAList` — 2 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_configuredPatterns_areKept` — 3 - `TaskRunPnpmInstallTest.runPnpmInstall_excludesVaadinPackagesFromTheMinimumAge` — 4 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npmTooOld_warnsInsteadOfExcluding` — 5 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_pnpmTooOld_warnsInsteadOfExcluding` — 5 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bun_warnsInsteadOfExcluding` — 5 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bunfigListsThePackages_noWarning` — 6 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_bunfigListsOtherPackages_warns` — 6 - `TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_zeroConfigured_noArgumentAndNoAge` — 7, 9 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_noAgeApplies_noArgumentOrWarning` — 7 - `TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_zeroConfiguredWithNpmrcValue_ageStillApplies` — 8 - `TaskRunNpmInstallTest.minimumFrontendPackageAgeExclude_npmrcValue_isStillExcludedFrom` — 8 - `TaskRunNpmInstallTest.resolveMinimumFrontendPackageAge_npmrcValueOfZero_noAgeApplies` — 9 - `FrontendToolsTest.getConfiguredSettingValues_listAndCommaSeparatedValue_areRead` — 10 - `FrontendToolsTest.getConfiguredSettingValues_braceExpansionInAList_isKeptTogether` — 10 - `FrontendToolsTest.getConfiguredSettingValues_keyWithoutValue_isEmpty` — 10 Left untested on purpose: the exact wording of the warning (only the key facts are asserted), and the unreadable-`bunfig.toml` path, which just falls back to warning. --------- Co-authored-by: totally-not-ai[bot] <290682512+totally-not-ai[bot]@users.noreply.github.com> Co-authored-by: Artur Signell <artur@vaadin.com>
This was referenced Sep 14, 2026
Collaborator
Author
|
This PR is eligible for auto-merging policy, so it has been approved automatically. If there are pending conditions, auto merge (with 'squash' method) has been enabled for this PR [Message is sent from bot] |
vaadin-review-bot
approved these changes
Sep 14, 2026
vaadin-bot
enabled auto-merge (squash)
September 14, 2026 10:16
|
Contributor
sissbruecker
pushed a commit
to vaadin/flow-components
that referenced
this pull request
Sep 15, 2026
Removes the `@NpmPackage` 24h gate workflow (`.github/workflows/npm-package-gate.yml`) from 25.3. Same change as #10118 on `main`. ## Why The gate blocked every PR that added an `@NpmPackage` version for 24 hours, because `vaadin.npm.minimumFrontendPackageAgeDays` defaults to `1` and a freshly published `@vaadin` package would otherwise break the snapshot builds of downstream projects. vaadin/flow#25620 ("exclude `@vaadin` packages from the minimum frontend package age") removes that reason: the minimum age no longer applies to `@vaadin` packages. ##⚠️ Merge order The cherry-pick of that fix to flow 25.3 — vaadin/flow#25702 — **is still open at the time of writing**. Please merge this PR only after vaadin/flow#25702 has landed, otherwise 25.3 loses the gate while flow 25.3 still enforces the minimum age for `@vaadin` packages. ## Scope The gate is intentionally kept on **25.2**, which does not get the exclusion. ## Risk Low, CI-only. The webjar/`@NpmPackage` update PRs (e.g. `chore: Update NpmPackages Webjars versions (25.3)`) stop being blocked and auto-approved after 24h — they now follow the normal review and merge flow. Nothing in the build or in any component changes. Reverting is a single-file revert. ## How to test Open or push a PR against 25.3 that adds an `@NpmPackage` version and check that no `CHANGES_REQUESTED` review from the review bot appears and no "NpmPackage 24h gate" workflow run is started. Co-authored-by: totally-not-ai[bot] <290682512+totally-not-ai[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR cherry-picks changes from the original PR #25620 to branch 25.3.
Original PR description