From bcd565d0031b77138fe0f3e36638a166b686920f Mon Sep 17 00:00:00 2001 From: Pawan Patel Date: Tue, 2 Jun 2026 14:29:47 -0400 Subject: [PATCH 1/6] Initial setup add changesets, versioning commented out github action --- .github/workflows/release.yml | 52 +++ package/.changeset/config.json | 11 + package/package.json | 26 +- package/pnpm-lock.yaml | 786 +++++++++++++++++++++++++++++++++ package/src/cli.ts | 6 +- package/tsconfig.build.json | 4 +- 6 files changed, 878 insertions(+), 7 deletions(-) create mode 100644 .github/workflows/release.yml create mode 100644 package/.changeset/config.json diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..6963a4b --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,52 @@ +# name: Release + +# on: +# push: +# branches: +# - main + +# permissions: +# contents: write +# id-token: write +# pull-requests: write + +# jobs: +# release: +# name: Version or publish npm package +# runs-on: ubuntu-latest + +# steps: +# - name: Checkout repo +# uses: actions/checkout@v4 + +# - name: Setup Node.js +# uses: actions/setup-node@v4 +# with: +# node-version: '20' +# registry-url: 'https://registry.npmjs.org' +# cache: pnpm +# cache-dependency-path: package/pnpm-lock.yaml + +# - name: Enable pnpm +# run: | +# corepack enable +# corepack prepare pnpm@10.28.0 --activate + +# - name: Update npm for OIDC publishing +# run: npm install --global npm@latest + +# - name: Install dependencies +# working-directory: package +# run: pnpm install --frozen-lockfile + +# - name: Create release PR or publish +# uses: changesets/action@v1 +# with: +# cwd: package +# publish: pnpm release +# version: pnpm version-packages +# env: +# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} +# # Keep this as a literal empty string. It forces npm OIDC Trusted +# # Publishing instead of falling back to token auth. +# NPM_TOKEN: '' diff --git a/package/.changeset/config.json b/package/.changeset/config.json new file mode 100644 index 0000000..2be13d4 --- /dev/null +++ b/package/.changeset/config.json @@ -0,0 +1,11 @@ +{ + "$schema": "https://unpkg.com/@changesets/config@3.1.1/schema.json", + "changelog": "@changesets/cli/changelog", + "commit": false, + "fixed": [], + "linked": [], + "access": "public", + "baseBranch": "main", + "updateInternalDependencies": "patch", + "ignore": [] +} diff --git a/package/package.json b/package/package.json index e760be1..244d789 100644 --- a/package/package.json +++ b/package/package.json @@ -1,34 +1,50 @@ { "name": "@shopify/shop-cli", "version": "0.1.0", - "description": "Installable CLI for the Shop personal shopping skill", + "description": "Personal shopping CLI for Shop catalog search, checkout, and order workflows", "type": "module", "license": "UNLICENSED", + "private": false, + "homepage": "https://help.shop.app/shop/shopping/personal-agents", "bin": { "shop": "./dist/bin.js" }, "main": "./dist/index.js", "types": "./dist/index.d.ts", "files": [ - "dist" + "dist", + "README.md", + "LICENSE.md" ], + "publishConfig": { + "access": "public", + "registry": "https://registry.npmjs.org" + }, "scripts": { "build": "rm -rf dist && tsc -p tsconfig.build.json && chmod +x dist/bin.js", "shop": "node dist/bin.js", - "test": "rm -rf .test-build && tsc -p tsconfig.test.json && node --test .test-build/tests/*.test.js", + "test": "rm -rf .test-build && tsc -p tsconfig.test.json && cp package.json .test-build/package.json && node --test .test-build/tests/*.test.js", "typecheck": "tsc --noEmit", - "pack:dry": "npm pack --dry-run" + "version-packages": "changeset version", + "release": "pnpm build && pnpm test && changeset publish", + "pack:dry": "pnpm dlx npm@latest pack --dry-run" }, "dependencies": { "commander": "^12.1.0", "keytar": "^7.9.0" }, "devDependencies": { + "@changesets/cli": "^2.31.0", "@types/node": "^22.15.3", "typescript": "^5.8.3" }, "engines": { "node": ">=20" }, - "packageManager": "pnpm@10.28.0" + "packageManager": "pnpm@10.28.0", + "pnpm": { + "onlyBuiltDependencies": [ + "keytar" + ] + } } diff --git a/package/pnpm-lock.yaml b/package/pnpm-lock.yaml index 15d37bf..649cb5b 100644 --- a/package/pnpm-lock.yaml +++ b/package/pnpm-lock.yaml @@ -15,6 +15,9 @@ importers: specifier: ^7.9.0 version: 7.9.0 devDependencies: + '@changesets/cli': + specifier: ^2.31.0 + version: 2.31.0(@types/node@22.19.19) '@types/node': specifier: ^22.15.3 version: 22.19.19 @@ -24,18 +27,136 @@ importers: packages: + '@babel/runtime@7.29.7': + resolution: {integrity: sha512-Nq8OhGWiZIZGV6hLHoyAKLLcJihP/xFeBMGJoUrxTX2psI8dCifzLhZISFb+VWS3wFMRDmCGw5R+dOySCqPLhw==} + engines: {node: '>=6.9.0'} + + '@changesets/apply-release-plan@7.1.1': + resolution: {integrity: sha512-9qPCm/rLx/xoOFXIHGB229+4GOL76S4MC+7tyOuTsR6+1jYlfFDQORdvwR5hDA6y4FL2BPt3qpbcQIS+dW85LA==} + + '@changesets/assemble-release-plan@6.0.10': + resolution: {integrity: sha512-rSDcqdJ9KbVyjpBIuCidhvZNIiVt1XaIYp73ycVQRIA5n/j6wQaEk0ChRLMUQ1vkxZe51PTQ9OIhbg6HQMW45A==} + + '@changesets/changelog-git@0.2.1': + resolution: {integrity: sha512-x/xEleCFLH28c3bQeQIyeZf8lFXyDFVn1SgcBiR2Tw/r4IAWlk1fzxCEZ6NxQAjF2Nwtczoen3OA2qR+UawQ8Q==} + + '@changesets/cli@2.31.0': + resolution: {integrity: sha512-AhI4enNTgHu2IZr6K4WZyf0EPch4XVMn1yOMFmCD9gsfBGqMYaHXls5HyDv6/CL5axVQABz68eG30eCtbr2wFg==} + hasBin: true + + '@changesets/config@3.1.4': + resolution: {integrity: sha512-pf0bvD/v6WI2cRlZ6hzpjtZdSlXDXMAJ+Iz7xfFzV4ZxJ8OGGAON+1qYc99ZPrijnt4xp3VGG7eNvAOGS24V1Q==} + + '@changesets/errors@0.2.0': + resolution: {integrity: sha512-6BLOQUscTpZeGljvyQXlWOItQyU71kCdGz7Pi8H8zdw6BI0g3m43iL4xKUVPWtG+qrrL9DTjpdn8eYuCQSRpow==} + + '@changesets/get-dependents-graph@2.1.4': + resolution: {integrity: sha512-ZsS00x6WvmHq3sQv8oCMwL0f/z3wbXCVuSVTJwCnnmbC/iBdNJGFx1EcbMG4PC6sXRyH69liM4A2WKXzn/kRPg==} + + '@changesets/get-release-plan@4.0.16': + resolution: {integrity: sha512-2K5Om6CrMPm45rtvckfzWo7e9jOVCKLCnXia5eUPaURH7/LWzri7pK1TycdzAuAtehLkW7VPbWLCSExTHmiI6g==} + + '@changesets/get-version-range-type@0.4.0': + resolution: {integrity: sha512-hwawtob9DryoGTpixy1D3ZXbGgJu1Rhr+ySH2PvTLHvkZuQ7sRT4oQwMh0hbqZH1weAooedEjRsbrWcGLCeyVQ==} + + '@changesets/git@3.0.4': + resolution: {integrity: sha512-BXANzRFkX+XcC1q/d27NKvlJ1yf7PSAgi8JG6dt8EfbHFHi4neau7mufcSca5zRhwOL8j9s6EqsxmT+s+/E6Sw==} + + '@changesets/logger@0.1.1': + resolution: {integrity: sha512-OQtR36ZlnuTxKqoW4Sv6x5YIhOmClRd5pWsjZsddYxpWs517R0HkyiefQPIytCVh4ZcC5x9XaG8KTdd5iRQUfg==} + + '@changesets/parse@0.4.3': + resolution: {integrity: sha512-ZDmNc53+dXdWEv7fqIUSgRQOLYoUom5Z40gmLgmATmYR9NbL6FJJHwakcCpzaeCy+1D0m0n7mT4jj2B/MQPl7A==} + + '@changesets/pre@2.0.2': + resolution: {integrity: sha512-HaL/gEyFVvkf9KFg6484wR9s0qjAXlZ8qWPDkTyKF6+zqjBe/I2mygg3MbpZ++hdi0ToqNUF8cjj7fBy0dg8Ug==} + + '@changesets/read@0.6.7': + resolution: {integrity: sha512-D1G4AUYGrBEk8vj8MGwf75k9GpN6XL3wg8i42P2jZZwFLXnlr2Pn7r9yuQNbaMCarP7ZQWNJbV6XLeysAIMhTA==} + + '@changesets/should-skip-package@0.1.2': + resolution: {integrity: sha512-qAK/WrqWLNCP22UDdBTMPH5f41elVDlsNyat180A33dWxuUDyNpg6fPi/FyTZwRriVjg0L8gnjJn2F9XAoF0qw==} + + '@changesets/types@4.1.0': + resolution: {integrity: sha512-LDQvVDv5Kb50ny2s25Fhm3d9QSZimsoUGBsUioj6MC3qbMUCuC8GPIvk/M6IvXx3lYhAs0lwWUQLb+VIEUCECw==} + + '@changesets/types@6.1.0': + resolution: {integrity: sha512-rKQcJ+o1nKNgeoYRHKOS07tAMNd3YSN0uHaJOZYjBAgxfV7TUE7JE+z4BzZdQwb5hKaYbayKN5KrYV7ODb2rAA==} + + '@changesets/write@0.4.0': + resolution: {integrity: sha512-CdTLvIOPiCNuH71pyDu3rA+Q0n65cmAbXnwWH84rKGiFumFzkmHNT8KHTMEchcxN+Kl8I54xGUhJ7l3E7X396Q==} + + '@inquirer/external-editor@1.0.3': + resolution: {integrity: sha512-RWbSrDiYmO4LbejWY7ttpxczuwQyZLBUyygsA9Nsv95hpzUWwnNTVQmAq3xuh7vNwCp07UTmE5i11XAEExx4RA==} + engines: {node: '>=18'} + peerDependencies: + '@types/node': '>=18' + peerDependenciesMeta: + '@types/node': + optional: true + + '@manypkg/find-root@1.1.0': + resolution: {integrity: sha512-mki5uBvhHzO8kYYix/WRy2WX8S3B5wdVSc9D6KcU5lQNglP2yt58/VfLuAK49glRXChosY8ap2oJ1qgma3GUVA==} + + '@manypkg/get-packages@1.1.3': + resolution: {integrity: sha512-fo+QhuU3qE/2TQMQmbVMqaQ6EWbMhi4ABWP+O4AM1NqPBuy0OrApV5LO6BrrgnhtAHS2NH6RrVk9OL181tTi8A==} + + '@nodelib/fs.scandir@2.1.5': + resolution: {integrity: sha512-vq24Bq3ym5HEQm2NKCr3yXDwjc7vTsEThRDnkp2DK9p1uqLR+DHurm/NOTo0KG7HYHU7eppKZj3MyqYuMBf62g==} + engines: {node: '>= 8'} + + '@nodelib/fs.stat@2.0.5': + resolution: {integrity: sha512-RkhPPp2zrqDAQA/2jNhnztcPAlv64XdhIp7a7454A5ovI7Bukxgt7MX7udwAu3zg1DcpPU0rz3VV1SeaqvY4+A==} + engines: {node: '>= 8'} + + '@nodelib/fs.walk@1.2.8': + resolution: {integrity: sha512-oGB+UxlgWcgQkgwo8GcEGwemoTFt3FIO9ababBmaGwXIoBKZ+GTy0pP185beGg7Llih/NSHSV2XAs1lnznocSg==} + engines: {node: '>= 8'} + + '@types/node@12.20.55': + resolution: {integrity: sha512-J8xLz7q2OFulZ2cyGTLE1TbbZcjpno7FaN6zdJNrgAdrJ+DZzh/uFR6YrTb4C+nXakvud8Q4+rbhoIWlYQbUFQ==} + '@types/node@22.19.19': resolution: {integrity: sha512-dyh/xO2Fh5bYrfWaaqGrRQQGkNdmYw6AmaAUvYeUMNTWQtvb796ikLdmTchRmOlOiIJ1TDXfWgVx1QkUlQ6Hew==} + ansi-colors@4.1.3: + resolution: {integrity: sha512-/6w/C21Pm1A7aZitlI5Ni/2J6FFQN8i1Cvz3kHABAAbw93v/NlvKdVOqz7CCWz/3iv/JplRSEEZ83XION15ovw==} + engines: {node: '>=6'} + + ansi-regex@5.0.1: + resolution: {integrity: sha512-quJQXlTSUGL2LH9SUXo8VwsY4soanhgo6LNSm84E1LBcE8s3O0wpdiRzyR9z/ZZJMlMWv37qOOb9pdJlMUEKFQ==} + engines: {node: '>=8'} + + argparse@1.0.10: + resolution: {integrity: sha512-o5Roy6tNG4SL/FOkCAN6RzjiakZS25RLYFrcMttJqbdd8BWrnA+fGz57iN5Pb06pvBGvl5gQ0B48dJlslXvoTg==} + + argparse@2.0.1: + resolution: {integrity: sha512-8+9WqebbFzpX9OR+Wa6O29asIogeRMzcGtAINdpMHHyAg10f05aSFVBbcEqGf/PXw1EjAZ+q2/bEBg3DvurK3Q==} + + array-union@2.1.0: + resolution: {integrity: sha512-HGyxoOTYUyCM6stUe6EJgnd4EoewAI7zMdfqO+kGjnlZmBDz/cR5pf8r/cR4Wq60sL/p0IkcjUEEPwS3GFrIyw==} + engines: {node: '>=8'} + base64-js@1.5.1: resolution: {integrity: sha512-AKpaYlHn8t4SVbOHCy+b5+KKgvR4vrsD8vbvrbiQJps7fKDTkjkDry6ji0rUJjC0kzbNePLwzxq8iypo41qeWA==} + better-path-resolve@1.0.0: + resolution: {integrity: sha512-pbnl5XzGBdrFU/wT4jqmJVPn2B6UHPBOhzMQkY/SPUPB6QtUXtmBHBIwCbXJol93mOpGMnQyP/+BB19q04xj7g==} + engines: {node: '>=4'} + bl@4.1.0: resolution: {integrity: sha512-1W07cM9gS6DcLperZfFSj+bWLtaPGSOHWhPiGzXmvVJbRLdG82sH/Kn8EtW1VqWVA54AKf2h5k5BbnIbwF3h6w==} + braces@3.0.3: + resolution: {integrity: sha512-yQbXgO/OSZVD2IsiLlro+7Hf6Q18EJrKSEsdoMzKePKXct3gvD8oLcOQdIzGupr5Fj+EDe8gO/lxc1BzfMpxvA==} + engines: {node: '>=8'} + buffer@5.7.1: resolution: {integrity: sha512-EHcyIPBQ4BSGlvjB16k5KgAJ27CIsHY/2JBmCRReo48y9rQ3MaUzWX3KVlBa4U7MyX02HdVj0K7C3WaB3ju7FQ==} + chardet@2.1.1: + resolution: {integrity: sha512-PsezH1rqdV9VvyNhxxOW32/d75r01NY7TQCmOqomRo15ZSOKbpTFVsfjghxo6JloQUCGnH4k1LGu0R4yCLlWQQ==} + chownr@1.1.4: resolution: {integrity: sha512-jJ0bqzaylmJtVnNgzTeSOs8DPavpbYgEr/b0YL8/2GO3xJEhInFmhKMUnEJQjZumK7KXGFhUy89PrsJWlakBVg==} @@ -43,6 +164,10 @@ packages: resolution: {integrity: sha512-Vw8qHK3bZM9y/P10u3Vib8o/DdkvA2OtPtZvD871QKjy74Wj1WSKFILMPRPSdUSx5RFK1arlJzEtA4PkFgnbuA==} engines: {node: '>=18'} + cross-spawn@7.0.6: + resolution: {integrity: sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA==} + engines: {node: '>= 8'} + decompress-response@6.0.0: resolution: {integrity: sha512-aW35yZM6Bb/4oJlZncMH2LCoZtJXTRxES17vE3hoRiowU2kWHaJKFkSBDnDR+cm9J+9QhXmREyIfv0pji9ejCQ==} engines: {node: '>=10'} @@ -51,35 +176,150 @@ packages: resolution: {integrity: sha512-LOHxIOaPYdHlJRtCQfDIVZtfw/ufM8+rVj649RIHzcm/vGwQRXFt6OPqIFWsm2XEMrNIEtWR64sY1LEKD2vAOA==} engines: {node: '>=4.0.0'} + detect-indent@6.1.0: + resolution: {integrity: sha512-reYkTUJAZb9gUuZ2RvVCNhVHdg62RHnJ7WJl8ftMi4diZ6NWlciOzQN88pUhSELEwflJht4oQDv0F0BMlwaYtA==} + engines: {node: '>=8'} + detect-libc@2.1.2: resolution: {integrity: sha512-Btj2BOOO83o3WyH59e8MgXsxEQVcarkUOpEYrubB0urwnN10yQ364rsiByU11nZlqWYZm05i/of7io4mzihBtQ==} engines: {node: '>=8'} + dir-glob@3.0.1: + resolution: {integrity: sha512-WkrWp9GR4KXfKGYzOLmTuGVi1UWFfws377n9cc55/tb6DuqyF6pcQ5AbiHEshaDpY9v6oaSr2XCDidGmMwdzIA==} + engines: {node: '>=8'} + end-of-stream@1.4.5: resolution: {integrity: sha512-ooEGc6HP26xXq/N+GCGOT0JKCLDGrq2bQUZrQ7gyrJiZANJ/8YDTxTpQBXGMn+WbIQXNVpyWymm7KYVICQnyOg==} + enquirer@2.4.1: + resolution: {integrity: sha512-rRqJg/6gd538VHvR3PSrdRBb/1Vy2YfzHqzvbhGIQpDRKIa4FgV/54b5Q1xYSxOOwKvjXweS26E0Q+nAMwp2pQ==} + engines: {node: '>=8.6'} + + esprima@4.0.1: + resolution: {integrity: sha512-eGuFFw7Upda+g4p+QHvnW0RyTX/SVeJBDM/gCtMARO0cLuT2HcEKnTPvhjV6aGeqrCB/sbNop0Kszm0jsaWU4A==} + engines: {node: '>=4'} + hasBin: true + expand-template@2.0.3: resolution: {integrity: sha512-XYfuKMvj4O35f/pOXLObndIRvyQ+/+6AhODh+OKWj9S9498pHHn/IMszH+gt0fBCRWMNfk1ZSp5x3AifmnI2vg==} engines: {node: '>=6'} + extendable-error@0.1.7: + resolution: {integrity: sha512-UOiS2in6/Q0FK0R0q6UY9vYpQ21mr/Qn1KOnte7vsACuNJf514WvCCUHSRCPcgjPT2bAhNIJdlE6bVap1GKmeg==} + + fast-glob@3.3.3: + resolution: {integrity: sha512-7MptL8U0cqcFdzIzwOTHoilX9x5BrNqye7Z/LuC7kCMRio1EMSyqRK3BEAUD7sXRq4iT4AzTVuZdhgQ2TCvYLg==} + engines: {node: '>=8.6.0'} + + fastq@1.20.1: + resolution: {integrity: sha512-GGToxJ/w1x32s/D2EKND7kTil4n8OVk/9mycTc4VDza13lOvpUZTGX3mFSCtV9ksdGBVzvsyAVLM6mHFThxXxw==} + + fill-range@7.1.1: + resolution: {integrity: sha512-YsGpe3WHLK8ZYi4tWDg2Jy3ebRz2rXowDxnld4bkQB00cc/1Zw9AWnC0i9ztDJitivtQvaI9KaLyKrc+hBW0yg==} + engines: {node: '>=8'} + + find-up@4.1.0: + resolution: {integrity: sha512-PpOwAdQ/YlXQ2vj8a3h8IipDuYRi3wceVQQGYWxNINccq40Anw7BlsEXCMbt1Zt+OLA6Fq9suIpIWD0OsnISlw==} + engines: {node: '>=8'} + fs-constants@1.0.0: resolution: {integrity: sha512-y6OAwoSIf7FyjMIv94u+b5rdheZEjzR63GTyZJm5qh4Bi+2YgwLCcI/fPFZkL5PSixOt6ZNKm+w+Hfp/Bciwow==} + fs-extra@7.0.1: + resolution: {integrity: sha512-YJDaCJZEnBmcbw13fvdAM9AwNOJwOzrE4pqMqBq5nFiEqXUqHwlK4B+3pUw6JNvfSPtX05xFHtYy/1ni01eGCw==} + engines: {node: '>=6 <7 || >=8'} + + fs-extra@8.1.0: + resolution: {integrity: sha512-yhlQgA6mnOJUKOsRUFsgJdQCvkKhcz8tlZG5HBQfReYZy46OwLcY+Zia0mtdHsOo9y/hP+CxMN0TU9QxoOtG4g==} + engines: {node: '>=6 <7 || >=8'} + github-from-package@0.0.0: resolution: {integrity: sha512-SyHy3T1v2NUXn29OsWdxmK6RwHD+vkj3v8en8AOBZ1wBQ/hCAQ5bAQTD02kW4W9tUp/3Qh6J8r9EvntiyCmOOw==} + glob-parent@5.1.2: + resolution: {integrity: sha512-AOIgSQCepiJYwP3ARnGx+5VnTu2HBYdzbGP45eLw1vr3zB3vZLeyed1sC9hnbcOc9/SrMyM5RPQrkGz4aS9Zow==} + engines: {node: '>= 6'} + + globby@11.1.0: + resolution: {integrity: sha512-jhIXaOzy1sb8IyocaruWSn1TjmnBVs8Ayhcy83rmxNJ8q2uWKCAj3CnJY+KpGSXCueAPc0i05kVvVKtP1t9S3g==} + engines: {node: '>=10'} + + graceful-fs@4.2.11: + resolution: {integrity: sha512-RbJ5/jmFcNNCcDV5o9eTnBLJ/HszWV0P73bc+Ff4nS/rJj+YaS6IGyiOL0VoBYX+l1Wrl3k63h/KrH+nhJ0XvQ==} + + human-id@4.1.3: + resolution: {integrity: sha512-tsYlhAYpjCKa//8rXZ9DqKEawhPoSytweBC2eNvcaDK+57RZLHGqNs3PZTQO6yekLFSuvA6AlnAfrw1uBvtb+Q==} + hasBin: true + + iconv-lite@0.7.2: + resolution: {integrity: sha512-im9DjEDQ55s9fL4EYzOAv0yMqmMBSZp6G0VvFyTMPKWxiSBHUj9NW/qqLmXUwXrrM7AvqSlTCfvqRb0cM8yYqw==} + engines: {node: '>=0.10.0'} + ieee754@1.2.1: resolution: {integrity: sha512-dcyqhDvX1C46lXZcVqCpK+FtMRQVdIMN6/Df5js2zouUsqG7I6sFxitIC+7KYK29KdXOLHdu9zL4sFnoVQnqaA==} + ignore@5.3.2: + resolution: {integrity: sha512-hsBTNUqQTDwkWtcdYI2i06Y/nUBEsNEDJKjWdigLvegy8kDuJAS8uRlpkkcQpyEXL0Z/pjDy5HBmMjRCJ2gq+g==} + engines: {node: '>= 4'} + inherits@2.0.4: resolution: {integrity: sha512-k/vGaX4/Yla3WzyMCvTQOXYeIHvqOKtnqBduzTHpzpQZzAskKMhZ2K+EnBiSM9zGSoIFeMpXKxa4dYeZIQqewQ==} ini@1.3.8: resolution: {integrity: sha512-JV/yugV2uzW5iMRSiZAyDtQd+nxtUnjeLt0acNdw98kKLrvuRVyB80tsREOE7yvGVgalhZ6RNXCmEHkUKBKxew==} + is-extglob@2.1.1: + resolution: {integrity: sha512-SbKbANkN603Vi4jEZv49LeVJMn4yGwsbzZworEoyEiutsN3nJYdbO36zfhGJ6QEDpOZIFkDtnq5JRxmvl3jsoQ==} + engines: {node: '>=0.10.0'} + + is-glob@4.0.3: + resolution: {integrity: sha512-xelSayHH36ZgE7ZWhli7pW34hNbNl8Ojv5KVmkJD4hBdD3th8Tfk9vYasLM+mXWOZhFkgZfxhLSnrwRr4elSSg==} + engines: {node: '>=0.10.0'} + + is-number@7.0.0: + resolution: {integrity: sha512-41Cifkg6e8TylSpdtTpeLVMqvSBEVzTttHvERD741+pnZ8ANv0004MRL43QKPDlK9cGvNp6NZWZUBlbGXYxxng==} + engines: {node: '>=0.12.0'} + + is-subdir@1.2.0: + resolution: {integrity: sha512-2AT6j+gXe/1ueqbW6fLZJiIw3F8iXGJtt0yDrZaBhAZEG1raiTxKWU+IPqMCzQAXOUCKdA4UDMgacKH25XG2Cw==} + engines: {node: '>=4'} + + is-windows@1.0.2: + resolution: {integrity: sha512-eXK1UInq2bPmjyX6e3VHIzMLobc4J94i4AWn+Hpq3OU5KkrRC96OAcR3PRJ/pGu6m8TRnBHP9dkXQVsT/COVIA==} + engines: {node: '>=0.10.0'} + + isexe@2.0.0: + resolution: {integrity: sha512-RHxMLp9lnKHGHRng9QFhRCMbYAcVpn69smSGcq3f36xjgVVWThj4qqLbTLlq7Ssj8B+fIQ1EuCEGI2lKsyQeIw==} + + js-yaml@3.14.2: + resolution: {integrity: sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==} + hasBin: true + + js-yaml@4.1.1: + resolution: {integrity: sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==} + hasBin: true + + jsonfile@4.0.0: + resolution: {integrity: sha512-m6F1R3z8jjlf2imQHS2Qez5sjKWQzbuuhuJ/FKYFRZvPE3PuHcSMVZzfsLhGVOkfd20obL5SWEBew5ShlquNxg==} + keytar@7.9.0: resolution: {integrity: sha512-VPD8mtVtm5JNtA2AErl6Chp06JBfy7diFQ7TQQhdpWOl6MrCRB+eRbvAZUsbGQS9kiMq0coJsy0W0vHpDCkWsQ==} + locate-path@5.0.0: + resolution: {integrity: sha512-t7hw9pI+WvuwNJXwk5zVHpyhIqzg2qTlklJOf0mVxGSbe3Fp2VieZcduNYjaLDoy6p9uGpQEGWG87WpMKlNq8g==} + engines: {node: '>=8'} + + lodash.startcase@4.4.0: + resolution: {integrity: sha512-+WKqsK294HMSc2jEbNgpHpd0JfIBhp7rEV4aqXWqFr6AlXov+SlcgB1Fv01y2kGe3Gc8nMW7VA0SrGuSkRfIEg==} + + merge2@1.4.1: + resolution: {integrity: sha512-8q7VEgMJW4J8tcfVPy8g09NcQwZdbwFEqhe/WZkoIzjn/3TGDwtOCYtXGxA3O8tPzpczCCDgv+P2P5y00ZJOOg==} + engines: {node: '>= 8'} + + micromatch@4.0.8: + resolution: {integrity: sha512-PXwfBhYu0hBCPw8Dn0E+WDYb7af3dSLVWKi3HGv84IdF4TyFoC0ysxFd0Goxw7nSv4T/PzEJQxsYsEiFCKo2BA==} + engines: {node: '>=8.6'} + mimic-response@3.1.0: resolution: {integrity: sha512-z0yWI+4FDrrweS8Zmt4Ej5HdJmky15+L2e6Wgn3+iK5fWzb6T3fhNFq2+MeTRb064c6Wr4N/wv0DzQTjNzHNGQ==} engines: {node: '>=10'} @@ -90,6 +330,10 @@ packages: mkdirp-classic@0.5.3: resolution: {integrity: sha512-gKLcREMhtuZRwRAfqP3RFW+TK4JqApVBtOIftVgjuABpAtpxhPGaDcfvbhNvD0B8iD1oUr/txX35NjcaY6Ns/A==} + mri@1.2.0: + resolution: {integrity: sha512-tzzskb3bG8LvYGFF/mDTpq3jpI6Q9wc3LEmBaghu+DdCssd1FakN7Bc0hVNmEyGq1bq3RgfkCb3cmQLpNPOroA==} + engines: {node: '>=4'} + napi-build-utils@2.0.0: resolution: {integrity: sha512-GEbrYkbfF7MoNaoh2iGG84Mnf/WZfB0GdGEsM8wz7Expx/LlWf5U8t9nvJKXSp3qr5IsEbK04cBGhol/KwOsWA==} @@ -103,40 +347,148 @@ packages: once@1.4.0: resolution: {integrity: sha512-lNaJgI+2Q5URQBkccEKHTQOPaXdUxnZZElQTZY0MFUAuaEqe1E+Nyvgdz/aIyNi6Z9MzO5dv1H8n58/GELp3+w==} + outdent@0.5.0: + resolution: {integrity: sha512-/jHxFIzoMXdqPzTaCpFzAAWhpkSjZPF4Vsn6jAfNpmbH/ymsmd7Qc6VE9BGn0L6YMj6uwpQLxCECpus4ukKS9Q==} + + p-filter@2.1.0: + resolution: {integrity: sha512-ZBxxZ5sL2HghephhpGAQdoskxplTwr7ICaehZwLIlfL6acuVgZPm8yBNuRAFBGEqtD/hmUeq9eqLg2ys9Xr/yw==} + engines: {node: '>=8'} + + p-limit@2.3.0: + resolution: {integrity: sha512-//88mFWSJx8lxCzwdAABTJL2MyWB12+eIY7MDL2SqLmAkeKU9qxRvWuSyTjm3FUmpBEMuFfckAIqEaVGUDxb6w==} + engines: {node: '>=6'} + + p-locate@4.1.0: + resolution: {integrity: sha512-R79ZZ/0wAxKGu3oYMlz8jy/kbhsNrS7SKZ7PxEHBgJ5+F2mtFW2fK2cOtBh1cHYkQsbzFV7I+EoRKe6Yt0oK7A==} + engines: {node: '>=8'} + + p-map@2.1.0: + resolution: {integrity: sha512-y3b8Kpd8OAN444hxfBbFfj1FY/RjtTd8tzYwhUqNYXx0fXx2iX4maP4Qr6qhIKbQXI02wTLAda4fYUbDagTUFw==} + engines: {node: '>=6'} + + p-try@2.2.0: + resolution: {integrity: sha512-R4nPAVTAU0B9D35/Gk3uJf/7XYbQcyohSKdvAxIRSNghFl4e71hVoGnBNQz9cWaXxO2I10KTC+3jMdvvoKw6dQ==} + engines: {node: '>=6'} + + package-manager-detector@0.2.11: + resolution: {integrity: sha512-BEnLolu+yuz22S56CU1SUKq3XC3PkwD5wv4ikR4MfGvnRVcmzXR9DwSlW2fEamyTPyXHomBJRzgapeuBvRNzJQ==} + + path-exists@4.0.0: + resolution: {integrity: sha512-ak9Qy5Q7jYb2Wwcey5Fpvg2KoAc/ZIhLSLOSBmRmygPsGwkVVt0fZa0qrtMz+m6tJTAHfZQ8FnmB4MG4LWy7/w==} + engines: {node: '>=8'} + + path-key@3.1.1: + resolution: {integrity: sha512-ojmeN0qd+y0jszEtoY48r0Peq5dwMEkIlCOu6Q5f41lfkswXuKtYrhgoTpLnyIcHm24Uhqx+5Tqm2InSwLhE6Q==} + engines: {node: '>=8'} + + path-type@4.0.0: + resolution: {integrity: sha512-gDKb8aZMDeD/tZWs9P6+q0J9Mwkdl6xMV8TjnGP3qJVJ06bdMgkbBlLU8IdfOsIsFz2BW1rNVT3XuNEl8zPAvw==} + engines: {node: '>=8'} + + picocolors@1.1.1: + resolution: {integrity: sha512-xceH2snhtb5M9liqDsmEw56le376mTZkEX/jEb/RxNFyegNul7eNslCXP9FDj/Lcu0X8KEyMceP2ntpaHrDEVA==} + + picomatch@2.3.2: + resolution: {integrity: sha512-V7+vQEJ06Z+c5tSye8S+nHUfI51xoXIXjHQ99cQtKUkQqqO1kO/KCJUfZXuB47h/YBlDhah2H3hdUGXn8ie0oA==} + engines: {node: '>=8.6'} + + pify@4.0.1: + resolution: {integrity: sha512-uB80kBFb/tfd68bVleG9T5GGsGPjJrLAUpR5PZIrhBnIaRTQRjqdJSsIKkOP6OAIFbj7GOrcudc5pNjZ+geV2g==} + engines: {node: '>=6'} + prebuild-install@7.1.3: resolution: {integrity: sha512-8Mf2cbV7x1cXPUILADGI3wuhfqWvtiLA1iclTDbFRZkgRQS0NqsPZphna9V+HyTEadheuPmjaJMsbzKQFOzLug==} engines: {node: '>=10'} deprecated: No longer maintained. Please contact the author of the relevant native addon; alternatives are available. hasBin: true + prettier@2.8.8: + resolution: {integrity: sha512-tdN8qQGvNjw4CHbY+XXk0JgCXn9QiF21a55rBe5LJAU+kDyC4WQn4+awm2Xfk2lQMk5fKup9XgzTZtGkjBdP9Q==} + engines: {node: '>=10.13.0'} + hasBin: true + pump@3.0.4: resolution: {integrity: sha512-VS7sjc6KR7e1ukRFhQSY5LM2uBWAUPiOPa/A3mkKmiMwSmRFUITt0xuj+/lesgnCv+dPIEYlkzrcyXgquIHMcA==} + quansync@0.2.11: + resolution: {integrity: sha512-AifT7QEbW9Nri4tAwR5M/uzpBuqfZf+zwaEM/QkzEjj7NBuFD2rBuy0K3dE+8wltbezDV7JMA0WfnCPYRSYbXA==} + + queue-microtask@1.2.3: + resolution: {integrity: sha512-NuaNSa6flKT5JaSYQzJok04JzTL1CA6aGhv5rfLW3PgqA+M2ChpZQnAC8h8i4ZFkBS8X5RqkDBHA7r4hej3K9A==} + rc@1.2.8: resolution: {integrity: sha512-y3bGgqKj3QBdxLbLkomlohkvsA8gdAiUQlSBJnBhfn+BPxg4bc62d8TcBW15wavDfgexCgccckhcZvywyQYPOw==} hasBin: true + read-yaml-file@1.1.0: + resolution: {integrity: sha512-VIMnQi/Z4HT2Fxuwg5KrY174U1VdUIASQVWXXyqtNRtxSr9IYkn1rsI6Tb6HsrHCmB7gVpNwX6JxPTHcH6IoTA==} + engines: {node: '>=6'} + readable-stream@3.6.2: resolution: {integrity: sha512-9u/sniCrY3D5WdsERHzHE4G2YCXqoG5FTHUiCC4SIbr6XcLZBY05ya9EKjYek9O5xOAwjGq+1JdGBAS7Q9ScoA==} engines: {node: '>= 6'} + resolve-from@5.0.0: + resolution: {integrity: sha512-qYg9KP24dD5qka9J47d0aVky0N+b4fTU89LN9iDnjB5waksiC49rvMB0PrUJQGoTmH50XPiqOvAjDfaijGxYZw==} + engines: {node: '>=8'} + + reusify@1.1.0: + resolution: {integrity: sha512-g6QUff04oZpHs0eG5p83rFLhHeV00ug/Yf9nZM6fLeUrPguBTkTQOdpAWWspMh55TZfVQDPaN3NQJfbVRAxdIw==} + engines: {iojs: '>=1.0.0', node: '>=0.10.0'} + + run-parallel@1.2.0: + resolution: {integrity: sha512-5l4VyZR86LZ/lDxZTR6jqL8AFE2S0IFLMP26AbjsLVADxHdhB/c0GUsH+y39UfCi3dzz8OlQuPmnaJOMoDHQBA==} + safe-buffer@5.2.1: resolution: {integrity: sha512-rp3So07KcdmmKbGvgaNxQSJr7bGVSVk5S9Eq1F+ppbRo70+YeaDxkw5Dd8NPN+GD6bjnYm2VuPuCXmpuYvmCXQ==} + safer-buffer@2.1.2: + resolution: {integrity: sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==} + semver@7.8.1: resolution: {integrity: sha512-rkVq3IXh+4FDGch+KwzX3aV9W3kO54GyEgpvBzSyctDA6Xtd7RJQV1xmXbeQp5v7+VzLOfVqiutSE6GICgPFvg==} engines: {node: '>=10'} hasBin: true + shebang-command@2.0.0: + resolution: {integrity: sha512-kHxr2zZpYtdmrN1qDjrrX/Z1rR1kG8Dx+gkpK1G4eXmvXswmcE1hTWBWYUzlraYw1/yZp6YuDY77YtvbN0dmDA==} + engines: {node: '>=8'} + + shebang-regex@3.0.0: + resolution: {integrity: sha512-7++dFhtcx3353uBaq8DDR4NuxBetBzC7ZQOhmTQInHEd6bSrXdiEyzCvG07Z44UYdLShWUyXt5M/yhz8ekcb1A==} + engines: {node: '>=8'} + + signal-exit@4.1.0: + resolution: {integrity: sha512-bzyZ1e88w9O1iNJbKnOlvYTrWPDl46O1bG0D3XInv+9tkPrxrN8jUUTiFlDkkmKWgn1M6CfIA13SuGqOa9Korw==} + engines: {node: '>=14'} + simple-concat@1.0.1: resolution: {integrity: sha512-cSFtAPtRhljv69IK0hTVZQ+OfE9nePi/rtJmw5UjHeVyVroEqJXP1sFztKUy1qU+xvz3u/sfYJLa947b7nAN2Q==} simple-get@4.0.1: resolution: {integrity: sha512-brv7p5WgH0jmQJr1ZDDfKDOSeWWg+OVypG99A/5vYGPqJ6pxiaHLy8nxtFjBA7oMa01ebA9gfh1uMCFqOuXxvA==} + slash@3.0.0: + resolution: {integrity: sha512-g9Q1haeby36OSStwb4ntCGGGaKsaVSjQ68fBxoQcutl5fS1vuY18H3wSt3jFyFtrkx+Kz0V1G85A4MyAdDMi2Q==} + engines: {node: '>=8'} + + spawndamnit@3.0.1: + resolution: {integrity: sha512-MmnduQUuHCoFckZoWnXsTg7JaiLBJrKFj9UI2MbRPGaJeVpsLcVBu6P/IGZovziM/YBsellCmsprgNA+w0CzVg==} + + sprintf-js@1.0.3: + resolution: {integrity: sha512-D9cPgkvLlV3t3IzL0D0YLvGA9Ahk4PcvVwUbN0dSGr1aP0Nrt4AEnTUbuGvquEC0mA64Gqt1fzirlRs5ibXx8g==} + string_decoder@1.3.0: resolution: {integrity: sha512-hkRX8U1WjJFd8LsDJ2yQ/wWWxaopEsABU1XfkM8A+j0+85JAGppt16cr1Whg6KIbb4okU6Mql6BOj+uup/wKeA==} + strip-ansi@6.0.1: + resolution: {integrity: sha512-Y38VPSHcqkFrCpFnQ9vuSXmquuv5oXOKpGeT6aGrr3o3Gc9AlVa6JBfUSOCnbxGGZF+/0ooI7KrPuUSztUdU5A==} + engines: {node: '>=8'} + + strip-bom@3.0.0: + resolution: {integrity: sha512-vavAMRXOgBVNF6nyEEmL3DBK19iRpDcoIwW+swQ+CbGiu7lju6t+JklA1MHweoWtadgt4ISVUsXLyDq34ddcwA==} + engines: {node: '>=4'} + strip-json-comments@2.0.1: resolution: {integrity: sha512-4gB8na07fecVVkOI6Rs4e7T6NOTki5EmL7TUduTs6bu3EdnSycntVJ4re8kgZA+wx9IueI2Y11bfbgwtzuE0KQ==} engines: {node: '>=0.10.0'} @@ -148,6 +500,14 @@ packages: resolution: {integrity: sha512-ujeqbceABgwMZxEJnk2HDY2DlnUZ+9oEcb1KzTVfYHio0UE6dG71n60d8D2I4qNvleWrrXpmjpt7vZeF1LnMZQ==} engines: {node: '>=6'} + term-size@2.2.1: + resolution: {integrity: sha512-wK0Ri4fOGjv/XPy8SBHZChl8CM7uMc5VML7SqiQ0zG7+J5Vr+RMQDoHa2CNT6KHUnTGIXH34UDMkPzAUyapBZg==} + engines: {node: '>=8'} + + to-regex-range@5.0.1: + resolution: {integrity: sha512-65P7iz6X5yEr1cwcgvQxbbIw7Uk3gOy5dIdtZ4rDveLqhrdJP+Li/Hx6tyK0NEb+2GCyneCMJiGqrADCSNk8sQ==} + engines: {node: '>=8.0'} + tunnel-agent@0.6.0: resolution: {integrity: sha512-McnNiV1l8RYeY8tBgEpuodCC1mLUdbSN+CYBL7kJsJNInOP8UjDDEwdk6Mw60vdLLrr5NHKZhMAOSrR2NZuQ+w==} @@ -159,70 +519,404 @@ packages: undici-types@6.21.0: resolution: {integrity: sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ==} + universalify@0.1.2: + resolution: {integrity: sha512-rBJeI5CXAlmy1pV+617WB9J63U6XcazHHF2f2dbJix4XzpUF0RS3Zbj0FGIOCAva5P/d/GBOYaACQ1w+0azUkg==} + engines: {node: '>= 4.0.0'} + util-deprecate@1.0.2: resolution: {integrity: sha512-EPD5q1uXyFxJpCrLnCc1nHnq3gOa6DZBocAIiI2TaSCA7VCJ1UJDMagCzIkXNsUYfD1daK//LTEQ8xiIbrHtcw==} + which@2.0.2: + resolution: {integrity: sha512-BLI3Tl1TW3Pvl70l3yq3Y64i+awpwXqsGBYWkkqMtnbXgrMD+yj7rhW0kuEDxzJaYXGjEW5ogapKNMEKNMjibA==} + engines: {node: '>= 8'} + hasBin: true + wrappy@1.0.2: resolution: {integrity: sha512-l4Sp/DRseor9wL6EvV2+TuQn63dMkPjZ/sp9XkghTEbV9KlPS1xUsZ3u7/IQO4wxtcFB4bgpQPRcR3QCvezPcQ==} snapshots: + '@babel/runtime@7.29.7': {} + + '@changesets/apply-release-plan@7.1.1': + dependencies: + '@changesets/config': 3.1.4 + '@changesets/get-version-range-type': 0.4.0 + '@changesets/git': 3.0.4 + '@changesets/should-skip-package': 0.1.2 + '@changesets/types': 6.1.0 + '@manypkg/get-packages': 1.1.3 + detect-indent: 6.1.0 + fs-extra: 7.0.1 + lodash.startcase: 4.4.0 + outdent: 0.5.0 + prettier: 2.8.8 + resolve-from: 5.0.0 + semver: 7.8.1 + + '@changesets/assemble-release-plan@6.0.10': + dependencies: + '@changesets/errors': 0.2.0 + '@changesets/get-dependents-graph': 2.1.4 + '@changesets/should-skip-package': 0.1.2 + '@changesets/types': 6.1.0 + '@manypkg/get-packages': 1.1.3 + semver: 7.8.1 + + '@changesets/changelog-git@0.2.1': + dependencies: + '@changesets/types': 6.1.0 + + '@changesets/cli@2.31.0(@types/node@22.19.19)': + dependencies: + '@changesets/apply-release-plan': 7.1.1 + '@changesets/assemble-release-plan': 6.0.10 + '@changesets/changelog-git': 0.2.1 + '@changesets/config': 3.1.4 + '@changesets/errors': 0.2.0 + '@changesets/get-dependents-graph': 2.1.4 + '@changesets/get-release-plan': 4.0.16 + '@changesets/git': 3.0.4 + '@changesets/logger': 0.1.1 + '@changesets/pre': 2.0.2 + '@changesets/read': 0.6.7 + '@changesets/should-skip-package': 0.1.2 + '@changesets/types': 6.1.0 + '@changesets/write': 0.4.0 + '@inquirer/external-editor': 1.0.3(@types/node@22.19.19) + '@manypkg/get-packages': 1.1.3 + ansi-colors: 4.1.3 + enquirer: 2.4.1 + fs-extra: 7.0.1 + mri: 1.2.0 + package-manager-detector: 0.2.11 + picocolors: 1.1.1 + resolve-from: 5.0.0 + semver: 7.8.1 + spawndamnit: 3.0.1 + term-size: 2.2.1 + transitivePeerDependencies: + - '@types/node' + + '@changesets/config@3.1.4': + dependencies: + '@changesets/errors': 0.2.0 + '@changesets/get-dependents-graph': 2.1.4 + '@changesets/logger': 0.1.1 + '@changesets/should-skip-package': 0.1.2 + '@changesets/types': 6.1.0 + '@manypkg/get-packages': 1.1.3 + fs-extra: 7.0.1 + micromatch: 4.0.8 + + '@changesets/errors@0.2.0': + dependencies: + extendable-error: 0.1.7 + + '@changesets/get-dependents-graph@2.1.4': + dependencies: + '@changesets/types': 6.1.0 + '@manypkg/get-packages': 1.1.3 + picocolors: 1.1.1 + semver: 7.8.1 + + '@changesets/get-release-plan@4.0.16': + dependencies: + '@changesets/assemble-release-plan': 6.0.10 + '@changesets/config': 3.1.4 + '@changesets/pre': 2.0.2 + '@changesets/read': 0.6.7 + '@changesets/types': 6.1.0 + '@manypkg/get-packages': 1.1.3 + + '@changesets/get-version-range-type@0.4.0': {} + + '@changesets/git@3.0.4': + dependencies: + '@changesets/errors': 0.2.0 + '@manypkg/get-packages': 1.1.3 + is-subdir: 1.2.0 + micromatch: 4.0.8 + spawndamnit: 3.0.1 + + '@changesets/logger@0.1.1': + dependencies: + picocolors: 1.1.1 + + '@changesets/parse@0.4.3': + dependencies: + '@changesets/types': 6.1.0 + js-yaml: 4.1.1 + + '@changesets/pre@2.0.2': + dependencies: + '@changesets/errors': 0.2.0 + '@changesets/types': 6.1.0 + '@manypkg/get-packages': 1.1.3 + fs-extra: 7.0.1 + + '@changesets/read@0.6.7': + dependencies: + '@changesets/git': 3.0.4 + '@changesets/logger': 0.1.1 + '@changesets/parse': 0.4.3 + '@changesets/types': 6.1.0 + fs-extra: 7.0.1 + p-filter: 2.1.0 + picocolors: 1.1.1 + + '@changesets/should-skip-package@0.1.2': + dependencies: + '@changesets/types': 6.1.0 + '@manypkg/get-packages': 1.1.3 + + '@changesets/types@4.1.0': {} + + '@changesets/types@6.1.0': {} + + '@changesets/write@0.4.0': + dependencies: + '@changesets/types': 6.1.0 + fs-extra: 7.0.1 + human-id: 4.1.3 + prettier: 2.8.8 + + '@inquirer/external-editor@1.0.3(@types/node@22.19.19)': + dependencies: + chardet: 2.1.1 + iconv-lite: 0.7.2 + optionalDependencies: + '@types/node': 22.19.19 + + '@manypkg/find-root@1.1.0': + dependencies: + '@babel/runtime': 7.29.7 + '@types/node': 12.20.55 + find-up: 4.1.0 + fs-extra: 8.1.0 + + '@manypkg/get-packages@1.1.3': + dependencies: + '@babel/runtime': 7.29.7 + '@changesets/types': 4.1.0 + '@manypkg/find-root': 1.1.0 + fs-extra: 8.1.0 + globby: 11.1.0 + read-yaml-file: 1.1.0 + + '@nodelib/fs.scandir@2.1.5': + dependencies: + '@nodelib/fs.stat': 2.0.5 + run-parallel: 1.2.0 + + '@nodelib/fs.stat@2.0.5': {} + + '@nodelib/fs.walk@1.2.8': + dependencies: + '@nodelib/fs.scandir': 2.1.5 + fastq: 1.20.1 + + '@types/node@12.20.55': {} + '@types/node@22.19.19': dependencies: undici-types: 6.21.0 + ansi-colors@4.1.3: {} + + ansi-regex@5.0.1: {} + + argparse@1.0.10: + dependencies: + sprintf-js: 1.0.3 + + argparse@2.0.1: {} + + array-union@2.1.0: {} + base64-js@1.5.1: {} + better-path-resolve@1.0.0: + dependencies: + is-windows: 1.0.2 + bl@4.1.0: dependencies: buffer: 5.7.1 inherits: 2.0.4 readable-stream: 3.6.2 + braces@3.0.3: + dependencies: + fill-range: 7.1.1 + buffer@5.7.1: dependencies: base64-js: 1.5.1 ieee754: 1.2.1 + chardet@2.1.1: {} + chownr@1.1.4: {} commander@12.1.0: {} + cross-spawn@7.0.6: + dependencies: + path-key: 3.1.1 + shebang-command: 2.0.0 + which: 2.0.2 + decompress-response@6.0.0: dependencies: mimic-response: 3.1.0 deep-extend@0.6.0: {} + detect-indent@6.1.0: {} + detect-libc@2.1.2: {} + dir-glob@3.0.1: + dependencies: + path-type: 4.0.0 + end-of-stream@1.4.5: dependencies: once: 1.4.0 + enquirer@2.4.1: + dependencies: + ansi-colors: 4.1.3 + strip-ansi: 6.0.1 + + esprima@4.0.1: {} + expand-template@2.0.3: {} + extendable-error@0.1.7: {} + + fast-glob@3.3.3: + dependencies: + '@nodelib/fs.stat': 2.0.5 + '@nodelib/fs.walk': 1.2.8 + glob-parent: 5.1.2 + merge2: 1.4.1 + micromatch: 4.0.8 + + fastq@1.20.1: + dependencies: + reusify: 1.1.0 + + fill-range@7.1.1: + dependencies: + to-regex-range: 5.0.1 + + find-up@4.1.0: + dependencies: + locate-path: 5.0.0 + path-exists: 4.0.0 + fs-constants@1.0.0: {} + fs-extra@7.0.1: + dependencies: + graceful-fs: 4.2.11 + jsonfile: 4.0.0 + universalify: 0.1.2 + + fs-extra@8.1.0: + dependencies: + graceful-fs: 4.2.11 + jsonfile: 4.0.0 + universalify: 0.1.2 + github-from-package@0.0.0: {} + glob-parent@5.1.2: + dependencies: + is-glob: 4.0.3 + + globby@11.1.0: + dependencies: + array-union: 2.1.0 + dir-glob: 3.0.1 + fast-glob: 3.3.3 + ignore: 5.3.2 + merge2: 1.4.1 + slash: 3.0.0 + + graceful-fs@4.2.11: {} + + human-id@4.1.3: {} + + iconv-lite@0.7.2: + dependencies: + safer-buffer: 2.1.2 + ieee754@1.2.1: {} + ignore@5.3.2: {} + inherits@2.0.4: {} ini@1.3.8: {} + is-extglob@2.1.1: {} + + is-glob@4.0.3: + dependencies: + is-extglob: 2.1.1 + + is-number@7.0.0: {} + + is-subdir@1.2.0: + dependencies: + better-path-resolve: 1.0.0 + + is-windows@1.0.2: {} + + isexe@2.0.0: {} + + js-yaml@3.14.2: + dependencies: + argparse: 1.0.10 + esprima: 4.0.1 + + js-yaml@4.1.1: + dependencies: + argparse: 2.0.1 + + jsonfile@4.0.0: + optionalDependencies: + graceful-fs: 4.2.11 + keytar@7.9.0: dependencies: node-addon-api: 4.3.0 prebuild-install: 7.1.3 + locate-path@5.0.0: + dependencies: + p-locate: 4.1.0 + + lodash.startcase@4.4.0: {} + + merge2@1.4.1: {} + + micromatch@4.0.8: + dependencies: + braces: 3.0.3 + picomatch: 2.3.2 + mimic-response@3.1.0: {} minimist@1.2.8: {} mkdirp-classic@0.5.3: {} + mri@1.2.0: {} + napi-build-utils@2.0.0: {} node-abi@3.92.0: @@ -235,6 +929,40 @@ snapshots: dependencies: wrappy: 1.0.2 + outdent@0.5.0: {} + + p-filter@2.1.0: + dependencies: + p-map: 2.1.0 + + p-limit@2.3.0: + dependencies: + p-try: 2.2.0 + + p-locate@4.1.0: + dependencies: + p-limit: 2.3.0 + + p-map@2.1.0: {} + + p-try@2.2.0: {} + + package-manager-detector@0.2.11: + dependencies: + quansync: 0.2.11 + + path-exists@4.0.0: {} + + path-key@3.1.1: {} + + path-type@4.0.0: {} + + picocolors@1.1.1: {} + + picomatch@2.3.2: {} + + pify@4.0.1: {} + prebuild-install@7.1.3: dependencies: detect-libc: 2.1.2 @@ -250,11 +978,17 @@ snapshots: tar-fs: 2.1.4 tunnel-agent: 0.6.0 + prettier@2.8.8: {} + pump@3.0.4: dependencies: end-of-stream: 1.4.5 once: 1.4.0 + quansync@0.2.11: {} + + queue-microtask@1.2.3: {} + rc@1.2.8: dependencies: deep-extend: 0.6.0 @@ -262,16 +996,41 @@ snapshots: minimist: 1.2.8 strip-json-comments: 2.0.1 + read-yaml-file@1.1.0: + dependencies: + graceful-fs: 4.2.11 + js-yaml: 3.14.2 + pify: 4.0.1 + strip-bom: 3.0.0 + readable-stream@3.6.2: dependencies: inherits: 2.0.4 string_decoder: 1.3.0 util-deprecate: 1.0.2 + resolve-from@5.0.0: {} + + reusify@1.1.0: {} + + run-parallel@1.2.0: + dependencies: + queue-microtask: 1.2.3 + safe-buffer@5.2.1: {} + safer-buffer@2.1.2: {} + semver@7.8.1: {} + shebang-command@2.0.0: + dependencies: + shebang-regex: 3.0.0 + + shebang-regex@3.0.0: {} + + signal-exit@4.1.0: {} + simple-concat@1.0.1: {} simple-get@4.0.1: @@ -280,10 +1039,25 @@ snapshots: once: 1.4.0 simple-concat: 1.0.1 + slash@3.0.0: {} + + spawndamnit@3.0.1: + dependencies: + cross-spawn: 7.0.6 + signal-exit: 4.1.0 + + sprintf-js@1.0.3: {} + string_decoder@1.3.0: dependencies: safe-buffer: 5.2.1 + strip-ansi@6.0.1: + dependencies: + ansi-regex: 5.0.1 + + strip-bom@3.0.0: {} + strip-json-comments@2.0.1: {} tar-fs@2.1.4: @@ -301,6 +1075,12 @@ snapshots: inherits: 2.0.4 readable-stream: 3.6.2 + term-size@2.2.1: {} + + to-regex-range@5.0.1: + dependencies: + is-number: 7.0.0 + tunnel-agent@0.6.0: dependencies: safe-buffer: 5.2.1 @@ -309,6 +1089,12 @@ snapshots: undici-types@6.21.0: {} + universalify@0.1.2: {} + util-deprecate@1.0.2: {} + which@2.0.2: + dependencies: + isexe: 2.0.0 + wrappy@1.0.2: {} diff --git a/package/src/cli.ts b/package/src/cli.ts index c62d31a..2169191 100644 --- a/package/src/cli.ts +++ b/package/src/cli.ts @@ -1,4 +1,5 @@ import { readFileSync } from 'node:fs' +import { createRequire } from 'node:module' import { extname } from 'node:path' import { Command } from 'commander' @@ -20,6 +21,9 @@ export interface CliDependencies { exit?: (code: number) => never } +const require = createRequire(import.meta.url) +const packageJson = require('../package.json') as { version: string } + type OutputFormat = 'md' | 'json' interface GlobalOptions { @@ -38,7 +42,7 @@ export function createProgram(deps: CliDependencies = {}): Command { program .name('shop') .description('Shop personal shopping CLI for catalog search, auth, checkout, and order search') - .version('0.1.0') + .version(packageJson.version) .option('--country ', 'Buyer country for this call (catalog context signal, not a ships-to filter). Transient; use `shop config set-country` to persist a default.', DEFAULT_COUNTRY) .option('--profile-url ', 'UCP agent profile URL for global catalog calls') .option('--memory-store', 'Use in-memory token storage for tests and dry runs') diff --git a/package/tsconfig.build.json b/package/tsconfig.build.json index a9fb3d3..828debf 100644 --- a/package/tsconfig.build.json +++ b/package/tsconfig.build.json @@ -1,7 +1,9 @@ { "extends": "./tsconfig.json", "compilerOptions": { - "outDir": "dist" + "outDir": "dist", + "sourceMap": false, + "declarationMap": false }, "include": ["src/**/*.ts"] } From fe291402de77ce26a1046dcf6a0f7a6473e9bfe8 Mon Sep 17 00:00:00 2001 From: Pawan Patel Date: Tue, 2 Jun 2026 14:31:26 -0400 Subject: [PATCH 2/6] Add licence and readme --- package/LICENSE.md | 8 ++++ package/README.md | 96 ++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 104 insertions(+) create mode 100644 package/LICENSE.md create mode 100644 package/README.md diff --git a/package/LICENSE.md b/package/LICENSE.md new file mode 100644 index 0000000..dbcb964 --- /dev/null +++ b/package/LICENSE.md @@ -0,0 +1,8 @@ +Copyright Shopify Inc. All rights reserved. + +This package is publicly installable but is not open source software. No license is granted to copy, modify, distribute, sublicense, or create derivative works from this package except as expressly permitted by Shopify in writing or by applicable law. + +Use of this CLI is limited to individual end-user personal shopping workflows. Building commercial services, resale platforms, aggregators, or services that provide third parties with programmatic access to Shopify's catalog, checkout, delegated payments, or aggregated user data is prohibited. + +For accepted and prohibited use, see: +https://help.shop.app/shop/shopping/personal-agents diff --git a/package/README.md b/package/README.md new file mode 100644 index 0000000..281b316 --- /dev/null +++ b/package/README.md @@ -0,0 +1,96 @@ +# Shop CLI + +Personal shopping CLI for Shop catalog search, checkout, and order workflows. + +> This package is publicly installable, but it is not open source. See [License](#license). + +## Install + +```bash +pnpm add --global @shopify/shop-cli +``` + +Or with npm: + +```bash +npm install --global @shopify/shop-cli +``` + +## Usage + +```bash +shop --help +shop search "trail running shoes" --limit 10 +shop catalog lookup gid://shopify/ProductVariant/50362300006715 +shop auth login +shop auth status +``` + +## Commands + +### Search catalog + +```bash +shop search "black crewneck sweater" --limit 10 +shop search "boots" --ships-to US --country US +shop search --like-id gid://shopify/p/abc123 +shop search --image ./photo.jpg +``` + +Useful flags: + +```text +--country Buyer country/catalog context +--ships-to Filter to products that ship to the destination +--limit Result limit, 1-50 +--format md|json Output format for catalog results +``` + +### Catalog lookup + +```bash +shop catalog lookup +shop catalog get-product +``` + +### Auth + +```bash +shop auth login +shop auth status +shop auth logout +``` + +### Checkout + +```bash +printf '{"email":"buyer@example.com"}' | \ + shop checkout create \ + --shop-domain example.myshopify.com \ + --variant-id 123 \ + --quantity 1 \ + --checkout-stdin +``` + +`shop checkout complete` requires `--confirm` and should only be used after confirming the item, variant, quantity, price, shipping, and total cost. + +### Orders + +```bash +shop orders search --type recent +shop orders search --type tracking --query "running shoes" +shop orders search --type returns --query "jacket" +shop orders search --type reorder --query "coffee" +``` + +## Personal-use limits + +This CLI is for individual end-users only. Building commercial services, resale platforms, aggregators, or anything that provides third parties with programmatic access to Shopify's catalog, checkout, delegated payments, or aggregated user data is prohibited. + +See https://help.shop.app/shop/shopping/personal-agents for accepted and prohibited use. + +## License + +Copyright Shopify Inc. All rights reserved. + +This package is not open source. See [LICENSE.md](./LICENSE.md). From 08ad94615255e7f92aee96375ceb00a8ed85f2bc Mon Sep 17 00:00:00 2001 From: Pawan Patel Date: Wed, 3 Jun 2026 09:32:03 -0400 Subject: [PATCH 3/6] Restructure repo to align with ucp/cli --- .changeset/README.md | 8 ++ .../.changeset => .changeset}/config.json | 2 +- .github/workflows/release.yml | 102 +++++++++--------- .npmrc | 4 + LICENSE | 19 ++++ package/README.md => README.md | 6 +- package/package.json => package.json | 23 +++- package/LICENSE.md | 8 -- package/pnpm-lock.yaml => pnpm-lock.yaml | 0 {package/src => src}/auth.ts | 0 {package/src => src}/bin.ts | 0 {package/src => src}/cli.ts | 0 {package/src => src}/constants.ts | 0 {package/src => src}/errors.ts | 0 {package/src => src}/http.ts | 0 {package/src => src}/index.ts | 0 {package/src => src}/render.ts | 0 {package/src => src}/shop-client.ts | 0 {package/src => src}/storage.ts | 0 {package/src => src}/types.ts | 0 {package/tests => tests}/auth.test.ts | 0 {package/tests => tests}/catalog.test.ts | 0 .../tests => tests}/checkout-orders.test.ts | 0 {package/tests => tests}/harness.ts | 0 {package/tests => tests}/render.test.ts | 0 {package/tests => tests}/test-utils.ts | 0 ...tsconfig.build.json => tsconfig.build.json | 0 package/tsconfig.json => tsconfig.json | 0 .../tsconfig.test.json => tsconfig.test.json | 0 29 files changed, 102 insertions(+), 70 deletions(-) create mode 100644 .changeset/README.md rename {package/.changeset => .changeset}/config.json (70%) create mode 100644 .npmrc create mode 100644 LICENSE rename package/README.md => README.md (90%) rename package/package.json => package.json (74%) delete mode 100644 package/LICENSE.md rename package/pnpm-lock.yaml => pnpm-lock.yaml (100%) rename {package/src => src}/auth.ts (100%) rename {package/src => src}/bin.ts (100%) rename {package/src => src}/cli.ts (100%) rename {package/src => src}/constants.ts (100%) rename {package/src => src}/errors.ts (100%) rename {package/src => src}/http.ts (100%) rename {package/src => src}/index.ts (100%) rename {package/src => src}/render.ts (100%) rename {package/src => src}/shop-client.ts (100%) rename {package/src => src}/storage.ts (100%) rename {package/src => src}/types.ts (100%) rename {package/tests => tests}/auth.test.ts (100%) rename {package/tests => tests}/catalog.test.ts (100%) rename {package/tests => tests}/checkout-orders.test.ts (100%) rename {package/tests => tests}/harness.ts (100%) rename {package/tests => tests}/render.test.ts (100%) rename {package/tests => tests}/test-utils.ts (100%) rename package/tsconfig.build.json => tsconfig.build.json (100%) rename package/tsconfig.json => tsconfig.json (100%) rename package/tsconfig.test.json => tsconfig.test.json (100%) diff --git a/.changeset/README.md b/.changeset/README.md new file mode 100644 index 0000000..654c6d4 --- /dev/null +++ b/.changeset/README.md @@ -0,0 +1,8 @@ +# Changesets + +Hello and welcome! This folder has been automatically generated by `@changesets/cli`, a build tool that works +with multi-package repos, or single-package repos to help you version and publish your code. You can +find the full documentation for it [in our repository](https://github.com/changesets/changesets). + +We have a quick list of common questions to get you started engaging with this project in +[our documentation](https://github.com/changesets/changesets/blob/main/docs/common-questions.md). diff --git a/package/.changeset/config.json b/.changeset/config.json similarity index 70% rename from package/.changeset/config.json rename to .changeset/config.json index 2be13d4..e24e3c5 100644 --- a/package/.changeset/config.json +++ b/.changeset/config.json @@ -1,5 +1,5 @@ { - "$schema": "https://unpkg.com/@changesets/config@3.1.1/schema.json", + "$schema": "https://cdn.jsdelivr.net/npm/@changesets/config@3.1.4/schema.json", "changelog": "@changesets/cli/changelog", "commit": false, "fixed": [], diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 6963a4b..71d7071 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,52 +1,50 @@ -# name: Release - -# on: -# push: -# branches: -# - main - -# permissions: -# contents: write -# id-token: write -# pull-requests: write - -# jobs: -# release: -# name: Version or publish npm package -# runs-on: ubuntu-latest - -# steps: -# - name: Checkout repo -# uses: actions/checkout@v4 - -# - name: Setup Node.js -# uses: actions/setup-node@v4 -# with: -# node-version: '20' -# registry-url: 'https://registry.npmjs.org' -# cache: pnpm -# cache-dependency-path: package/pnpm-lock.yaml - -# - name: Enable pnpm -# run: | -# corepack enable -# corepack prepare pnpm@10.28.0 --activate - -# - name: Update npm for OIDC publishing -# run: npm install --global npm@latest - -# - name: Install dependencies -# working-directory: package -# run: pnpm install --frozen-lockfile - -# - name: Create release PR or publish -# uses: changesets/action@v1 -# with: -# cwd: package -# publish: pnpm release -# version: pnpm version-packages -# env: -# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} -# # Keep this as a literal empty string. It forces npm OIDC Trusted -# # Publishing instead of falling back to token auth. -# NPM_TOKEN: '' +name: Release + +on: + push: + branches: [main] + +permissions: + contents: write + id-token: write + pull-requests: write + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +jobs: + changesets: + name: changeset release + runs-on: ubuntu-22.04 + environment: + name: npm-shop-cli + url: https://www.npmjs.com/package/@shopify/shop-cli + permissions: + contents: write + pull-requests: write + id-token: write + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + - uses: pnpm/action-setup@v4 + with: + version: 10.28.0 + - uses: actions/setup-node@v4 + with: + node-version: 24 + registry-url: https://registry.npmjs.org + cache: pnpm + - name: Update npm for OIDC publishing + run: npm install --global npm@latest + - run: pnpm install --frozen-lockfile + - uses: changesets/action@v1 + with: + version: pnpm version-packages + publish: pnpm release + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + NPM_CONFIG_PROVENANCE: "true" + NPM_TOKEN: "" + NODE_AUTH_TOKEN: "" diff --git a/.npmrc b/.npmrc new file mode 100644 index 0000000..d151287 --- /dev/null +++ b/.npmrc @@ -0,0 +1,4 @@ +minimum-release-age=10080 +package-manager-strict=true +auto-install-peers=true +strict-peer-dependencies=false diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..2904ff7 --- /dev/null +++ b/LICENSE @@ -0,0 +1,19 @@ +Copyright 2026-present, Shopify Inc. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/package/README.md b/README.md similarity index 90% rename from package/README.md rename to README.md index 281b316..75eb9f4 100644 --- a/package/README.md +++ b/README.md @@ -2,8 +2,6 @@ Personal shopping CLI for Shop catalog search, checkout, and order workflows. -> This package is publicly installable, but it is not open source. See [License](#license). - ## Install ```bash @@ -91,6 +89,4 @@ See https://help.shop.app/shop/shopping/personal-agents for accepted and prohibi ## License -Copyright Shopify Inc. All rights reserved. - -This package is not open source. See [LICENSE.md](./LICENSE.md). +MIT. See [LICENSE](./LICENSE). diff --git a/package/package.json b/package.json similarity index 74% rename from package/package.json rename to package.json index 244d789..e09ce7c 100644 --- a/package/package.json +++ b/package.json @@ -3,18 +3,32 @@ "version": "0.1.0", "description": "Personal shopping CLI for Shop catalog search, checkout, and order workflows", "type": "module", - "license": "UNLICENSED", - "private": false, - "homepage": "https://help.shop.app/shop/shopping/personal-agents", + "license": "MIT", + "repository": { + "type": "git", + "url": "https://github.com/Shopify/shop-cli" + }, + "bugs": { + "url": "https://github.com/Shopify/shop-cli/issues" + }, + "homepage": "https://github.com/Shopify/shop-cli#readme", + "sideEffects": false, "bin": { "shop": "./dist/bin.js" }, "main": "./dist/index.js", "types": "./dist/index.d.ts", + "exports": { + ".": { + "types": "./dist/index.d.ts", + "default": "./dist/index.js" + } + }, "files": [ "dist", "README.md", - "LICENSE.md" + "LICENSE", + "src" ], "publishConfig": { "access": "public", @@ -26,6 +40,7 @@ "test": "rm -rf .test-build && tsc -p tsconfig.test.json && cp package.json .test-build/package.json && node --test .test-build/tests/*.test.js", "typecheck": "tsc --noEmit", "version-packages": "changeset version", + "changeset": "changeset", "release": "pnpm build && pnpm test && changeset publish", "pack:dry": "pnpm dlx npm@latest pack --dry-run" }, diff --git a/package/LICENSE.md b/package/LICENSE.md deleted file mode 100644 index dbcb964..0000000 --- a/package/LICENSE.md +++ /dev/null @@ -1,8 +0,0 @@ -Copyright Shopify Inc. All rights reserved. - -This package is publicly installable but is not open source software. No license is granted to copy, modify, distribute, sublicense, or create derivative works from this package except as expressly permitted by Shopify in writing or by applicable law. - -Use of this CLI is limited to individual end-user personal shopping workflows. Building commercial services, resale platforms, aggregators, or services that provide third parties with programmatic access to Shopify's catalog, checkout, delegated payments, or aggregated user data is prohibited. - -For accepted and prohibited use, see: -https://help.shop.app/shop/shopping/personal-agents diff --git a/package/pnpm-lock.yaml b/pnpm-lock.yaml similarity index 100% rename from package/pnpm-lock.yaml rename to pnpm-lock.yaml diff --git a/package/src/auth.ts b/src/auth.ts similarity index 100% rename from package/src/auth.ts rename to src/auth.ts diff --git a/package/src/bin.ts b/src/bin.ts similarity index 100% rename from package/src/bin.ts rename to src/bin.ts diff --git a/package/src/cli.ts b/src/cli.ts similarity index 100% rename from package/src/cli.ts rename to src/cli.ts diff --git a/package/src/constants.ts b/src/constants.ts similarity index 100% rename from package/src/constants.ts rename to src/constants.ts diff --git a/package/src/errors.ts b/src/errors.ts similarity index 100% rename from package/src/errors.ts rename to src/errors.ts diff --git a/package/src/http.ts b/src/http.ts similarity index 100% rename from package/src/http.ts rename to src/http.ts diff --git a/package/src/index.ts b/src/index.ts similarity index 100% rename from package/src/index.ts rename to src/index.ts diff --git a/package/src/render.ts b/src/render.ts similarity index 100% rename from package/src/render.ts rename to src/render.ts diff --git a/package/src/shop-client.ts b/src/shop-client.ts similarity index 100% rename from package/src/shop-client.ts rename to src/shop-client.ts diff --git a/package/src/storage.ts b/src/storage.ts similarity index 100% rename from package/src/storage.ts rename to src/storage.ts diff --git a/package/src/types.ts b/src/types.ts similarity index 100% rename from package/src/types.ts rename to src/types.ts diff --git a/package/tests/auth.test.ts b/tests/auth.test.ts similarity index 100% rename from package/tests/auth.test.ts rename to tests/auth.test.ts diff --git a/package/tests/catalog.test.ts b/tests/catalog.test.ts similarity index 100% rename from package/tests/catalog.test.ts rename to tests/catalog.test.ts diff --git a/package/tests/checkout-orders.test.ts b/tests/checkout-orders.test.ts similarity index 100% rename from package/tests/checkout-orders.test.ts rename to tests/checkout-orders.test.ts diff --git a/package/tests/harness.ts b/tests/harness.ts similarity index 100% rename from package/tests/harness.ts rename to tests/harness.ts diff --git a/package/tests/render.test.ts b/tests/render.test.ts similarity index 100% rename from package/tests/render.test.ts rename to tests/render.test.ts diff --git a/package/tests/test-utils.ts b/tests/test-utils.ts similarity index 100% rename from package/tests/test-utils.ts rename to tests/test-utils.ts diff --git a/package/tsconfig.build.json b/tsconfig.build.json similarity index 100% rename from package/tsconfig.build.json rename to tsconfig.build.json diff --git a/package/tsconfig.json b/tsconfig.json similarity index 100% rename from package/tsconfig.json rename to tsconfig.json diff --git a/package/tsconfig.test.json b/tsconfig.test.json similarity index 100% rename from package/tsconfig.test.json rename to tsconfig.test.json From dba77603a440e76d940bc14d8a6158534c010da1 Mon Sep 17 00:00:00 2001 From: Pawan Patel Date: Wed, 3 Jun 2026 09:35:01 -0400 Subject: [PATCH 4/6] Disable releaase.yaml for now --- .github/workflows/release.yml | 90 +++++++++++++++++------------------ 1 file changed, 44 insertions(+), 46 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 71d7071..9c11bac 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,50 +1,48 @@ -name: Release +# name: Release -on: - push: - branches: [main] +# on: +# push: +# branches: [main] -permissions: - contents: write - id-token: write - pull-requests: write +# permissions: +# contents: write # Required for Changesets to push branches +# id-token: write # Required for OIDC authentication +# pull-requests: write # Required for Changesets to create PRs -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: false +# concurrency: +# group: ${{ github.workflow }}-${{ github.ref }} +# cancel-in-progress: false -jobs: - changesets: - name: changeset release - runs-on: ubuntu-22.04 - environment: - name: npm-shop-cli - url: https://www.npmjs.com/package/@shopify/shop-cli - permissions: - contents: write - pull-requests: write - id-token: write - steps: - - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - uses: pnpm/action-setup@v4 - with: - version: 10.28.0 - - uses: actions/setup-node@v4 - with: - node-version: 24 - registry-url: https://registry.npmjs.org - cache: pnpm - - name: Update npm for OIDC publishing - run: npm install --global npm@latest - - run: pnpm install --frozen-lockfile - - uses: changesets/action@v1 - with: - version: pnpm version-packages - publish: pnpm release - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - NPM_CONFIG_PROVENANCE: "true" - NPM_TOKEN: "" - NODE_AUTH_TOKEN: "" +# jobs: +# changesets: +# name: changeset release +# if: github.event_name == 'push' +# runs-on: ubuntu-22.04 +# environment: +# name: npm-shop-cli +# url: https://www.npmjs.com/package/@shopify/shop-cli +# permissions: +# contents: write +# pull-requests: write +# id-token: write +# steps: +# - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 +# with: +# fetch-depth: 0 +# - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v4.4.0 +# with: +# version: 10.28.0 +# - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 +# with: +# node-version: 24 +# cache: pnpm +# - run: pnpm install --frozen-lockfile +# - uses: changesets/action@63a615b9cd06ba9a3e6d13796c7fbcb080a60a0b # v1.8.0 +# with: +# version: pnpm version-packages +# publish: pnpm release +# env: +# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} +# NPM_CONFIG_PROVENANCE: "true" +# NPM_TOKEN: "" +# NODE_AUTH_TOKEN: "" From 13a2917109aae3cbf667dfc430ef89b0e20f777f Mon Sep 17 00:00:00 2001 From: Pawan Patel Date: Wed, 3 Jun 2026 11:25:26 -0400 Subject: [PATCH 5/6] Update skill.md references to be accurate --- SKILL.md | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/SKILL.md b/SKILL.md index 06ef8b2..6a89fb5 100644 --- a/SKILL.md +++ b/SKILL.md @@ -2,7 +2,7 @@ name: shop description: "Your personal shopping assistant — Search, Buy, Track, Return, and Re-order products through the best product catalog in the world." metadata: - version: "0.3.0" + version: "0.1.0" homepage: "https://shop.app" --- @@ -19,10 +19,9 @@ If package installation is blocked, use the direct API instructions in the refer ## Installation -From this skill folder: +From the repository root: ```bash -cd package pnpm install pnpm build pnpm link --global @@ -32,18 +31,15 @@ shop --help Uninstall: ```bash -cd package pnpm unlink --global ``` If installed from a registry or tarball instead of `pnpm link --global`: ```bash -pnpm remove --global @shopify/shop +pnpm remove --global @shopify/shop-cli ``` -## Package Contents - ## Core Flow 1. Search using shop search before asking the user to authenticate. From 64ff42a6c15a3b191aacfc2760c43a4c1ea722cf Mon Sep 17 00:00:00 2001 From: Pawan Patel Date: Wed, 3 Jun 2026 11:31:05 -0400 Subject: [PATCH 6/6] Add only https handling for image urls reject file:// or data:// --- src/render.ts | 15 +++++++++++++- tests/render.test.ts | 48 ++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 62 insertions(+), 1 deletion(-) diff --git a/src/render.ts b/src/render.ts index 4332850..843fe18 100644 --- a/src/render.ts +++ b/src/render.ts @@ -287,13 +287,26 @@ function firstMediaUrl(media: unknown): string | undefined { if (!Array.isArray(media)) return undefined for (const item of media) { if (isObject(item)) { - const url = asString(item.url) + const url = safeImageUrl(asString(item.url)) if (url) return url } } return undefined } +// Media URLs come from untrusted merchant catalog content, so only surface +// HTTPS URLs. Reject http:, file:, data:, javascript:, and any other scheme +// (per references/safety.md) so a malicious listing can't emit a dangerous or +// tracking link as a user-visible image. +function safeImageUrl(url: string | undefined): string | undefined { + if (!url) return undefined + try { + return new URL(url).protocol === 'https:' ? url : undefined + } catch { + return undefined + } +} + // top_features / tech_specs come back from the catalog as newline-delimited // strings (one item per line), though older/compact payloads sometimes use a // plain array. Handle both: split strings on newlines, map arrays through diff --git a/tests/render.test.ts b/tests/render.test.ts index 48a5f25..f20cff7 100644 --- a/tests/render.test.ts +++ b/tests/render.test.ts @@ -100,6 +100,54 @@ describe('renderCatalogResult', () => { expect(gbp).not.toContain('$20.00 GBP') }) + it('renders an https image url as Img:', () => { + expect(md).toContain('Img: https://cdn.shopify.com/s/files/1/2995/0112/files/u530csb_nb_02_i.jpg') + }) + + it('rejects non-https image urls (file/data/javascript/http) and falls through to a safe one', () => { + const out = renderCatalogResult('search_catalog', { + result: { + structuredContent: { + products: [ + { + title: 'Unsafe media product', + variants: [{ id: 'gid://shopify/ProductVariant/1' }], + media: [ + { type: 'image', url: 'javascript:alert(1)' }, + { type: 'image', url: 'data:image/png;base64,AAAA' }, + { type: 'image', url: 'file:///etc/passwd' }, + { type: 'image', url: 'http://evil.example.com/track.png' }, + { type: 'image', url: 'https://cdn.shopify.com/s/files/ok.jpg' }, + ], + }, + ], + }, + }, + }) + expect(out).toContain('Img: https://cdn.shopify.com/s/files/ok.jpg') + expect(out).not.toContain('javascript:') + expect(out).not.toContain('data:') + expect(out).not.toContain('file:') + expect(out).not.toContain('http://evil.example.com') + }) + + it('omits Img entirely when no media url is https', () => { + const out = renderCatalogResult('search_catalog', { + result: { + structuredContent: { + products: [ + { + title: 'Only unsafe media', + variants: [{ id: 'gid://shopify/ProductVariant/1' }], + media: [{ type: 'image', url: 'http://insecure.example.com/x.png' }], + }, + ], + }, + }, + }) + expect(out).not.toContain('Img:') + }) + it('shows the product UPID (short id), not the full gid', () => { expect(md).toContain('id: 6J8JMOV0g1JeQNJlp3juMV') expect(md).not.toContain('gid://shopify/p/')