Skip to content

Npm library - #228

Merged
riquito merged 2 commits into
masterfrom
npm-library
Sep 2, 2026
Merged

riquito merged 2 commits into
masterfrom
npm-library

Conversation

@riquito

@riquito riquito commented Sep 2, 2026

Copy link
Copy Markdown
Owner

No description provided.

Everything lived in main.rs, so we moved the graph walking and rendering into
src/lib.rs, leaving main.rs with argument parsing, I/O and exit codes.

The two process-wide OnceCells are gone: MAX_PKG_VISITS and the TTY check
that drove colorization are now Options fields, so a caller can run several
queries in one process without them fighting over global state.

No behaviour change: ~2700 comparisons of the old and new binaries over
every bundled lockfile (per-package queries across -j/-D/-N/-d, plus
--print-records and --full-tree) produce byte-identical output.
Adds an npm package that answers the same questions as the CLI from
JavaScript, in Node and in the browser:

    import { why } from "yarn-why";
    await why(lockfileContents, "lodash");

The engine is compiled to wasm32-unknown-unknown with wasm-bindgen and
wrapped in TypeScript. Options cross the boundary as JSON and results come
back as JSON, so the ergonomics (defaults, camelCase, types) live in
npm/src/index.ts rather than in Rust.

The lockfile is passed as a string, so nothing touches the filesystem. That
is why this is a wasm-bindgen build rather than WASI: WASI would have meant
shipping the CLI in a sandbox, writing the lockfile to a temp file for every
call, and being Node-only.

The stale `wasm32-wasi` note in Cargo.toml is gone; that target was renamed
to wasm32-wasip1 in Rust 1.78 and removed in 1.84. npm/build.sh is now the
one place that knows how to build it.

On a tag, CI checks that the tag, Cargo.toml and package.json agree, then
publishes to npm with provenance and attaches the .wasm to the release. The
.wasm is never committed.

Verified against the CLI: 700 checks over four lockfiles (whyText, JSON
output and records, across default/-D/-d) produce identical output.
@riquito
riquito merged commit 62af09e into master Sep 2, 2026
3 checks passed
@riquito
riquito deleted the npm-library branch September 2, 2026 06:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant