Skip to content

stpa is broken under Node — every subcommand that spawns a tool dies #11

Description

@MyAlterLego

What

PR #9 (59c6861 feat: run on Node or Bun — Bun is no longer an install prerequisite) does not hold. On Node v25.9.0, every stpa subcommand that spawns a tool fails:

$ ./stpa run .stpa
(node:59015) Warning: Failed to load the ES module: .../Tools/RenderReport.ts.
Make sure to set "type": "module" in the nearest package.json file or use the .mjs extension.

.../Tools/RenderReport.ts:25
import { readFileSync, existsSync, writeFileSync } from "node:fs";
^^^^^^
SyntaxError: Cannot use import statement outside a module

Only ./stpa --help works, because the launcher never spawns a child. Bun is fine: bun stpa run completes the whole pipeline.

Root cause

The two halves disagree about module system, and fixing one breaks the other:

  1. Tools/*.ts are ESM. The repo has no package.json, so Node resolves .ts as CommonJS and every import is a syntax error. --experimental-strip-types does not change this — it strips types, it does not change module resolution.
  2. Adding package.json with {"type":"module"} fixes every tool — and then breaks the launcher, because stpa is CJS:
$ ./stpa run .stpa       # with {"type":"module"} present
const { spawnSync } = require("node:child_process");
                      ^
ReferenceError: require is not defined in ES module scope

So a fix needs both halves. Options:

  • package.json with {"type":"module"} and convert stpa to ESM import (it uses require at lines 24-26), or
  • rename the tools to .mts and leave the launcher alone, or
  • keep stpa CJS by giving it a .cjs extension, or createRequire.

Why CI did not catch it

.github/workflows/ci.yml installs oven-sh/setup-bun@v2, invokes tools as bun Tools/X.ts, and never runs Node at all. It also never exercises ./stpa <subcommand> past --help. The one runtime PR #9 was written to support is the one runtime CI does not test — so the feature shipped green and broken.

Whatever the fix, CI should gain a Node job that runs ./stpa run Examples/ledgerline end-to-end. A claim about a runtime that no job exercises is not a tested claim.

Reproduce

node --version                          # v25.9.0
./stpa --help                           # works
node Tools/RenderReport.ts --help       # SyntaxError
./stpa run Examples/ledgerline          # SyntaxError, no report
bun stpa run Examples/ledgerline        # works

Also noticed

  • Tools/DiscoveryGate.ts:275 writes its template with writeFileSync and no mkdir, so pointing it at a directory with no .stpa/ inside dies with a raw ENOENT stack trace instead of a usable message.
  • Several tool usage strings still say bun ControlInventory.ts, which contradicts the Node-or-Bun claim.
  • The committed Examples/ledgerline/REPORT.html is stale against RenderReport.ts — regenerating it adds 5 lines of .corr CSS that a later commit introduced.

🤖 Generated with Claude Code

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions