move SDK into symlink, drop force from installation path - #488
Merged
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Contributor
|
Repository Guard
Repository GuardCargo dependency pinning
Cross-program Anchor/Solana version consistency
solana-program crate pin
Anchor.toml solana_version
Crate minimum age
Yarn package.json pinning
npm minimum age
Workflow toolchain consistency
GitHub Action SHA pinning
Sensitive program / config changes
Overall status: pass Lockfile freshness (Cargo.lock + yarn.lock) is checked by the workflow directly and cannot be bypassed. The sensitive-diff section is a review hint - CODEOWNERS handles the actual merge gate. |
meta-reid
approved these changes
Sep 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tests currently import
@metadaoproject/programsfrom a copy ofsdk/that yarn makes at install time.The CI action caches
node_modulesunder a constant key, and when the root lockfile is unchanged yarn reportsAlready up-to-dateand keeps the stale copy, so SDK changes are invisible to CI until the cache is cleared/evicted.Switching the dependency to
link:./sdkmakes the entry a symlink, so tests always see the currentsdk/dist, which CI andrebuild.shalready rebuild on every run. Drops theyarn install --forceworkaround fromrebuild.shand the docs.Greptile Summary
This PR changes the root SDK dependency from a copied local package to a Yarn-managed symlink so consumers see the current SDK build, removes the forced root reinstall, and updates development documentation accordingly.
link:./sdkfor@metadaoproject/programs.rebuild.sh.Confidence Score: 5/5
The PR appears safe to merge; the linked SDK is built and supplied with its own dependencies by the supported setup and CI workflows.
No actionable failure remains: the lockfile matches Yarn 1 semantics, SDK dependencies are installed within
sdk, andbuild-localgenerates the distribution files consumed through the symlink.Important Files Changed
link:protocol.rebuild.shand documents symlink-based SDK resolution.Reviews (1): Last reviewed commit: "move SDK into symlink, drop force from i..." | Re-trigger Greptile
Context used: