fix(deps): the end-to-end test framework ships in the production container #178
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web#178
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
nightwatchis declared independenciesrather thandevDependencies. The Containerfile installsproduction dependencies only —
pnpm install --frozen-lockfile --prodat line 21 andpnpm install --prod --frozen-lockfileat line 37 — so a WebDriver client and its whole closure isinstalled into the image that serves the public site.
Nothing in
src/imports it. It is used bynightwatch.conf.jsandscripts/e2e.mjs, both of whichrun only on a developer machine, via the
pre-pushhook.Roughly 24 MB of the runtime image is test tooling:
selenium-webdriver(~18 MB),nightwatch(~3.3 MB),
axe-core(~2.9 MB), plus transitive dependencies. Beyond the size, a browser-automationclient with no runtime purpose is avoidable attack surface in a public-facing container.
This is independent of any test-framework decision — the same misplacement would ship whichever
framework is used, and it should be corrected before that work rather than folded into it.
What to do
Move
nightwatchtodevDependenciesand refresh the lockfile. Checkgeckodriverand anythingelse test-only at the same time.
Done when
nightwatchis indevDependencies--prodinstall tree contains noselenium-webdriverand nonightwatchpnpm lint,pnpm checkandpnpm testpass