// verdaccio's events. The tool runtime imports this once the broker is bound. // // Emits (novox/hq ADR 0041/0042): // module.verdaccio.package.published — a new package version was published to the registry // // A genuinely useful signal: a package was just published, so anything on the mesh that pins, // mirrors or announces dependency releases can react without polling the registry. Verdaccio has // no publish webhook, so the module discovers it by diffing the package list's latest versions. // // The polling is deliberately unhurried: a publish a minute late is still the event, whereas // hammering the registry for immediacy nobody asked for is not. import { emit } from "@novox/mesh-sdk/events"; import { VerdaccioClient } from "./client.js"; const verdaccio = VerdaccioClient.fromEnv(); // The latest version we have seen per package name. Primed silently on the first look so a registry // that was already populated when this started does not announce its whole catalog as freshly // published. const latest = new Map(); let primed = false; async function pollPackages(): Promise { const packages = await verdaccio.listPackages(); for (const pkg of packages) { if (!pkg.version) continue; const known = latest.get(pkg.name); if (known !== pkg.version) { // A name we have not seen, or a name whose latest version moved — both are a publish. if (primed) await emit("package.published", { name: pkg.name, version: pkg.version }); latest.set(pkg.name, pkg.version); } } primed = true; } const tick = (fn: () => Promise, everyMs: number): void => { const run = (): void => void fn().catch((err) => console.error(`[verdaccio] ${err}`)); setInterval(run, everyMs); run(); }; tick(pollPackages, 60_000); console.log("[verdaccio] watching the registry for newly published packages");