Resolve the SDK by version from the registry, not from a git URL

package.json names @novox/mesh-sdk by version and the install is a
buildkit-secret-mounted resolve from the mesh's package registry, closing the
git-URL half of issue 053. The lock is regenerated against the registry (a
follow-up switches install to ci with a committed lock).

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 10:27:26 +02:00
parent 6b6ec68a43
commit b618057fb1
3 changed files with 2 additions and 120 deletions
+1 -1
View File
@@ -22,7 +22,7 @@ RUN apt-get update \
WORKDIR /app
COPY package.json package-lock.json ./
# Development dependencies included: the compiler is one, and so is the toolkit's own.
RUN npm install --no-audit --no-fund
RUN --mount=type=secret,id=npmrc,target=/root/.npmrc npm install --no-audit --no-fund
# The toolkit arrives compiled. It used to arrive as sources, and this compiled it by hand — the
# hook that builds it on install was running all along, and the result was then packed out of the
# package, because with no explicit file list npm falls back to .gitignore and that ignores the