build: move from pnpm to npm

Replace pnpm-lock.yaml with package-lock.json. Both overrides move to
package.json#overrides, including the request -> @cypress/request alias.
allowBuilds for es5-ext becomes package.json#allowScripts.

The deploy script chained "pnpm register", which would have failed once pnpm
was gone; it now calls npm run register.
This commit is contained in:
tiennm99 committed 2026-08-17 12:20:41 +07:00
1 parent ffdbc7b048
commit 88cfc380f4
7 files changed
+1967 -1372

No files matched your search

+3 -5
View File
@@ -11,16 +11,14 @@ jobs:
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7 - uses: actions/setup-node@v7
with: with:
node-version: '24' node-version: '24'
cache: 'pnpm' cache: 'npm'
- run: pnpm install --frozen-lockfile --ignore-scripts - run: npm ci --ignore-scripts
- run: pnpm lint - run: npm run lint
# Update find roots when adding new top-level JS dirs. # Update find roots when adding new top-level JS dirs.
- name: Syntax check all JS - name: Syntax check all JS
+1 -1
View File
@@ -2,7 +2,7 @@ node_modules/
npm-debug.log* npm-debug.log*
yarn-debug.log* yarn-debug.log*
yarn-error.log* yarn-error.log*
pnpm-debug.log* npm-debug.log*
.env .env
.env.local .env.local
+7 -7
View File
@@ -60,12 +60,12 @@ Storage uses Upstash Redis keys: `admin`, `group:{chatId}`, `apple:{appId}`,
```sh ```sh
git clone https://github.com/tiennm99/store-scraper-bot git clone https://github.com/tiennm99/store-scraper-bot
cd store-scraper-bot cd store-scraper-bot
pnpm install npm install
cp .env.example .env.local cp .env.example .env.local
# Fill in TELEGRAM_BOT_TOKEN, UPSTASH_REDIS_REST_URL, UPSTASH_REDIS_REST_TOKEN, etc. # Fill in TELEGRAM_BOT_TOKEN, UPSTASH_REDIS_REST_URL, UPSTASH_REDIS_REST_TOKEN, etc.
vercel link vercel link
vercel env pull .env.local vercel env pull .env.local
pnpm dev # vercel dev — local webhook tunnel npm run dev # vercel dev — local webhook tunnel
``` ```
--- ---
@@ -87,7 +87,7 @@ Set these as Vercel environment variables (or in `.env.local` for local dev):
| `APP_CACHE_SECONDS` | No | Upstream scraper cache TTL in seconds (default: `600`) | | `APP_CACHE_SECONDS` | No | Upstream scraper cache TTL in seconds (default: `600`) |
| `NUM_DAYS_WARNING_NOT_UPDATED` | No | Default stale threshold in days (default: `30`) | | `NUM_DAYS_WARNING_NOT_UPDATED` | No | Default stale threshold in days (default: `30`) |
Operator-only deploy variables (used by `pnpm register` and `pnpm describe`) go in Operator-only deploy variables (used by `npm run register` and `npm run describe`) go in
`.env.deploy` — see `.env.deploy.example`. `.env.deploy` — see `.env.deploy.example`.
--- ---
@@ -95,10 +95,10 @@ Operator-only deploy variables (used by `pnpm register` and `pnpm describe`) go
## Deploy ## Deploy
```sh ```sh
pnpm deploy # vercel deploy --prod && register webhook + Telegram menu npm run deploy # vercel deploy --prod && register webhook + Telegram menu
``` ```
Re-run `pnpm register` any time `src/bot/commands/index.js` changes — Telegram Re-run `npm run register` any time `src/bot/commands/index.js` changes — Telegram
caches the command menu until `setMyCommands` is called again. caches the command menu until `setMyCommands` is called again.
--- ---
@@ -128,10 +128,10 @@ caches the command menu until `setMyCommands` is called again.
**Credential rotation (quarterly):** **Credential rotation (quarterly):**
- Upstash token — regenerate in Upstash console, update `UPSTASH_REDIS_REST_TOKEN`, redeploy - Upstash token — regenerate in Upstash console, update `UPSTASH_REDIS_REST_TOKEN`, redeploy
- Webhook secret — generate new value, update `TELEGRAM_WEBHOOK_SECRET`, redeploy, then `pnpm register` - Webhook secret — generate new value, update `TELEGRAM_WEBHOOK_SECRET`, redeploy, then `npm run register`
**Dependency note:** The legacy `app-store-scraper → request` transitive is aliased **Dependency note:** The legacy `app-store-scraper → request` transitive is aliased
to the maintained `@cypress/request` fork via pnpm overrides. Store calls still only to the maintained `@cypress/request` fork via npm overrides. Store calls still only
target known endpoints (`itunes.apple.com`, `play.google.com`). target known endpoints (`itunes.apple.com`, `play.google.com`).
--- ---
+1949
View File
File diff suppressed because it is too large. Load diff
+7 -6
View File
@@ -10,14 +10,13 @@
"main": "api/webhook.js", "main": "api/webhook.js",
"scripts": { "scripts": {
"dev": "vercel dev", "dev": "vercel dev",
"deploy": "vercel deploy --prod && pnpm register", "deploy": "vercel deploy --prod && npm run register",
"register": "node --env-file=.env.deploy scripts/register-webhook.js", "register": "node --env-file=.env.deploy scripts/register-webhook.js",
"register:dry": "node --env-file=.env.deploy scripts/register-webhook.js --dry-run", "register:dry": "node --env-file=.env.deploy scripts/register-webhook.js --dry-run",
"describe": "node --env-file=.env.deploy scripts/set-bot-description.js", "describe": "node --env-file=.env.deploy scripts/set-bot-description.js",
"describe:dry": "node --env-file=.env.deploy scripts/set-bot-description.js --dry-run", "describe:dry": "node --env-file=.env.deploy scripts/set-bot-description.js --dry-run",
"lint": "node scripts/check-secret-leaks.js" "lint": "node scripts/check-secret-leaks.js"
}, },
"packageManager": "[email protected]",
"license": "Apache-2.0", "license": "Apache-2.0",
"dependencies": { "dependencies": {
"@upstash/redis": "^1.38.0", "@upstash/redis": "^1.38.0",
@@ -25,9 +24,11 @@
"app-store-scraper": "^0.18.0", "app-store-scraper": "^0.18.0",
"google-play-scraper": "^10.1.3" "google-play-scraper": "^10.1.3"
}, },
"pnpm": { "overrides": {
"onlyBuiltDependencies": [ "request": "npm:@cypress/request@^4.0.1",
"es5-ext" "undici": "7.28.0"
] },
"allowScripts": {
"es5-ext": true
} }
} }
-1347
View File
File diff suppressed because it is too large. Load diff
-6
View File
@@ -1,6 +0,0 @@
allowBuilds:
es5-ext: true
overrides:
request: "npm:@cypress/request@^4.0.1"
undici: "7.28.0"