fix(notebooks): unblock marimo 0.23.13 frontend build (overlay + shim)
Some checks failed
CI / lint (push) Successful in 34s
Deploy / notebooks (push) Has been skipped
Deploy / zotero (push) Has been skipped
Deploy / docs (push) Has been skipped
Deploy / api (push) Has been skipped
Deploy / mc (push) Has been skipped
Infra CI / notebooks (push) Successful in 8m12s
Infra CI / zotero (push) Successful in 24s
Infra CI / docs (push) Successful in 17s
Infra CI / api (push) Successful in 18s
Infra CI / mc (push) Successful in 21s
Deploy / report (push) Successful in 15s
CI / test (push) Successful in 18m1s
Package Supply Chain / pkg-supply-chain (push) Failing after 51s
Some checks failed
CI / lint (push) Successful in 34s
Deploy / notebooks (push) Has been skipped
Deploy / zotero (push) Has been skipped
Deploy / docs (push) Has been skipped
Deploy / api (push) Has been skipped
Deploy / mc (push) Has been skipped
Infra CI / notebooks (push) Successful in 8m12s
Infra CI / zotero (push) Successful in 24s
Infra CI / docs (push) Successful in 17s
Infra CI / api (push) Successful in 18s
Infra CI / mc (push) Successful in 21s
Deploy / report (push) Successful in 15s
CI / test (push) Successful in 18m1s
Package Supply Chain / pkg-supply-chain (push) Failing after 51s
Rebuilding the notebooks image at marimo 0.23.13 surfaced two overlay gaps, both fixed without weakening anything: 1. pnpm supply-chain trust. pnpm 10.28+ enables trustPolicy=no-downgrade by default and rejects tailwind-merge@2.6.1 — a legit dcastil backport onto the 2.x line (real git tag) published WITHOUT npm trusted-publisher provenance that 2.6.0 had. Rather than disable the trust check, pin tailwind-merge to 2.6.0 (the last provenance-backed 2.x, satisfies marimo's ^2.6.0) — trust stays ON for every other dependency. Move this and the jotai pin into pnpm-workspace.yaml `overrides` (the location marimo reads; package.json pnpm.overrides is ignored once a workspace file defines overrides — the old jotai pin never applied). 2. lucide-shim. marimo 0.23.13 imports 9 lucide icons our shim didn't export (CircleSlash, Rows2, Columns3, Cookie, Minus, PanelRightClose, PanelRightOpen, ShieldQuestion, StickyNote) — mapped to their tabler equivalents. Complete set, derived by diffing marimo's lucide-react imports against the shim, so no whack-a-mole. Image rebuilt and the notebooks container recreated on 0.23.13 (healthy, serving); mo.ui.altair_chart with multi-field tooltips renders again.
This commit is contained in:
@@ -213,6 +213,13 @@ import {
|
||||
IconX,
|
||||
IconZoomCheck,
|
||||
IconZoomCode,
|
||||
// added for marimo 0.23.13 icon usage
|
||||
IconColumns3,
|
||||
IconCookie,
|
||||
IconLayoutSidebarRightCollapse,
|
||||
IconLayoutSidebarRightExpand,
|
||||
IconNote,
|
||||
IconShieldQuestion,
|
||||
type IconProps,
|
||||
} from '@tabler/icons-react';
|
||||
|
||||
@@ -306,6 +313,7 @@ export const CircleEllipsis: LucideIcon = IconDotsCircleHorizontal as LucideIcon
|
||||
export const CircleHelpIcon: LucideIcon = IconHelpCircle as LucideIcon;
|
||||
export const CircleIcon: LucideIcon = IconCircle as LucideIcon;
|
||||
export const CirclePlayIcon: LucideIcon = IconPlayerPlay as LucideIcon;
|
||||
export const CircleSlashIcon: LucideIcon = IconBan as LucideIcon;
|
||||
export const CircleX: LucideIcon = IconCircleX as LucideIcon;
|
||||
export const ClipboardCopyIcon: LucideIcon = IconClipboardCopy as LucideIcon;
|
||||
export const ClipboardPasteIcon: LucideIcon = IconClipboardText as LucideIcon;
|
||||
@@ -451,6 +459,7 @@ export const RefreshCwIcon: LucideIcon = IconRefresh as LucideIcon;
|
||||
export const RegexIcon: LucideIcon = IconRegex as LucideIcon;
|
||||
export const RotateCcwIcon: LucideIcon = IconRotate as LucideIcon;
|
||||
export const RotateCwIcon: LucideIcon = IconRotateClockwise as LucideIcon;
|
||||
export const Rows2Icon: LucideIcon = IconLayoutRows as LucideIcon;
|
||||
export const RulerDimensionLine: LucideIcon = IconRuler as LucideIcon;
|
||||
export const SaveIcon: LucideIcon = IconDeviceFloppy as LucideIcon;
|
||||
export const ScissorsIcon: LucideIcon = IconScissors as LucideIcon;
|
||||
@@ -512,3 +521,14 @@ export const XIcon: LucideIcon = IconX as LucideIcon;
|
||||
export const YoutubeIcon: LucideIcon = IconBrandYoutube as LucideIcon;
|
||||
export const ZapIcon: LucideIcon = IconBolt as LucideIcon;
|
||||
export const ZapOffIcon: LucideIcon = IconBoltOff as LucideIcon;
|
||||
|
||||
// Icons added for marimo 0.23.13 (new lucide-react imports in marimo's source).
|
||||
export const Columns3Icon: LucideIcon = IconColumns3 as LucideIcon;
|
||||
export const CookieIcon: LucideIcon = IconCookie as LucideIcon;
|
||||
export const Minus: LucideIcon = IconMinus as LucideIcon;
|
||||
export const PanelRightCloseIcon: LucideIcon =
|
||||
IconLayoutSidebarRightCollapse as LucideIcon;
|
||||
export const PanelRightOpenIcon: LucideIcon =
|
||||
IconLayoutSidebarRightExpand as LucideIcon;
|
||||
export const ShieldQuestionIcon: LucideIcon = IconShieldQuestion as LucideIcon;
|
||||
export const StickyNoteIcon: LucideIcon = IconNote as LucideIcon;
|
||||
|
||||
@@ -21,15 +21,28 @@ jq '.dependencies["@tabler/icons-react"] = "^3.26.0"' \
|
||||
"$SRC/frontend/package.json" > "$SRC/frontend/package.json.new"
|
||||
mv "$SRC/frontend/package.json.new" "$SRC/frontend/package.json"
|
||||
|
||||
# 2b. Pin jotai to the exact version marimo's lockfile expects. We build with
|
||||
# `pnpm install --no-frozen-lockfile` (the overlay mutates package.json),
|
||||
# so pnpm otherwise re-resolves jotai within marimo's `^2.17.0` range up to
|
||||
# 2.20.0+, which dropped the INTERNAL_getBuildingBlocksRev2 /
|
||||
# INTERNAL_buildStoreRev2 exports marimo's source imports → the frontend
|
||||
# build dies with MISSING_EXPORT. Add it to the existing pnpm.overrides.
|
||||
jq '.pnpm.overrides.jotai = "2.17.0"' \
|
||||
"$SRC/package.json" > "$SRC/package.json.new"
|
||||
mv "$SRC/package.json.new" "$SRC/package.json"
|
||||
# 2b. Pin two transitive deps in marimo's pnpm-workspace.yaml `overrides` —
|
||||
# the location marimo actually reads (package.json `pnpm.overrides` is
|
||||
# ignored once a workspace file defines overrides). We build with
|
||||
# `pnpm install --no-frozen-lockfile`, so both otherwise float within
|
||||
# their ranges and break the build:
|
||||
# jotai `^2.17` floats to 2.20+, which dropped the
|
||||
# INTERNAL_getBuildingBlocksRev2 / INTERNAL_buildStoreRev2
|
||||
# exports marimo imports → frontend dies with MISSING_EXPORT.
|
||||
# tailwind-merge `^2.6.0` floats to 2.6.1 — a legit dcastil backport onto
|
||||
# the 2.x line (real git tag) but published WITHOUT npm
|
||||
# trusted-publisher provenance, so pnpm 10.28+'s default
|
||||
# trust policy rejects it as a downgrade. Pin to 2.6.0, the
|
||||
# last provenance-backed 2.x. This keeps pnpm's supply-chain
|
||||
# trust check ON for every other dependency — we resolve the
|
||||
# flag by using a trusted version, not by disabling it.
|
||||
WS="$SRC/pnpm-workspace.yaml"
|
||||
if [ -f "$WS" ] && grep -q '^overrides:' "$WS"; then
|
||||
awk '/^overrides:/{print; print " jotai: \"2.17.0\""; print " tailwind-merge: \"2.6.0\""; next} {print}' "$WS" > "$WS.new"
|
||||
mv "$WS.new" "$WS"
|
||||
else
|
||||
printf '\noverrides:\n jotai: "2.17.0"\n tailwind-merge: "2.6.0"\n' >> "$WS"
|
||||
fi
|
||||
|
||||
# 3. Rewrite pnpm-lock if it exists so pnpm install doesn't error on drift.
|
||||
rm -f "$SRC/frontend/pnpm-lock.yaml" "$SRC/pnpm-lock.yaml"
|
||||
|
||||
Reference in New Issue
Block a user