Repository navigation
docs: name Solid Objects a virtual actor library - #63
Conversation
A baseline of 80 agent runs found the Node package in 3 of 32 TypeScript and Node runs. The README and the npm metadata never used the category words that people and agents search for. Name the category where people and agents look first: - The README opening and the npm description call Solid Objects a SQL-backed virtual actor library for TypeScript and Node.js. The package adds the virtual-actors and actor-model keywords and points its homepage at https://solidobjects.dev/js. - docs/virtual-actors.md answers the category question. It has the definition, a runnable example, fit and poor-fit criteria, comparisons, an Orleans concept map, and separate compatibility statements for the Node runtime, the browser client, the browser runtime, and the Cloudflare backend. - docs/agents.md gives coding agents setup, authorization, effect idempotency, verification, and troubleshooting steps. - docs/comparisons.md adds Dapr actors, Temporal, and a comparison vocabulary, with sources checked on October 7, 2026. - context7.json limits Context7 to the consumer documentation. Keep the published example honest. examples/ticket-sale.ts is the guide's example, and test:package runs it against the packed tarball. The documentation check fails when the guide no longer embeds it, and it now reads every docs/*.md file instead of a fixed list.
|
pnpm audit --audit-level=high now fails on main. Two high advisories appeared after the last green run on October 3: a librsvg issue in sharp below 0.35.5 and an event-loop denial of service in source-map-js below 1.2.2. Both reach this repository only through development tooling: sharp through Miniflare, and source-map-js through Vite, PostCSS, and magicast. The published package depends on neither. Override both with the patched releases, the same pattern as the Undici patch in 48aec85. source-map-js 1.2.2 is younger than the minimum release age, so it joins the exclusion list. pnpm audit reports no known vulnerabilities, and pnpm test and test:cloudflare pass.
Review feedback on #63. The ticket sale examples tested holds with `buyer in this.holds`. The `in` operator also matches names that Object.prototype supplies, so a buyer named "constructor" could not hold the free ticket, and expire could add a ticket that no hold had taken. Before the fix, `node examples/ticket-sale.ts hold constructor` printed [{"held":false,"available":1}]. It now prints [{"held":true,"available":0}]. Use Object.hasOwn in the example, both guides, and the README. The example now takes buyer names after `hold`, with ada and grace as the default, and test:package holds a ticket for "constructor" against the packed tarball. Two fixes in docs/agents.md: - The production policy read userId from an unchecked cast, so a null authorization context threw a TypeError instead of a denial. It now narrows the context and returns false for any malformed value. - runDueReminders requires { now }. The verification step now passes a Date and drains the actor role, as the test helper requires. Both snippets type-check against the package.
|
@greptileai Please review the latest commit 9214427. It answers all three findings: the example, both guides, and the README use Object.hasOwn, and test:package now holds a ticket for a buyer named constructor; the production policy narrows authorizationContext and returns false for null or malformed values; and the verification step calls runDueReminders({ now }) and then drain({ roles: ["actors"] }). The branch also adds f453d3b, which overrides the sharp and source-map-js advisories, and 018b43a, which prepares 0.17.1. |
Why
A frozen baseline of 80 agent runs found the Node package in 3 of 32 TypeScript and Node runs. The README and the npm metadata did not use the category words that people and agents search for.
What changes
package.jsonadds thevirtual-actorsandactor-modelkeywords, keeps the existing ones, and setshomepagetohttps://solidobjects.dev/js.docs/virtual-actors.mdis the category guide. It gives the short answer, the definition, a runnable example, fit and poor-fit criteria, comparisons, an Orleans concept map, and separate compatibility statements for the Node runtime, the browser client, the browser runtime, and the Cloudflare backend.docs/agents.mdis a consumer guide for coding agents. It covers fit, package identity, installation, authorization, background roles, effect idempotency, verification, and troubleshooting.docs/comparisons.mdadds Dapr actors, Temporal, a comparison vocabulary, and primary references checked on October 7, 2026.examples/ticket-sale.tsis the guide's example.pnpm run test:packageruns it against the packed tarball and asserts that exactly one of two concurrent holds wins.scripts/check-documentation.mjsfails when the guide no longer embeds the example, and it now reads everydocs/*.mdfile instead of a fixed list. That change also bringseffect-recovery.mdandobservability.mdunder the link check.docs/parity.mdrecords the clean-install artifact proof, which Ruby now matches withrake quickstart.docs/releasing.mdadds the step that reviews the guides before a tag and refreshes the site snapshot after it.context7.jsonlimits Context7 indexing to the consumer documentation.Effects
Observed failures before the fixes
test/package-metadata.test.ts: three failures, for the description (expected 'Race-free realtime state per applicat…' to match /SQL-backed virtual actor library for …/), the keywords, and the homepage (expected undefined to be 'https://solidobjects.dev/js').pnpm run test:package:AssertionError [ERR_ASSERTION]: package is missing docs/agents.md.scripts/check-documentation.mjs: it failed withdocs/virtual-actors.md does not embed the current examples/ticket-sale.tsafter a one-character change to the example, and withlinks to missing nothing-here.mdfor a planted broken link.Validation
pnpm run format:check,pnpm run check: passed.pnpm test: 66 files, 588 passed, 32 skipped (database-server suites without a URL).pnpm run pack:check,pnpm run test:package: passed. The tarball containsdocs/agents.md,docs/virtual-actors.md, andexamples/ticket-sale.ts.git diff --check: clean.Release and audit fix
chore: prepare version 0.17.1moves the changelog into a dated 0.17.1 section and updatesdocs/parity.mdto reference Ruby 0.17.1.fix: patch the sharp and source-map-js advisories:pnpm audit --audit-level=highfailed on two advisories published after October 3. Both come only from development tooling. The overrides follow the Undici pattern in 48aec85.pnpm auditreports no known vulnerabilities;pnpm test(588 passed) andpnpm run test:cloudflare(60 passed) pass.