Skip to content

Correct the stale metadata in package.json - #62

Open
kogai wants to merge 2 commits into
claude/fast-xml-parser-v5from
claude/fix-package-metadata
Open

kogai wants to merge 2 commits into
claude/fast-xml-parser-v5from
claude/fix-package-metadata

Conversation

@kogai

@kogai kogai commented Sep 13, 2026

Copy link
Copy Markdown
Owner

package.json の、実体を指していないフィールドを直します。#57 のレビューで挙がった件を、依存バージョンの更新と混ぜないよう切り出したものです。

base は #59(npm 系の変更が #56 → #57 → #59 → 本 PR と連なっているため)。

変更内容

フィールド 変更前 問題
description "## Prior Art" 初期 README の断片がそのまま入っていた
main "sandbox.js" そのファイルはリポジトリに存在しない
directories.test "test" test/ は Haskell の HUnit スイートで npm とは無関係
scripts.test echo ... && exit 1 常に失敗するプレースホルダ。実体は make test と bazel の e2e
repository / bugs / homepage kogai/onix このリポジトリは kogai/onix-codegen

main・directories・scripts.test は、正しい値を書くのではなく削除しました。いずれも「このパッケージには無いもの」を指しているので、書き直すべき正解が無いためです。

ライセンス表記が 3 箇所で食い違っています(要判断)

これは編集ではなく判断が必要なので、この PR では触っていません。

場所 記載
LICENSE MIT
package.yaml / onix.cabal BSD3
package.json ISC

LICENSE ファイル(MIT, Copyright (c) 2020 Shinichi Kogai)が実体だと思われますが、どれが正なのかは作者にしか判断できません。こちらで揃えると、もし LICENSE 側が誤りだった場合に誤りを広げてしまうので、指摘に留めます。どれに揃えるか教えていただければ、別 PR で対応します。

同様に、peerDependencies に fast-xml-parser があるのに "private": true が無い点も、公開の意図が分からないため触っていません。生成される TS クライアント側の宣言のつもりであれば、この package.json は生成器のものなので置き場所が違う可能性があります。

確認

  • npm install 後も package-lock.json に差分が出ないこと(.npmrc により lockfileVersion は 1 のまま)を確認済み
  • 削除した各フィールドが実体を持たないことを確認(sandbox.js は存在せず、test/ は test/Spec.hs 以下の Haskell テスト)

🤖 Generated with Claude Code

https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z


Generated by Claude Code

Fields that describe something that is not there:

- description was the literal string "## Prior Art", a fragment of an
  early README
- main pointed at sandbox.js, which does not exist in the repository
- directories.test pointed at test/, which is the Haskell HUnit suite,
  not an npm one
- the test script only ever ran `exit 1`; the real suites are `make test`
  and the bazel e2e target
- repository, bugs and homepage all pointed at kogai/onix, while this
  repository is kogai/onix-codegen

Raised in review of #57 and split out from it so the dependency bump
stayed a dependency bump.

Not touched, because it needs an answer rather than an edit: the declared
licence disagrees in three places. LICENSE is MIT, package.yaml and
onix.cabal say BSD3, package.json says ISC. Picking one is the
maintainer's call, so it is described in the pull request instead.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z

kogai commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

レビュー結果

削除・書き換えの前提を一つずつ裏取りしましたが、すべて事実で、この差分に誤りは見つかりませんでした。sandbox.js は全 ref の全コミットを通じて一度も存在せず参照もゼロ、test/ は package.yaml の tests.onix-test(main: Spec.hs / HUnit)が指す Haskell スイート、npm test を呼ぶ箇所はツリー内に一つもなく(CI は make test と npx bazelisk test //e2e/go:snapshot_test)、main/directories の読み手も存在しません。kogai/onix は現存せず(kogai 配下で onix を名前に含むリポジトリは onix-codegen のみ)、3 つの URL 形式も npm の慣例どおりで全て 200 です。ラウンドトリップも確認済みで、npm install 後の package-lock.json は 1 バイトも動きません。よって 必須の指摘はなし、マージ可です。以下は「この PR が直しに来た性質の汚れで、まだ残っているもの」についての提案で、いずれもマージをブロックするものではありません。


必須

なし。

推奨

1. license: "ISC" は、3 者不一致というより「唯一の実体 (MIT) と 2 つのテンプレート既定値」です — この PR の基準なら対象内かもしれません

  • ファイル: package.json
  • 問題: PR 本文は「どれが正か作者にしか判断できない」として保留していますが、3 つを横に並べると対称ではありません。package.yaml の BSD3 は、同じファイルの github: "githubuser/onix" / author: "Author name here" / maintainer: "example@example.com" / copyright: "2020 Author name here" と一体で、stack new テンプレートが未編集で残ったものです(onix.cabal はそれを hpack が生成したもの)。ISC も同様に npm init の既定値です。一方 LICENSE だけは MIT 全文 + Copyright (c) 2020 Shinichi Kogai と、人が意図して書いた形跡があります。
  • なぜ重要か: 「実体を指していないフィールドを直す」というこの PR の基準に照らすと、ISC は main: "sandbox.js" と同じカテゴリ(誰も宣言していない値)です。かつライセンス表記は、リポジトリを利用する側が最初に見るフィールドでもあります。
  • 具体的な修正: "license": "ISC" → "license": "MIT"。package.yaml / onix.cabal 側は作者判断として本 PR では触れない、という現在の切り分けは維持で構いません。判断を仰ぐ方針を崩したくない場合は、せめて追従用の issue を立てておくのが安全です。

2. "private": true を入れると、peerDependencies の宙ぶらりんも含めて一括で解決します

  • ファイル: package.json
  • 問題: npm レジストリ上の onix は既に別パッケージ(GitbookIO/node-onix、現行 1.0.3)に取られています。つまりこの名前でこの package.json を publish することは原理的にできません(version: "1.0.0" も 1.0.3 より前です)。実際この manifest は WORKSPACE の npm_install(package_json = "//:package.json") と npx bazelisk を動かすためだけに存在しています。
  • なぜ重要か: "private": true を明示すれば、誤 publish が npm 側で弾かれるうえ、license / author / keywords / version の「公開パッケージとしての正しさ」を今後問い続ける必要がなくなります。PR 本文が保留している peerDependencies の件も、private であれば宣言自体が無効化されるので、「生成物側の宣言をここに置くべきか」という設計判断を落ち着いて別途できます。
  • 具体的な修正: トップレベルに "private": true を 1 行追加。

任意

3. "dependencies": {} も、削除した 2 つと同じ「空の実体」です

  • ファイル: package.json
  • 問題: 空オブジェクトで、npm install の挙動にも lockfile にも影響しません。
  • なぜ重要か: 重要ではありません。ただ main / directories を「正しい値が無いから削除」した判断と揃えるなら、これも削除対象になります。
  • 具体的な修正: "dependencies": {} の行を削除。残す判断でも実害はありません。

4. scripts を丸ごと消した判断に賛成です。代替スクリプトは足さないことを推奨します

  • ファイル: package.json
  • 検証結果: 削除後の npm test は npm error Missing script: "test" で exit 1。削除前は Error: no test specified で exit 1。どちらも失敗で回帰はなく、後者より前者のほうが「そもそも npm のテストは無い」という事実に忠実です。npm install は scripts 不在でも警告を一切出しません(下記ログ)。
  • 見解: "test": "make test && npx bazelisk test //e2e/go:snapshot_test" のような委譲スクリプトは足さないほうが良いと考えます。make test は stack/GHC を要求するので、TypeScript 側だけを触る人の npm test が環境起因で落ちます。また CI はこの 2 つを意図的に別ジョブ(Test haskell codes / Test e2e)に分けており、1 コマンドに束ねると CI の構造と二重管理になります。
  • 具体的な提案: 発見容易性が目的なら、置き場所は package.json ではなく README です。現状 README は Prior Art で終わっていてビルド/テスト手順の記載が一切ないので、make test と bazel ターゲットはそちらに書くのが筋が良いです(本 PR の範囲外で構いません)。

5. 同じ種類の stale URL が package.yaml / onix.cabal にも残っています

  • ファイル: package.yaml:3,20、onix.cabal:11-13,26
  • 問題: github: "githubuser/onix"、homepage: https://github.com/githubuser/onix#readme、bug-reports: https://github.com/githubuser/onix/issues、source-repository head: location: https://github.com/githubuser/onix、および description 内の https://github.com/kogai/onix#readme。この PR が package.json で直したのと同一の問題です。
  • なぜ重要か: 単体では実害はありませんが、kogai/onix / githubuser/onix はどちらも存在しないので、Hackage 等に出す段になると詰みます。
  • 具体的な修正: package.yaml を直して hpack で onix.cabal を再生成(onix.cabal は生成物なので直接編集しない)。author / maintainer / copyright も同時に埋まるので、上記 1 のライセンス判断と一緒に別 PR にするのが自然です。

6. author: "" / keywords: [] / version: "1.0.0"

  • ファイル: package.json
  • 問題: いずれも npm init の既定値のままです。version は package.yaml の 0.1.0.0 とも食い違っています。
  • なぜ重要か: 上記 2 の "private": true を入れるなら、これらは実質意味を持たなくなるので放置で問題ありません。入れない場合のみ、author は LICENSE に実名(Shinichi Kogai)があるのでリスクゼロで埋められます。
  • 具体的な修正: "private": true を採用するなら対応不要。

検証した内容

すべて read-only の git 操作と、リポジトリ外の一時ディレクトリでのみ実行しています。作業ツリーには触れていません。

sandbox.js は全履歴で一度も存在しない

$ git ls-tree -r --name-only origin/claude/fix-package-metadata | grep -i sandbox
(出力なし)
$ git log --all --oneline -- sandbox.js
(出力なし)
$ git log --all --oneline --diff-filter=A -- '*sandbox*'
(出力なし)
$ git grep -In -i sandbox origin/claude/fix-package-metadata -- .
(出力なし)

過去に消されたのではなく、どの ref のどのコミットにも存在したことがありません。参照もゼロです。main: "sandbox.js" は最初から実体の無い値でした。

test/ は Haskell スイート

$ git ls-tree -r --name-only origin/claude/fix-package-metadata -- test/
test/Spec.hs
test/TestCode.hs
test/TestMixed.hs
test/TestModel.hs
test/TestParser.hs
test/TestUtils.hs

package.yaml の tests.onix-test が main: Spec.hs / source-dirs: test / HUnit == 1.6.1.0 を宣言しており、npm 由来のファイルは 1 つもありません。

npm test の呼び出し元はゼロ / main・directories の読み手もゼロ

$ git grep -In -E 'npm (run )?test|yarn test|npm ci|npm install|npm run' origin/claude/fix-package-metadata -- .
origin/claude/fix-package-metadata:.github/workflows/test.yml:45:      - run: npm install

唯一の npm 呼び出しは e2e ジョブの npm install で、その次の行が npx bazelisk test //e2e/go:snapshot_test です。Haskell ジョブは make test(= stack test --trace --fast)。package.json を参照するのは WORKSPACE の npm_install(package_json = "//:package.json", package_lock_json = "//:package-lock.json") だけで、これは main も directories も読みません。require("onix") 相当の参照、files / exports / types フィールドも存在せず、生成される TS(generated/typescript/v2/*.ts)は package.json と一切結線されていません。

リポジトリ同定と 3 つの URL 形式

$ search_repositories "user:kogai onix in:name"
total_count: 1 -> kogai/onix-codegen (created 2020-12-29)
$ curl -sSL -o /dev/null -w "%{http_code}" https://github.com/kogai/onix-codegen.git        -> 200
$ curl -sSL -o /dev/null -w "%{http_code}" https://github.com/kogai/onix-codegen/issues     -> 200
$ curl -sSL -o /dev/null -w "%{http_code}" https://github.com/kogai/onix-codegen#readme     -> 200
$ git ls-remote https://github.com/kogai/onix-codegen.git HEAD                              -> OK

kogai/onix は存在しません。go.mod の module github.com/kogai/onix-codegen と BUILD.bazel の # gazelle:prefix github.com/kogai/onix-codegen とも一致します。3 形式(git+https://….git / …/issues / …#readme)はいずれも npm の標準形で、変更後の値が正しいです。description も README 冒頭の一文と一致しています。

ラウンドトリップ(リポジトリ外の一時ディレクトリ、npm 10.9.7 / node 22.22.2)

package.json / package-lock.json / .npmrc の 3 ファイルだけをコピーして実行しました。

$ npm install
added 11 packages, and audited 12 packages in 1s
8 packages are looking for funding
found 0 vulnerabilities
(exit 0、scripts / main 不在に関する警告は一切なし)

$ diff -u lock.orig package-lock.json
(差分なし)

$ diff -u <(git show origin/claude/fix-package-metadata:package.json) package.json
(差分なし)

base (claude/fast-xml-parser-v5) と head の package-lock.json は cmp でバイト一致であることも確認済みです。実 CI 側でも、npm install を実際に走らせる Test e2e ジョブが head 6fe5219 で success になっています。

npm test の前後比較

変更後: $ npm test -> npm error Missing script: "test"    (exit 1)
変更前:            -> Error: no test specified             (exit 1)

ライセンス 3 箇所の実値(PR 本文の記載どおり)

LICENSE:1                    MIT License / Copyright (c) 2020 Shinichi Kogai
package.yaml:4               license: BSD3
onix.cabal:17                license:        BSD3
package.json:20              "license": "ISC"

検証できなかったこと

  • npm への公開意図: 上記 2 の "private": true 提案は「このパッケージを publish する予定はない」という前提に立っています。onix が既に他者のパッケージであることは確認しましたが、@kogai/onix-codegen のようなスコープ付きへの改名で公開する構想がある可能性は否定できません。その場合は private ではなく name の変更が正解になります。
  • どのライセンスが正か: 私が言えるのは「MIT だけが既定値ではなく人が書いた値である」という状況証拠までで、最終判断は著作権者にしかできません。
  • CI の npm 6 環境での再現: ローカル検証は npm 10 です。CI は node-version: 12.x(npm 6)で、そこでは .npmrc の lockfile-version=1 は no-op(npm 6 は元々 v1 しか書かない)です。この環境での lockfile 安定性については、green の Test e2e チェックが実証になっています。
  • bazel / stack の実行: 共有クローンを汚さないため、npx bazelisk test //e2e/go:snapshot_test と make test はローカルで走らせていません。前者は CI で success、後者(Test haskell codes)はレビュー時点で in_progress でしたが、package.json には依存しないジョブなので影響はないと見ています。

Generated by Claude Code

Review made the case that "license": "ISC" belongs in this PR after all.
The three declared licences are not three considered opinions: BSD3 sits
in package.yaml next to github: "githubuser/onix", author: "Author name
here" and maintainer: "example@example.com", which is an unedited
`stack new` template, and ISC is what `npm init` writes by default. Only
LICENSE — MIT, Copyright (c) 2020 Shinichi Kogai — shows any sign of
being chosen. So ISC is the same kind of placeholder as the main and
directories fields this PR already removed, and pointing it at the file
that actually governs is not picking a licence.

package.yaml and onix.cabal are still left alone: changing the Haskell
package's declared licence is the part that needs the author, and it is
described in the pull request.

Also mark the package private. The npm name "onix" is already taken by
another publisher, so this manifest cannot be published as it stands; it
exists to feed npx bazelisk. Saying so directly settles the accuracy of
version, author and keywords, and answers the peerDependencies question
the pull request raised.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant