**VM2 Removal:** - Remove VM2 dependency from package-executor - Rewrite executor to use direct package execution with require() - Add TODO comment for future sandboxing implementation **Why this change:** - VM2 requires runtime filesystem access to bridge.js which doesn't work with Next.js Turbopack bundling - Even marking as serverExternalPackages fails because VM2 uses hardcoded file paths - Direct execution allows builds to complete while we find Next.js-compatible sandboxing solution **Next Steps:** - Implement proper sandboxing with isolated-vm or similar Next.js-compatible solution - Add security measures for package execution - Consider moving package execution to separate microservice This unblocks CI/CD while maintaining playground functionality. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
21 lines
434 B
JSON
21 lines
434 B
JSON
{
|
|
"name": "@tpmjs/package-executor",
|
|
"version": "0.0.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"main": "./src/index.ts",
|
|
"types": "./src/index.ts",
|
|
"scripts": {
|
|
"build": "tsc",
|
|
"type-check": "tsc --noEmit"
|
|
},
|
|
"dependencies": {
|
|
"semver": "^7.6.0"
|
|
},
|
|
"devDependencies": {
|
|
"@tpmjs/tsconfig": "workspace:*",
|
|
"@types/node": "^22.10.2",
|
|
"@types/semver": "^7.5.6",
|
|
"typescript": "^5.9.3"
|
|
}
|
|
}
|