Skip to content

fix(package): drop the unused @rolldown/binding-linux-x64-gnu optionalDependency — it ships a 20 MB bundler binary to every consumer #461

Description

@Shinrai

Problem

The published package.json declares:

"optionalDependencies": { "@rolldown/binding-linux-x64-gnu": "1.1.3" }

Nothing in slothlet uses it — grep -r rolldown dist src → 0 hits. It was added in the v3.3.1 release commit 8c32dd9b (2026-04-29), alongside a rolldown override, apparently to get vitest's native binding installed in CI. It is still present in 3.20.0.

Because it is an optionalDependency (not a devDependency), every consumer installs it, and any tool that stages a package's runtime closure (dependencies + optionalDependencies) ships it to production. In @cldmv/rummage web deploys it is a 20 MB Linux build of a bundler sitting in the server runtime tree — the only build-only package found there (CLDMV/rummage#73).

Fix

  • Remove @rolldown/binding-linux-x64-gnu from optionalDependencies.
  • If CI genuinely needs it for vitest on linux-x64, declare it as a devDependency (or install it in the CI workflow step) so it never reaches consumers.
  • Verify with npm pack --dry-run / a clean consumer install that no @rolldown/* package is pulled in.

Downstream

CLDMV/rummage#73 — once a slothlet release carries this, the rummage runtime staging drops the package with no consumer-side special-casing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: mediumShould be addressed in the normal course of developmentsemver: patchThis release contains only backwards-compatible bug fixesstatus: implementedBuilt and deployed, but not yet fully tested/verifiedtype: bugSomething is broken or not behaving as expectedtype: dependenciesRelates to dependency updates, version bumps, or package management

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions