Skip to content

build: drop the unused sharp dependency so a failed binary download can't break the deploy - #230

Open
NitinKumar004 wants to merge 1 commit into
gofr-dev:mainfrom
NitinKumar004:fix/drop-unused-sharp
Open

NitinKumar004 wants to merge 1 commit into
gofr-dev:mainfrom
NitinKumar004:fix/drop-unused-sharp

Conversation

@NitinKumar004

Copy link
Copy Markdown
Contributor

Why

The website stage pipeline failed on development (gofr-dev/gofr run 37425616104), in the "Dockerize" job, at yarn install --frozen-lockfile:

sharp: Downloading https://github.com/lovell/sharp-libvips/releases/download/v8.14.5/libvips-8.14.5-linuxmusl-x64.tar.br
prebuild-install warn install No prebuilt binaries found (target=7 runtime=napi arch=x64 libc=musl platform=linux)
gyp ERR! find Python ... Could not find any Python installation to use
error /app/node_modules/sharp: Command failed.

sharp@0.32.6 downloads its native binary from GitHub releases on every install. When that download fails, it falls back to compiling with node-gyp, and the node:24.19.0-alpine3.24 builder has no Python. The binary does exist (sharp-v0.32.6-napi-v7-linuxmusl-x64.tar.gz returns 200), and the same build passes from a clean cache on linux/amd64, so this was a failed download. Any one failed download breaks the deploy, though, and the gofr docs/Dockerfile stage runs a second npm install that fetches it again.

The site doesn't need sharp:

  • It is a static export with images: { unoptimized: true } (next.config.mjs), so Next's image optimiser, the thing sharp is for, never runs.
  • Nothing in src/ imports it.

Change

  • Removes sharp from devDependencies.
  • Removes sharp and the 38 packages only it pulled in (prebuild-install, tar-fs, node-abi, ...) from yarn.lock and package-lock.json. Both lockfiles lose the same 39 entries.
  • No other lockfile entry changes. I didn't use yarn remove, because it also rewrote unrelated stale entries (algolia, typescript, @next/swc-*).

Testing

I reproduced the full stage pipeline locally for main and for this branch, with Node 24, against gofr development (6e9bf3cd):

  1. yarn install --frozen-lockfile;
  2. the website builder (changelog RSS, llms-full, next build);
  3. the gofr docs/Dockerfile overlay, including AGENTS.md;
  4. npm install;
  5. npm run build, including check-changelog.

npm ci --dry-run also accepts the edited package-lock.json.

main this branch
pipeline passes passes
sharp installed yes no
files in out/ 580 580
visible text of all 145 HTML pages — identical to main
images, CSS, fonts, .md — byte-identical
sitemap 117 URLs same 117 URLs (order and lastmod differ between any two builds)

The only other differences are build noise: webpack chunk ids, where the two renamed chunks hold the same code, and the 8x8 blurDataURL that Next computes for static image imports, which uses its built-in encoder instead of sharp. The site never sets placeholder="blur", so that placeholder isn't rendered.

next build now prints Next's "sharp is strongly recommended for production Image Optimization" warning. It refers to the runtime optimiser, which a static export doesn't have.

sharp is only Next's runtime image optimiser. The site is a static export
with images.unoptimized, so nothing uses it, but every install still
downloaded its prebuilt binary from GitHub releases and fell back to a
node-gyp source build when that download failed. The Alpine builder has
no Python, so one failed download broke the website stage pipeline
(gofr-dev/gofr run 37425616104).

Removes sharp and the 38 packages only it pulled in from package.json,
yarn.lock and package-lock.json. No other entry changes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant