forgejo/package.json
Adam Moussa 87c4b58da8
fix: declare and pin tsx runner for CDK app
TypeScript 7's native port is incompatible with ts-node, so cdk.json was
switched to tsx — but it was invoked via `npx`, which fetches an
unpinned copy from the registry at synth/deploy time with no lockfile
entry or integrity check.

Declare tsx as a pinned devDependency (~4.23.0) and invoke the local bin
instead of npx. Update the README's cdk.json section to match. Verified
with `npm run build` (tsc 7.0.2) and `cdk synth` — both green.
2026-07-10 17:35:30 -04:00

26 lines
531 B
JSON

{
"name": "forgejo",
"version": "1.0.0",
"bin": {
"app": "bin/app.js"
},
"scripts": {
"build": "tsc",
"cdk": "cdk",
"synth": "cdk synth",
"deploy": "cdk deploy",
"diff": "cdk diff"
},
"devDependencies": {
"@types/node": "^24",
"aws-cdk": "^2.1129.0",
"source-map-support": "^0.5.21",
"tsx": "~4.23.0",
"typescript": "~7.0.2"
},
"dependencies": {
"@aws-cdk/aws-lambda-python-alpha": "2.257.0-alpha.0",
"aws-cdk-lib": "2.261.0",
"constructs": "^10.0.0"
}
}