What breaks
A Worker product that imports only @tangle-network/agent-integrations/catalog and /specs — to describe connectors, never to execute one — fails its bundle:
[UNLOADABLE_DEPENDENCY] Could not load
node_modules/.pnpm/@duckdb+node-bindings-linux-x64@1.5.5-r.2/…/duckdb.node
[UNRESOLVED_IMPORT] Could not resolve '../build/Release/cpufeatures.node'
in node_modules/.pnpm/cpu-features@0.0.10/…/lib/index.js
Measured on legal-agent (Cloudflare Workers, rolldown). Its only imports are /catalog and /specs.
Why
specs/registry.ts → connectors/bundled-manifests.ts → import * as bundledAdapters from './adapters/index.js', which re-exports every adapter so their static manifests can be read. Two of those adapters import a native client at module top level:
connectors/adapters/duckdb.ts → @duckdb/node-api (native addon)
connectors/adapters/sftp.ts → ssh2-sftp-client → ssh2 → cpu-features (native addon)
So reading static manifest data drags two native Node clients into the bundle. A Worker cannot load a .node file at all.
Walking the built graph confirms it: from dist/catalog.js + dist/specs.js, 11 files, reaching @duckdb/node-api.
Versions
0.53.32 introduced @duckdb/node-api; ssh2-sftp-client predates it. The last version a Worker consumer can bundle through these subpaths is 0.53.30 — and legal-agent is currently held at ^0.52.0 because of it, off the latest integrations while every other product is current.
Fix
Load both clients inside the execute path. The manifest is static data; only execution needs a client, and the TYPES erase. PR follows, plus a source-graph test so a new adapter cannot reopen it silently.
What breaks
A Worker product that imports only
@tangle-network/agent-integrations/catalogand/specs— to describe connectors, never to execute one — fails its bundle:Measured on
legal-agent(Cloudflare Workers, rolldown). Its only imports are/catalogand/specs.Why
specs/registry.ts→connectors/bundled-manifests.ts→import * as bundledAdapters from './adapters/index.js', which re-exports every adapter so their static manifests can be read. Two of those adapters import a native client at module top level:connectors/adapters/duckdb.ts→@duckdb/node-api(native addon)connectors/adapters/sftp.ts→ssh2-sftp-client→ssh2→cpu-features(native addon)So reading static manifest data drags two native Node clients into the bundle. A Worker cannot load a
.nodefile at all.Walking the built graph confirms it: from
dist/catalog.js+dist/specs.js, 11 files, reaching@duckdb/node-api.Versions
0.53.32introduced@duckdb/node-api;ssh2-sftp-clientpredates it. The last version a Worker consumer can bundle through these subpaths is 0.53.30 — and legal-agent is currently held at^0.52.0because of it, off the latest integrations while every other product is current.Fix
Load both clients inside the execute path. The manifest is static data; only execution needs a client, and the TYPES erase. PR follows, plus a source-graph test so a new adapter cannot reopen it silently.