import { readFileSync } from 'node:fs' import { join } from 'node:path' import { describe, expect, it } from 'vitest' const pkg = JSON.parse(readFileSync(join(import.meta.dirname, '..', 'package.json'), 'utf8')) describe('runtime dependencies', () => { /** * actor-typeahead renders inside the sign-in form, in the popup, with the * privileges of an extension page — the highest-leverage third-party surface * the extension has, and a 0.x release line that can change shape between * patch versions. An exact range means a bare `npm install` cannot move it * without someone deciding to. * * The lockfile already pins what a release installs (`deploy-ext.sh` runs * `npm ci`); this is the half that covers the development tree. */ it('pins actor-typeahead to an exact version', () => { expect(pkg.dependencies['actor-typeahead']).toMatch(/^\d+\.\d+\.\d+$/) }) })