Skip to content

docs: document vg lib lockfile pin and failure modes - #423

Merged
vibgrate-team merged 2 commits into
mainfrom
cursor/docs-vg-lib-lockfile-5d36
Oct 9, 2026
Merged

vibgrate-team merged 2 commits into
mainfrom
cursor/docs-vg-lib-lockfile-5d36

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

### vg lib listed the subcommands and stopped there. A reader couldn't tell which version the page describes, which lockfiles are read, or what happens when the lookup fails. The README also showed vg lib express --fn middleware, a flag vg lib doesn't accept.

DOCS.md now covers:

  • Lockfile pin. The version label is the lockfile pin, then the installed copy, then the declared range. --json reports the choice as source (lockfile, installed, declared or unknown).
  • Which files are read, from the directory you run in (-C changes it): package-lock.json, pnpm-lock.yaml, yarn.lock, poetry.lock, uv.lock, Pipfile.lock, Cargo.lock, Gemfile.lock, composer.lock, packages.lock.json, Package.resolved, pubspec.lock and gradle.lockfile. The lookup skips go.sum (Go keeps the version declared in go.mod), pdm.lock, npm-shrinkwrap.json, bun.lock and Maven lockfiles.
  • When a lookup fails: a missing lockfile entry, a lockfile and install that disagree (version_mismatch on --json), --offline or --local, and a failed catalog fetch. Each names the next action, and none prints credentials or lockfile contents.
  • The only example is vg lib react, and the README matches it and links to the section.

Related issues

Closes #281

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated where behavior is described
  • No proprietary or internal references
  • Commits use Conventional Commits and are signed off

How to verify

Read DOCS.md and the README's vg lib section, then run:

pnpm test
pnpm lint
pnpm typecheck

cursoragent and others added 2 commits October 9, 2026 12:06
Describe lockfile → installed → declared resolution, the lockfiles
that lookup reads, and the offline and registry failure text.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Rewrite the vg lib section so the version label comes from the
lockfiles that are read. go.sum is skipped; Go keeps the version
declared in go.mod.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
@vibgrate-team
vibgrate-team merged commit d04c48b into main Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Docs: document vg lib lockfile-pinned docs fetch and failure modes

2 participants