Vercel's deploy security check was blocking the showcase-docs build with:
Build Failed
Vulnerable version of next-mdx-remote detected (5.0.0). Please update
to version 6.0.0 or later.
The previous build pipeline fix (npm install + postinstall sibling
scripts) is working — the install runs cleanly and `next build` even
compiles successfully. The deploy is rejected by Vercel's vulnerability
scanner before promotion.
Bump `next-mdx-remote` from ^5.0.0 to ^6.0.0 and refresh the
package-lock. v6's main behavior change is `blockJS` / `blockDangerousJS`
defaulting to `true`, but our content uses JSX components and code-block
embeds rather than raw `{expression}` interpolations, so the existing
MDXRemote call sites need no option changes. Verified with a clean local
`next build` of shell-docs (29/29 pages, no errors).
Two layered Vercel deploy failures, fixed together:
1. The original `functions` block in vercel.json globbed `app/og/**`
for a non-api App Router route. Vercel's `functions` only resolves
under `api/` (or `app/api/...`), so any glob matching `src/app/og/`
throws "doesn't match any Serverless Functions inside the 'api'
directory" regardless of the prefix.
Fix: drop the `functions` block, set `maxDuration` inline via
Next.js's segment config in
`src/app/og/[...slug]/route.tsx` (`export const maxDuration = 60`).
Matches the upstream `docs/` package's intent for the same route.
2. With (1) cleared, the next deploy attempt fell over on the install
step:
Scope: all 53 workspace projects
WARN Ignoring not compatible lockfile at /vercel/path0/pnpm-lock.yaml
WARN GET https://registry.npmjs.org/... ERR_INVALID_THIS
Vercel auto-detected pnpm at the repo root and tried a workspace-
wide install. shell-docs is intentionally NOT in
`pnpm-workspace.yaml` — it's a flat standalone Next.js app that
ships its own `package-lock.json` (same setup as `shell-dashboard`,
which is also out-of-workspace and uses npm).
Fix: add `vercel.json` with `installCommand: "npm install ..."`
and `buildCommand: "npm run build"` so Vercel uses the local
package-lock.json instead of walking up into the pnpm workspace.
Mirrors the `Dockerfile`'s `npm install` path used by Railway.
shell-docs's build script shells out to sibling
`tsx ../scripts/generate-registry.ts` etc., so the
`showcase/scripts/` package's deps need to be installed too. Add a
`postinstall` hook to `showcase/shell-docs/package.json` that
does `cd ../scripts && npm install` — same pattern already in
`showcase/shell-dashboard/package.json` for the same reason.
The shell-docs Docker build fails because link-to-copilot-cloud.tsx
imports from lucide-react but the package was never added to
shell-docs/package.json. Adding it at ^0.469.0 to match sibling
showcase packages.
Brings PostHog, GA4, HubSpot, Reo.dev, Scarf, and RB2B into shell-docs
with parity to docs/. Adds the client-side PostHog provider with
session-stitched bootstrap and pageview capture, the AnalyticsClient
wrapper that mounts RB2B + GA4 hooks behind a single client boundary,
the Scarf pixel for OSS attribution, and the HubSpot and Reo.dev
scripts.
Renames POSTHOG_PROJECT_KEY to POSTHOG_KEY across shell and shell-docs
middlewares so the env names match the upstream pattern, and env-drives
POSTHOG_HOST with eu.i.posthog.com as the fallback.
Now that generated JSON is gitignored, every path that consumes these
files must run generators first. Fixes:
- shell: add bundle-demo-content to dev preamble (eliminates race
between watcher and Next.js on fresh clone); add
bundle-starter-content to Dockerfile RUN chain
- shell-dojo: add predev hook (generate-registry + bundle-demo-content)
- shell-docs: add predev hook (generate-registry + bundle-demo-content
+ generate-search-index)
- ops: replace direct COPY of gitignored registry.json with
generate-registry.ts at build time (copy scripts+shared+packages,
npm ci, run generator)
- Add `engines.node >=18.18` to match Next.js 15 runtime requirements.
- Align `npm run start` with the dev port (3003) for local parity; the
Docker runner sets PORT=10000 via ENV and is unaffected.
- Drop unused dependencies that are not imported anywhere in shell-docs:
`react-markdown`, `react-syntax-highlighter`, `rehype-raw`, and
`@types/react-syntax-highlighter`. These are used in showcase/shell/
but not here; removing them keeps the dependency surface honest.
- Regenerate package-lock.json to match.