Skip to content

feat!: add pub.dev endpoints and correct search behavior - #79

Merged
leoafarias merged 6 commits into
mainfrom
chore/updated-endpoints
Aug 19, 2026
Merged

leoafarias merged 6 commits into
mainfrom
chore/updated-endpoints

Conversation

@leoafarias

@leoafarias leoafarias commented Aug 19, 2026 •

Copy link
Copy Markdown
Owner

Summary

Audits the client against pub.dev's current routes and live responses, adds the
missing read-only endpoints, fixes search encoding, and prepares version 4.0.0
for release. The final review also tightened the public Dart API documentation,
made obsolete members explicitly deprecated, removed a flaky live assertion,
and repaired the publish workflow.

API additions

Method Endpoint
packageLikes(package) GET /api/packages/<package>/likes — public like count
publisherInfo(id) GET /api/publishers/<id>
packageVersionScore(package, version) GET /api/packages/<package>/versions/<version>/score
packageVersionOptions(package, version) GET /api/packages/<package>/versions/<version>/options
topicNameCompletion() GET /api/topic-name-completion-data

Also added:

  • SearchOrder.trending, matching pub.dev's trend-score ordering.
  • SearchResults.message, which pub.dev returns when it cannot fully honor a
    query.
  • Missing fromMap and fromJson helpers on Repository.
  • Re-exports for the pubspec_parse types exposed by PubPackage.latestPubspec.

topicNameCompletion rejects the versioned Accept header used by the other
endpoints, so _fetch now supports a case-insensitive per-request header
override.

Fixes and compatibility

  • Search queries and tag filters are now encoded with
    Uri.replace(queryParameters:); reserved characters such as # and & no
    longer truncate the request.
  • fetchGooglePackages no longer sends the malformed tools.dart.dev
    publisher tag and now includes labs.dart.dev.
  • The package-like integration test no longer compares two independently
    cached, mutable live counts.
  • SearchOrder.popularity is deprecated in favor of
    SearchOrder.downloads; pub.dev silently treats the old value as top.
  • PackageScore.popularityScore is deprecated in favor of
    downloadCount30Days; pub.dev no longer returns the popularity field.
  • LatestVersion is deprecated because no endpoint or client method produces
    it. It is scheduled for removal in 5.0.0.

Adding SearchOrder.trending extends a public enum. Consumers with exhaustive
switches over SearchOrder must add a trending case. The release is therefore
versioned as 4.0.0 and the migration is called out as a breaking change.

Documentation and cleanup

  • Added caller-facing documentation for the new endpoints and models, including
    field meanings, authentication behavior, retraction semantics, and preferred
    replacements for deprecated APIs.
  • Corrected README examples that had missing arguments, invalid variable scope,
    incorrect return-value claims, and inconsistent Dart formatting.
  • Documented pub.dev's 10-page search limit and how it affects the recursive
    helper methods.
  • Excluded generated *.mapper.dart output from analysis and removed lint rules
    that no longer exist in the current Dart SDK.

Release readiness

  • Bumps the package from 3.2.0 to 4.0.0 with a completed changelog.
  • Removes the Cider sequence that failed against an already-finalized release
    changelog.
  • Uses Dart's official reusable publishing workflow with temporary GitHub OIDC
    credentials; the workflow no longer reads the legacy PUB_CREDENTIALS
    secret.
  • Restricts publication to bare semantic-version tag pushes matching the
    repository convention, with a pub.dev GitHub deployment environment bound
    into the trusted-publisher identity.
  • The normal pull-request workflow uses actions/checkout@v4, current dart run commands, explicit read-only permissions, analysis, and tests.

Validation

  • dart run build_runner build — generated output matches the committed files.
  • dart format --output=none --set-exit-if-changed — 17 changed Dart files,
    no changes required.
  • dart analyze — no issues found.
  • dart test — 76 passed, 1 documented pre-existing skip.
  • dart doc --dry-run . — 0 warnings, 0 errors.
  • actionlint — both GitHub Actions workflows pass.
  • dart pub publish --dry-run — package 4.0.0 validates with 0 warnings.
  • Direct runtime dependencies are current.
  • New endpoint contracts and search behavior were exercised against live
    pub.dev responses and checked against the current pub.dev source.

Audited the client against pub.dev's current route table, the officially
supported API doc, and the hosted repository spec v2.

Adds five public, read-only endpoints:
- packageLikes            GET /api/packages/<pkg>/likes
- publisherInfo           GET /api/publishers/<id>
- packageVersionScore     GET /api/packages/<pkg>/versions/<v>/score
- packageVersionOptions   GET /api/packages/<pkg>/versions/<v>/options
- topicNameCompletion     GET /api/topic-name-completion-data

Fixes search query encoding: the query was interpolated into the URL raw,
so a `#` opened a URI fragment and an `&` terminated the query string,
silently truncating the search. Verified against pub.dev that `flutter` and
`flutter#zzzz` previously returned identical results.

Deprecates SearchOrder.popularity, which pub.dev no longer accepts and
serves as `top`, and adds the SearchOrder.trending it does accept.
Verified each new endpoint against pub.dev's response DTOs in
pkg/_pub_shared/lib/data and swept 31 package/version pairs plus 9
publishers. Records why likeCount/tags/package/likes stay non-nullable
despite the server DTOs declaring them optional, and notes the gzip
requirement on package-names and topic-name-completion-data.
Deprecate obsolete API members, tighten public documentation, and remove a mutable live-count assertion. Modernize CI and make the 3.3.0 publish path validate the release tag and package before publishing.
Use Dart's official reusable publishing workflow for bare semantic-version tags and bind its token to the pub.dev GitHub environment. Remove the long-lived PUB_CREDENTIALS path.
Complete the release notes, name all new public model helpers, and move LatestVersion removal to 5.0.0.

BREAKING CHANGE: SearchOrder.trending extends the public enum, so exhaustive switches must add a trending case.
@leoafarias leoafarias changed the title chore: audit pub.dev endpoints, add missing ones, fix search encoding feat!: add pub.dev endpoints and correct search behavior Aug 19, 2026
@leoafarias
leoafarias merged commit 4a1c949 into main Aug 19, 2026
1 check passed
@leoafarias
leoafarias deleted the chore/updated-endpoints branch August 19, 2026 01:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant