feat!: add pub.dev endpoints and correct search behavior - #79
Merged
Merged
Conversation
Audited the client against pub.dev's current route table, the officially supported API doc, and the hosted repository spec v2. Adds five public, read-only endpoints: - packageLikes GET /api/packages/<pkg>/likes - publisherInfo GET /api/publishers/<id> - packageVersionScore GET /api/packages/<pkg>/versions/<v>/score - packageVersionOptions GET /api/packages/<pkg>/versions/<v>/options - topicNameCompletion GET /api/topic-name-completion-data Fixes search query encoding: the query was interpolated into the URL raw, so a `#` opened a URI fragment and an `&` terminated the query string, silently truncating the search. Verified against pub.dev that `flutter` and `flutter#zzzz` previously returned identical results. Deprecates SearchOrder.popularity, which pub.dev no longer accepts and serves as `top`, and adds the SearchOrder.trending it does accept.
Verified each new endpoint against pub.dev's response DTOs in pkg/_pub_shared/lib/data and swept 31 package/version pairs plus 9 publishers. Records why likeCount/tags/package/likes stay non-nullable despite the server DTOs declaring them optional, and notes the gzip requirement on package-names and topic-name-completion-data.
Deprecate obsolete API members, tighten public documentation, and remove a mutable live-count assertion. Modernize CI and make the 3.3.0 publish path validate the release tag and package before publishing.
Use Dart's official reusable publishing workflow for bare semantic-version tags and bind its token to the pub.dev GitHub environment. Remove the long-lived PUB_CREDENTIALS path.
Complete the release notes, name all new public model helpers, and move LatestVersion removal to 5.0.0. BREAKING CHANGE: SearchOrder.trending extends the public enum, so exhaustive switches must add a trending case.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Audits the client against pub.dev's current routes and live responses, adds the
missing read-only endpoints, fixes search encoding, and prepares version 4.0.0
for release. The final review also tightened the public Dart API documentation,
made obsolete members explicitly deprecated, removed a flaky live assertion,
and repaired the publish workflow.
API additions
packageLikes(package)GET /api/packages/<package>/likes— public like countpublisherInfo(id)GET /api/publishers/<id>packageVersionScore(package, version)GET /api/packages/<package>/versions/<version>/scorepackageVersionOptions(package, version)GET /api/packages/<package>/versions/<version>/optionstopicNameCompletion()GET /api/topic-name-completion-dataAlso added:
SearchOrder.trending, matching pub.dev's trend-score ordering.SearchResults.message, which pub.dev returns when it cannot fully honor aquery.
fromMapandfromJsonhelpers onRepository.pubspec_parsetypes exposed byPubPackage.latestPubspec.topicNameCompletionrejects the versionedAcceptheader used by the otherendpoints, so
_fetchnow supports a case-insensitive per-request headeroverride.
Fixes and compatibility
Uri.replace(queryParameters:); reserved characters such as#and&nolonger truncate the request.
fetchGooglePackagesno longer sends the malformedtools.dart.devpublisher tag and now includes
labs.dart.dev.cached, mutable live counts.
SearchOrder.popularityis deprecated in favor ofSearchOrder.downloads; pub.dev silently treats the old value astop.PackageScore.popularityScoreis deprecated in favor ofdownloadCount30Days; pub.dev no longer returns the popularity field.LatestVersionis deprecated because no endpoint or client method producesit. It is scheduled for removal in 5.0.0.
Adding
SearchOrder.trendingextends a public enum. Consumers with exhaustiveswitches over
SearchOrdermust add atrendingcase. The release is thereforeversioned as 4.0.0 and the migration is called out as a breaking change.
Documentation and cleanup
field meanings, authentication behavior, retraction semantics, and preferred
replacements for deprecated APIs.
incorrect return-value claims, and inconsistent Dart formatting.
helper methods.
*.mapper.dartoutput from analysis and removed lint rulesthat no longer exist in the current Dart SDK.
Release readiness
changelog.
credentials; the workflow no longer reads the legacy
PUB_CREDENTIALSsecret.
repository convention, with a
pub.devGitHub deployment environment boundinto the trusted-publisher identity.
actions/checkout@v4, currentdart runcommands, explicit read-only permissions, analysis, and tests.Validation
dart run build_runner build— generated output matches the committed files.dart format --output=none --set-exit-if-changed— 17 changed Dart files,no changes required.
dart analyze— no issues found.dart test— 76 passed, 1 documented pre-existing skip.dart doc --dry-run .— 0 warnings, 0 errors.actionlint— both GitHub Actions workflows pass.dart pub publish --dry-run— package 4.0.0 validates with 0 warnings.pub.dev responses and checked against the current pub.dev source.