Skip to content

feat(store): offer a per-module Update on Installed cards - #53

Open
Heyian wants to merge 2 commits into
spicetify:mainfrom
Heyian:feat/store-installed-update-button
Open

Heyian wants to merge 2 commits into
spicetify:mainfrom
Heyian:feat/store-installed-update-button

Conversation

@Heyian

@Heyian Heyian commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The update banner gives a count, but the Installed section doesn't show which modules have an update, and Update all is the only way to install them.

An installed module with a pending vault update now shows Update in place of its Enable/Disable toggle. Clicking it installs that one update the same way a gallery card's update button does, including the stdlib-restart guard. The module's enabled state is kept, so the toggle returns once the update finishes. The button is disabled while its own update or Update all runs, and hovering it shows the target version.

Testing

Tested in the client with pnpm dev store: a disabled theme on 0.1.4 showed Update, moved to 0.1.5, stayed disabled, and the banner count dropped by one.

screenshot-20261004-11:19:51

A module with a pending vault update shows Update in place of its
Enable/Disable toggle, so the Installed section shows which modules
the banner counts and each can be updated on its own.
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 45 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: e299b9dc-f1e8-4ec8-a78d-f73b46dffa05
📥 Commits

Reviewing files that changed from the base of the PR and between 08dd192 and a93784a.

📒 Files selected for processing (1)
  • modules/store/metadata.json

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ba80745d-8b66-48b2-849b-173de12efaa1
📥 Commits

Reviewing files that changed from the base of the PR and between 6939433 and 08dd192.

📒 Files selected for processing (1)
  • modules/store/page.tsx

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

Installed module cards now show an Update button when a pending update is available. The store page matches updates to modules and runs each update through runInstall.

Changes

Installed module updates

Layer / File(s) Summary
Per-module update action
modules/store/page.tsx
The page matches pending updates to installed modules and passes each card its update, update-all state, and update callback. Cards track update activity, disable the Update button while updates are blocked or running, and hide the enable/disable control when an update is available.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: afonsojramos

Merge Risk: ⚪ Minimal · up to 08dd1

No concrete merge-blocking risk is established: per-card updates use the existing installation flow, and the suspected stdlib-order bypass has no demonstrated failure.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 08dd1

The new action reuses the existing update selection and installation controls. No introduced security weakness was established, but persistence atomicity and interruption recovery were not independently verified end to end.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The action reaches the existing local module loader for the selected module and any dependencies requiring installation, including existing stdlib staging behavior. Compared with the gallery route, no additional installation authority or independently attackable service boundary was established.

Trust Boundaries and Controls

  • observed — The new button receives updates from the existing pendingUpdates resolver, which excludes custom records and revoked catalog entries. Artifact-controlled metadata does not choose the installed identity: the installer overwrites its identifier with the selected catalog ID.

Resilience and Maintainability Implications

  • inferred — UI blocking is not a global installation mutex. Same-ID races are contained by the installer; distinct-ID concurrency remains possible through existing routes. No new concurrency-related security weakening was established, but atomic persistence and teardown completion beneath installLocal remain unverified.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: adding a per-module Update button to installed cards.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit spots an update near,
It taps the button, bright and clear.
The card waits while the work runs through,
Then checks for updates fresh and new.
The burrow hums; the modules bloom.

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant