Packages, bundles, budgets
There is no node_modules and no bundler to set up. A package is fetched once into the app's vendor/ and recorded in its sluurp-deps.json — the import map, each version and a hash of every file — and the server bundles everything when it starts.
# its sources and its dependencies, into vendor/
sluurp add npm:d3-force@3
# a JSR package, through JSR's npm registry
sluurp add jsr:@std/path@^1
# wanted and latest, as pnpm reports them
sluurp outdated
# also removes what only the old version needed
sluurp update --latest
# checks every file against npm's tarballs
sluurp vendor verify
sluurp remove d3-force
# where the shared store is, and its size; `clear` empties it
sluurp cache- Packages are vendored as source, not as a CDN’s build. CommonJS is converted to ES modules with rolldown at vendoring time.
- Types come with the package, its own or DefinitelyTyped’s, along with paths for the editor.
- A shared store, keyed by content hash, makes the same package instant for a second app. npm’s and pnpm’s caches are read when they have the file, and
--offlineworks from the caches alone.
In production
When it starts, the server bundles each page’s modules with rolldown. Bundles are code-split and minified, and include workers and new URL(…) assets. The result is cached on disk by content and precompressed with brotli and gzip. In development, modules are served one at a time, as written.
A budget
{ "first-load-kb": 320, "pages": { "/signup.html": 140 } }/_sluurp/bundle/report.json reports how much each page downloads, compressed, before it can run, and flags any page over its budget. Code that only one page needs should be loaded with import() from that page.