Skip to content

ci: add CI pipeline and publish create-nyxel setup CLI - #10

Merged
rgxdev merged 3 commits into
mainfrom
claude/ci-pipeline-setup-commands-cdglbq
Jul 2, 2026
Merged

rgxdev merged 3 commits into
mainfrom
claude/ci-pipeline-setup-commands-cdglbq

Conversation

@rgxdev

@rgxdev rgxdev commented Jul 2, 2026

Copy link
Copy Markdown
Member

Summary

  • PR checks (.github/workflows/ci.yml): lint (biome ci --changed, scoped to files touched by the PR so it doesn't block on pre-existing repo-wide lint debt), typecheck, and build run on every PR and push to main.
  • Extra PR guardrails: pr-title.yml enforces Conventional Commit PR titles, codeql.yml runs CodeQL JS/TS analysis, dependency-review.yml flags risky dependency changes, and dependabot.yml keeps bun/GitHub Actions/Docker base images up to date.
  • Docker images (.github/workflows/docker.yml): builds apps/server and apps/web on every PR (validation only, multi-arch) and pushes to ghcr.io/quavon-dev/nyxelos-server / nyxelos-web on merges to main and v*.*.* tags.
  • New create-nyxel package (packages/create-nyxel): a npx create-nyxel / bunx create-nyxel CLI that sets NyxelOS up for use, not development — it writes only a docker-compose.yml, .env, and (server mode) Caddyfile pointed at the published GHCR images. No repository checkout, no build toolchain, no application source installed. Cloning the repo + bun install + bun dev remains the documented path for contributors.
  • Package CI (.github/workflows/package.yml): builds, typechecks, and smoke-tests create-nyxel on every PR; publishes to npm on create-nyxel@<version> tags (with a tag/package.json version match check).
  • Updated README.md / docs/INSTALL.md to lead with the npx create-nyxel quick start and clarify that git clone is the development workflow.

Incidental fix

bun run build was failing on main (pre-existing) because /chat and /mcp-auth/callback call useSearchParams() without a Suspense boundary, which Next.js requires for static export. Wrapped both in Suspense so the new build/docker CI jobs are meaningful rather than red on day one. Also reformatted those two files with biome check --write (tabs → biome's configured spaces) since the new lint job checks files touched by a change — no behavior change, verified via bun run build/typecheck.

Test plan

  • bun run typecheck — passes across all workspace packages
  • bun run build — passes across all workspace packages (previously failing on apps/web)
  • bunx biome ci --changed --since=origin/main — passes (0 errors, pre-existing non-blocking warnings only)
  • packages/create-nyxel: built, ran --help, --mode pc --yes, and --mode server --yes locally; validated both generated docker-compose.yml files with docker compose config -q
  • CI itself — will confirm once the workflows run on this PR

Generated by Claude Code

claude added 2 commits July 2, 2026 09:06
Add GitHub Actions workflows for pull-request checks (lint, typecheck,
build, conventional-commit PR titles, CodeQL, dependency review), Docker
image builds/pushes to GHCR for apps/server and apps/web, and build +
npm publish of a new create-nyxel package, plus Dependabot config.

create-nyxel is a new npx/bunx setup CLI (packages/create-nyxel) that
writes only a docker-compose.yml, .env, and (server mode) Caddyfile
pointed at the published GHCR images — no repository checkout or
source build required. Cloning the repo remains the documented path
for development.

Also wraps the two pages using useSearchParams() in a Suspense
boundary so `next build` succeeds, which the new build/Docker workflows
depend on.
apps/web/src/app/chat/page.tsx and apps/web/src/app/mcp-auth/callback/page.tsx
predated biome's space-indent config and used tabs; reformat them (via
`biome check --write`) now that the new lint CI job (biome ci --changed)
checks files touched by a change. No behavioral change — build and
typecheck still pass.
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

biome ci --changed couldn't resolve vcs.defaultBranch to a ref in the
PR checkout (detached HEAD on the merge ref, no local "main" branch),
so pass --since=origin/main explicitly.

Make the dependency-review job non-blocking: it errors on this repo
until the "Dependency graph" setting is turned on in repo Security
settings, which is outside this PR.
@rgxdev
rgxdev marked this pull request as ready for review July 2, 2026 09:26
@rgxdev
rgxdev merged commit 7d21c85 into main Jul 2, 2026
9 of 10 checks passed
@rgxdev
rgxdev deleted the claude/ci-pipeline-setup-commands-cdglbq branch July 2, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants