ci: add CI pipeline and publish create-nyxel setup CLI - #10
Merged
Merged
Conversation
Add GitHub Actions workflows for pull-request checks (lint, typecheck, build, conventional-commit PR titles, CodeQL, dependency review), Docker image builds/pushes to GHCR for apps/server and apps/web, and build + npm publish of a new create-nyxel package, plus Dependabot config. create-nyxel is a new npx/bunx setup CLI (packages/create-nyxel) that writes only a docker-compose.yml, .env, and (server mode) Caddyfile pointed at the published GHCR images — no repository checkout or source build required. Cloning the repo remains the documented path for development. Also wraps the two pages using useSearchParams() in a Suspense boundary so `next build` succeeds, which the new build/Docker workflows depend on.
apps/web/src/app/chat/page.tsx and apps/web/src/app/mcp-auth/callback/page.tsx predated biome's space-indent config and used tabs; reformat them (via `biome check --write`) now that the new lint CI job (biome ci --changed) checks files touched by a change. No behavioral change — build and typecheck still pass.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
biome ci --changed couldn't resolve vcs.defaultBranch to a ref in the PR checkout (detached HEAD on the merge ref, no local "main" branch), so pass --since=origin/main explicitly. Make the dependency-review job non-blocking: it errors on this repo until the "Dependency graph" setting is turned on in repo Security settings, which is outside this PR.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.github/workflows/ci.yml): lint (biome ci --changed, scoped to files touched by the PR so it doesn't block on pre-existing repo-wide lint debt),typecheck, andbuildrun on every PR and push tomain.pr-title.ymlenforces Conventional Commit PR titles,codeql.ymlruns CodeQL JS/TS analysis,dependency-review.ymlflags risky dependency changes, anddependabot.ymlkeeps bun/GitHub Actions/Docker base images up to date..github/workflows/docker.yml): buildsapps/serverandapps/webon every PR (validation only, multi-arch) and pushes toghcr.io/quavon-dev/nyxelos-server/nyxelos-webon merges tomainandv*.*.*tags.create-nyxelpackage (packages/create-nyxel): anpx create-nyxel/bunx create-nyxelCLI that sets NyxelOS up for use, not development — it writes only adocker-compose.yml,.env, and (server mode)Caddyfilepointed at the published GHCR images. No repository checkout, no build toolchain, no application source installed. Cloning the repo +bun install+bun devremains the documented path for contributors..github/workflows/package.yml): builds, typechecks, and smoke-testscreate-nyxelon every PR; publishes to npm oncreate-nyxel@<version>tags (with a tag/package.jsonversion match check).README.md/docs/INSTALL.mdto lead with thenpx create-nyxelquick start and clarify thatgit cloneis the development workflow.Incidental fix
bun run buildwas failing onmain(pre-existing) because/chatand/mcp-auth/callbackcalluseSearchParams()without aSuspenseboundary, which Next.js requires for static export. Wrapped both inSuspenseso the newbuild/dockerCI jobs are meaningful rather than red on day one. Also reformatted those two files withbiome check --write(tabs → biome's configured spaces) since the new lint job checks files touched by a change — no behavior change, verified viabun run build/typecheck.Test plan
bun run typecheck— passes across all workspace packagesbun run build— passes across all workspace packages (previously failing onapps/web)bunx biome ci --changed --since=origin/main— passes (0 errors, pre-existing non-blocking warnings only)packages/create-nyxel: built, ran--help,--mode pc --yes, and--mode server --yeslocally; validated both generateddocker-compose.ymlfiles withdocker compose config -qGenerated by Claude Code