-
Notifications
You must be signed in to change notification settings - Fork 9.1k
Add GitHub Actions workflow for Node.js with Webpack #2192
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,28 @@ | ||
| name: NodeJS with Webpack | ||
|
|
||
| on: | ||
| push: | ||
| branches: [ "main" ] | ||
| pull_request: | ||
| branches: [ "main" ] | ||
|
|
||
| jobs: | ||
| build: | ||
| runs-on: ubuntu-latest | ||
|
|
||
| strategy: | ||
| matrix: | ||
| node-version: [18.x, 20.x, 22.x] | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: printf '%s\n' '--- applicable repository conventions ---'
head -5 /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01/*/.github*.md 2>/dev/null || true
head -5 /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01/*/*.md 2>/dev/null || true
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/webpack.ymlRepository: Gitlawb/openclaude Length of output: 7290 Pin external actions to immutable commits. Replace 🧰 Tools🪛 zizmor (1.29.0)[warning] 18-18: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [warning] 1-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 10-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI AgentsSources: Path instructions, Linters/SAST tools 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: printf '%s\n' '--- workflow ---'
cat -n .github/workflows/webpack.yml
printf '%s\n' '--- applicable repository conventions ---'
find /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01 -maxdepth 2 -type f -name '*.md' -printRepository: Gitlawb/openclaude Length of output: 2167 🏁 Script executed: printf '%s\n' '--- GitHub workflow review conventions ---'
cat /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01/conventions/github.md
printf '%s\n' '--- workflow diff ---'
git diff --unified=20 -- .github/workflows/webpack.ymlRepository: Gitlawb/openclaude Length of output: 747 🌐 Web query:
💡 Result: When a workflow is triggered by a pull_request event (for an open, mergeable pull request), GitHub automatically creates a temporary synthetic merge commit that represents the result of merging the pull request's head branch into the base branch [1][2]. Key technical details regarding GITHUB_REF and actions/checkout: 1. GITHUB_REF Value: During a pull_request event, GITHUB_REF is set to the fully-qualified reference of this synthetic merge branch, formatted as refs/pull/<PR_NUMBER>/merge [3][2][4]. 2. Default actions/checkout Behavior: Because the actions/checkout action uses GITHUB_REF by default, it automatically checks out this synthetic merge commit [1][5]. This ensures that your CI tests and workflow steps run against the code as it would exist if the pull request were merged, rather than just the state of the head branch alone [1][5]. 3. Alternative Checkout: If you need to check out the head branch of the pull request instead of the synthetic merge commit, you must explicitly configure the actions/checkout action to use the head SHA [6][7]: - uses: actions/checkout@v4 with: ref: ${{ github.event.pull_request.head.sha }} It is important to note that GITHUB_SHA for a pull_request event similarly points to this synthetic merge commit [1][2]. If your workflow requires the SHA of the actual commit that triggered the pull request, you should access github.event.pull_request.head.sha instead [1][8]. Citations:
Document the intended pull request revision or check the head commit explicitly. If this workflow must validate the submitted head commit, set 🧰 Tools🪛 zizmor (1.29.0)[warning] 18-18: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [warning] 1-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 10-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI AgentsSource: Path instructions 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- applicable repository conventions ---'
find /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01 -maxdepth 2 -type f -name '*.md' -print
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/webpack.yml
printf '%s\n' '--- package manifest ---'
cat -n package.json
printf '%s\n' '--- workflow references and related scripts ---'
rg -n --glob '.github/**' --glob 'package.json' 'actions/|npm install|npm ci|npx webpack|webpack|permissions:|persist-credentials|pull_request|push:' .Repository: Gitlawb/openclaude Length of output: 11679 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- GitHub workflow conventions ---'
cat /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01/conventions/github.md
printf '%s\n' '--- repository-wide conventions ---'
cat /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01/conventions/repo-wide.md
printf '%s\n' '--- lockfiles and package lifecycle declarations ---'
git ls-files | grep -E '(^|/)(package-lock\.json|npm-shrinkwrap\.json|yarn\.lock|pnpm-lock\.yaml|bun\.lockb?|\.npmrc)$' || true
rg -n '"(preinstall|install|postinstall|prepare)"|allowScripts|ignore-scripts' package.json bun.lock* package-lock.json npm-shrinkwrap.json .npmrc 2>/dev/null || trueRepository: Gitlawb/openclaude Length of output: 3270 Restrict the token before running package code.
🧰 Tools🪛 zizmor (1.29.0)[warning] 18-18: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [warning] 1-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 10-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI AgentsSources: Path instructions, Linters/SAST tools |
||
|
|
||
| - name: Use Node.js ${{ matrix.node-version }} | ||
| uses: actions/setup-node@v4 | ||
| with: | ||
| node-version: ${{ matrix.node-version }} | ||
|
|
||
| - name: Build | ||
| run: | | ||
| npm install | ||
| npx webpack | ||
|
Comment on lines
+27
to
+28
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: printf '%s\n' '--- repository rules ---'
find /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01 -maxdepth 2 -type f -name '*.md' -print
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/webpack.yml
printf '%s\n' '--- package manifest ---'
cat -n package.jsonRepository: Gitlawb/openclaude Length of output: 11614 🏁 Script executed: printf '%s\n' '--- GitHub workflow conventions ---'
cat /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01/conventions/github.md
printf '%s\n' '--- repository-wide conventions ---'
cat /tmp/coderabbit-repo-knowledge/gitlawb-openclaude-c7dc8a01/conventions/repo-wide.md
printf '%s\n' '--- package-manager and build metadata ---'
git ls-files | grep -E '(^|/)(bun.lock|package-lock.json|npm-shrinkwrap.json|yarn.lock|pnpm-lock.yaml|webpack\.config|scripts/build\.)$|(^|/)package\.json$'
printf '%s\n' '--- build script entry point ---'
if [ -f scripts/build.ts ]; then cat -n scripts/build.ts | sed -n '1,180p'; fiRepository: Gitlawb/openclaude Length of output: 13349 [Blocker] Invoke the declared project build.
🧰 Tools🪛 zizmor (1.29.0)[warning] 1-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 10-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) 🤖 Prompt for AI Agents |
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win
Cancel superseded pull request runs.
Each new pull request commit starts the full Node.js matrix while older runs continue. Add a concurrency group keyed by the pull request number or branch ref, with
cancel-in-progress: true, to stop obsolete builds.🧰 Tools
🪛 zizmor (1.29.0)
[warning] 1-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[warning] 10-29: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[info] 10-10: workflow or action definition without a name (anonymous-definition): this job
(anonymous-definition)
🤖 Prompt for AI Agents
Source: Linters/SAST tools