Repository navigation
chore(deps-dev): bump @types/node from 26.2.0 to 26.3.0 #237
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # 22 is the floor declared in `engines` and the first line that strips | |
| # TypeScript without a flag; 26 is what the fleet develops against. | |
| node-version: [22, 26] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| with: | |
| fetch-depth: 0 | |
| fetch-tags: true | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v7 | |
| with: | |
| node-version: ${{ matrix.node-version }} | |
| cache: npm | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v2.2.0 | |
| with: | |
| # Exact pin: setup-bun resolves floating versions via an | |
| # unauthenticated api.github.com tag listing, which GitHub-hosted | |
| # runners routinely get 503/rate-limited on (broke this repo's CI | |
| # 3 runs in a row). An exact version downloads directly instead. | |
| bun-version: "1.3.14" | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Verify tracked pm project health | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| # Catch durable checkout-visible failures: conflict markers, parse failures, | |
| # invalid or drifted history, tracked runtime caches, extension health, | |
| # stale in-progress work, and any merge evidence present in this clone. | |
| # | |
| # This is not a lossless-merge attestation. Merge receipts are clone-local and | |
| # absent from a fresh CI checkout. Some unreconciled loss shapes surface as | |
| # history drift, but reconciliation or history repair can remove that signal. | |
| # Keep receipt review as a local pre-push step; pm-cli#921 and pm-cli#922 track | |
| # the missing durable proof. | |
| # | |
| # `--strict-exit` is load-bearing: non-strict health may report findings while | |
| # still exiting successfully. | |
| ./node_modules/.bin/pm health --strict-exit | |
| - name: Type check | |
| run: npm run typecheck | |
| - name: Build | |
| run: npm run build | |
| - name: Verify complete docstring coverage | |
| run: npm run docstring | |
| # Fail-closed identity / secret / host-path audit over the local object | |
| # store (pm-github-zqad). In CI this is evidence about refs and tags; the | |
| # local release:check run additionally covers unreachable objects. | |
| - name: Privacy gate (identities, secrets, host paths) | |
| run: npm run privacy | |
| - name: Test with coverage gate | |
| run: npm run coverage | |
| - name: Production dependency audit | |
| run: npm run audit:prod | |
| - name: Verify npm package contents | |
| run: npm run pack:dry-run | |
| - name: Verify generated changelog | |
| run: npm run changelog:check | |
| - name: Verify every publish invocation is attested | |
| run: npm run verify:release-publish-attestation | |
| - name: Verify Bun can install the package graph | |
| run: bun install --no-save |