Skip to content

chore(deps-dev): bump @types/node from 26.2.0 to 26.3.0 #237

chore(deps-dev): bump @types/node from 26.2.0 to 26.3.0

chore(deps-dev): bump @types/node from 26.2.0 to 26.3.0 #237

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
test:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# 22 is the floor declared in `engines` and the first line that strips
# TypeScript without a flag; 26 is what the fleet develops against.
node-version: [22, 26]
steps:
- name: Checkout
uses: actions/checkout@v7
with:
fetch-depth: 0
fetch-tags: true
- name: Setup Node.js
uses: actions/setup-node@v7
with:
node-version: ${{ matrix.node-version }}
cache: npm
- name: Setup Bun
uses: oven-sh/setup-bun@v2.2.0
with:
# Exact pin: setup-bun resolves floating versions via an
# unauthenticated api.github.com tag listing, which GitHub-hosted
# runners routinely get 503/rate-limited on (broke this repo's CI
# 3 runs in a row). An exact version downloads directly instead.
bun-version: "1.3.14"
- name: Install dependencies
run: npm ci
- name: Verify tracked pm project health
shell: bash
run: |
set -euo pipefail
# Catch durable checkout-visible failures: conflict markers, parse failures,
# invalid or drifted history, tracked runtime caches, extension health,
# stale in-progress work, and any merge evidence present in this clone.
#
# This is not a lossless-merge attestation. Merge receipts are clone-local and
# absent from a fresh CI checkout. Some unreconciled loss shapes surface as
# history drift, but reconciliation or history repair can remove that signal.
# Keep receipt review as a local pre-push step; pm-cli#921 and pm-cli#922 track
# the missing durable proof.
#
# `--strict-exit` is load-bearing: non-strict health may report findings while
# still exiting successfully.
./node_modules/.bin/pm health --strict-exit
- name: Type check
run: npm run typecheck
- name: Build
run: npm run build
- name: Verify complete docstring coverage
run: npm run docstring
# Fail-closed identity / secret / host-path audit over the local object
# store (pm-github-zqad). In CI this is evidence about refs and tags; the
# local release:check run additionally covers unreachable objects.
- name: Privacy gate (identities, secrets, host paths)
run: npm run privacy
- name: Test with coverage gate
run: npm run coverage
- name: Production dependency audit
run: npm run audit:prod
- name: Verify npm package contents
run: npm run pack:dry-run
- name: Verify generated changelog
run: npm run changelog:check
- name: Verify every publish invocation is attested
run: npm run verify:release-publish-attestation
- name: Verify Bun can install the package graph
run: bun install --no-save