Repository navigation
104 lines (84 loc) · 3.33 KB
/
Copy pathci.yml
File metadata and controls
104 lines (84 loc) · 3.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
test:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# 22 is the floor declared in `engines` and the first line that strips
# TypeScript without a flag; 26 is what the fleet develops against.
node-version: [22, 26]
steps:
- name: Checkout
uses: actions/checkout@v7
with:
fetch-depth: 0
fetch-tags: true
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ matrix.node-version }}
cache: npm
- name: Setup Bun
uses: oven-sh/setup-bun@v2.2.0
with:
# Exact pin: setup-bun resolves floating versions via an
# unauthenticated api.github.com tag listing, which GitHub-hosted
# runners routinely get 503/rate-limited on (broke this repo's CI
# 3 runs in a row). An exact version downloads directly instead.
bun-version: "1.3.14"
- name: Install dependencies
run: npm ci
- name: Verify tracked pm project health
shell: bash
run: |
set -euo pipefail
# Catch durable checkout-visible failures: conflict markers, parse failures,
# invalid or drifted history, tracked runtime caches, extension health,
# stale in-progress work, and any merge evidence present in this clone.
#
# This is not a lossless-merge attestation. Merge receipts are clone-local and
# absent from a fresh CI checkout. Some unreconciled loss shapes surface as
# history drift, but reconciliation or history repair can remove that signal.
# Keep receipt review as a local pre-push step; pm-cli#921 and pm-cli#922 track
# the missing durable proof.
#
# `--strict-exit` is load-bearing: non-strict health may report findings while
# still exiting successfully.
./node_modules/.bin/pm health --strict-exit --require-merge-drivers
- name: Type check
run: npm run typecheck
- name: Build
run: npm run build
- name: Verify complete docstring coverage
run: npm run docstring
- name: ESLint source policy
run: npm run lint
- name: Complete source duplication gate
run: npm run duplication
# Fail-closed identity / secret / host-path audit over the local object
# store (pm-github-zqad). In CI this is evidence about refs and tags; the
# local release:check run additionally covers unreachable objects.
- name: Privacy gate (identities, secrets, host paths)
run: npm run privacy
- name: Test with coverage gate
run: npm run coverage
- name: Production dependency audit
run: npm run audit:prod
- name: Verify npm package contents
run: npm run pack:dry-run
- name: Verify generated changelog
run: npm run changelog:check
- name: Verify every publish invocation is attested
run: npm run verify:release-publish-attestation
- name: Verify Bun can install the package graph
run: bun install --no-save
- name: Verify native Bun extension behavior
run: npm run test:bun