-
Notifications
You must be signed in to change notification settings - Fork 0
146 lines (118 loc) · 6.05 KB
/
Copy pathci.yml
File metadata and controls
146 lines (118 loc) · 6.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
# .github/workflows/ci.yml
name: CI
on:
push:
branches: [main]
pull_request:
jobs:
ci:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version-file: .bun-version
- name: Install (frozen lockfile)
run: bun install --frozen-lockfile
# First of the gates: pure Node over Markdown, no build, no dist/, so a
# corpus mistake reports in seconds instead of after the whole pipeline.
# Keeps docs/knowledge/'s two trees apart — no hand-written entry under
# harvested/, whose `<sub>` shas digest whole source files and so cannot
# record an edit; the next harvest would delete it silently. The companion
# drift report is deliberately NOT here: 16 of the 47 sources are a
# sibling styleguide repository that no CI checkout has.
- name: Knowledge-corpus structure check
run: bun run verify:knowledge-structure
- name: Typecheck
run: bun run typecheck
- name: Lint
run: bun run lint
- name: Build
run: bun run build
# `bun run test`, not a bare `bun test`: the root script passes both test
# trees explicitly (`./packages ./tests`), and bunfig's `root = "packages"`
# means a bare invocation silently skips `tests/`. See CLAUDE.md.
- name: Test (with coverage)
run: bun run test --coverage
# `examples/` is not a workspace member and is not in the root test script's two trees, so
# until 2026-09-04 the petstore canary -- the witness for the codegen target surface, and the
# only assertion anywhere that an unsatisfiable AUTH requirement raises before the transport is
# touched -- compiled and lint-checked but never ran. Its own step rather than a widening of
# `bun run test`: examples are not workspace packages and their coverage does not belong in the
# 80% floor's denominator.
- name: Example canaries
run: bun run test:examples
# The gates' own tests (`scripts/*.test.mjs`), on `node --test`. Deliberately outside
# `bun run test`: bunfig scopes discovery and the 80% coverage floor to `packages`, and that
# floor is a statement about `packages/core`, not about repo tooling. What this protects is a
# gate's logic silently degrading — a bad glob, a swallowed assertion — which no other step
# would notice, since a degraded gate still exits 0. Closes open-items H13, whose trigger had
# already fired: `knowledge.test.mjs` was failing on `main` and nothing ran it.
- name: Gate self-tests (scripts/*.test.mjs)
run: bun run test:scripts
- name: API surface check
run: bun run api
# `lint:publish` ignores attw's `cjs-resolves-to-esm` rule. That is not a
# workaround for a fixable defect: @dexpace/core is ESM-only by design (no
# `require` condition in its exports map), so a CJS `require()` of it
# necessarily resolves to ESM and attw always flags it. Every other attw
# rule stays blocking. The `main`/`types` fields on the package exist so
# legacy `node10` resolution still finds the entry point — without them
# attw reports a hard resolution failure.
- name: Package health (publint + attw)
run: bun run lint:publish
- name: Dual JS/TS consumption check
run: bun run verify:dual-consumption
- name: Consumer typecheck against the published .d.ts
run: bun run verify:consumer-types
- name: SEAM-1 zero-dependency check
run: bun run verify:seam-1
- name: Verify SSE-37/SSE-38 (no serde dependency, no reconnect path in core SSE)
run: bun run verify:sse-37
- name: Runtime-floor consistency check
run: bun run verify:runtime-floor
# Reads the five files that must agree on `tests/node-conformance/`. The rule and the reasons
# it exists live in CLAUDE.md, "HARD RULE — the `tests/` partition"; what matters here is only
# that every way it breaks is silent, so nothing else in this workflow would catch it.
- name: Test-partition check (tests/ vs tests/node-conformance/)
run: bun run verify:test-partition
# docs/knowledge/harvested/module-organization.md:20 treats an import cycle as a bug rather
# than a style nit, and :22 requires it be gated here. Hand-written and dependency-free like
# every other verify:* gate, so it cannot be skipped by a missing install (docs/open-items.md
# K12). Type-only edges count, deliberately.
- name: Import-cycle check
run: bun run verify:import-cycles
# NFR-12. Deliberately last in this job: it sweeps every dist/ and rebuilds
# the workspace twice, so it would otherwise pull the rug from under any
# step above that resolves a workspace package through its dist/.
- name: Reproducible-build check (NFR-12)
run: bun run verify:reproducible-build
- name: Dependency audit
run: bun run audit
node-conformance:
needs: ci
runs-on: ubuntu-latest
strategy:
# Report both versions rather than stopping at the first failure: "broken on the floor" and
# "broken on LTS" are different diagnoses and the matrix exists to tell them apart.
fail-fast: false
matrix:
# The declared floor AND current LTS, which is the "in addition to current LTS" half of
# sdk-design-nodejs/09:52-54 that a floor-only pin left unexercised (checkpoint 5.9).
# `lts/*` resolves at run time, so this does not go stale as LTS moves.
node: ['20.3.0', 'lts/*']
name: node-conformance (${{ matrix.node }})
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version-file: .bun-version
- name: Install (frozen lockfile)
run: bun install --frozen-lockfile
- name: Build
run: bun run build
- uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node }}
- name: Node-runtime conformance against the built artifact (NFR-10/NFR-17)
run: bun run test:node