mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-09-19 00:03:33 +00:00
* chore(deps): add tree-sitter aware Dependabot config and drift monitoring
Two things Dependabot cannot see on its own:
1. ABI consistency. The tree-sitter runtime supports a known range of
grammar ABIs. When a grammar bumps past that range, require() silently
fails and fallback paths mask the regression in test coverage.
2. Vendored upstream drift. vendor/tree-sitter-proto is a snapshot of
coder3101/tree-sitter-proto regenerated against a pinned cli version.
Upstream keeps moving. Nothing notices until a maintainer remembers to
look.
Dependabot configuration
- Added npm ecosystems for gitnexus, gitnexus-web, gitnexus-shared.
- Grouped all tree-sitter-* grammar bumps into one PR (ecosystem moves in
lockstep, one PR per grammar is noise).
- Pinned the tree-sitter runtime itself. Bumping 0.21 to 0.22+ changes
which grammar ABIs load and requires coordinated updates to the
vendored proto grammar. That stays a deliberate human decision.
- Pinned tree-sitter-cli for the same reason (it controls which ABI
vendor/tree-sitter-proto/src/parser.c emits when regenerated).
Drift check (.github/scripts/check-tree-sitter-drift.py)
- Reads the tree-sitter runtime version from gitnexus/package.json.
- Walks every installed tree-sitter-* grammar plus the vendored proto
and reports its LANGUAGE_VERSION against the runtime's supported ABI
range (table maintained in the script; extend when bumping runtime).
- Fetches coder3101/tree-sitter-proto main parser.c and compares byte
for byte to the vendored copy. Reports the upstream HEAD short SHA
and the upstream ABI so a maintainer can act.
- Prints a Markdown report; exits 0 when everything is in range and
matches upstream, 1 otherwise.
- Stdlib only, no external deps.
Drift workflow (.github/workflows/tree-sitter-drift-check.yml)
- Runs weekly (Mondays 09:00 UTC) to match Dependabot's cadence.
- Also runs on PRs that touch the script or workflow itself, where it
fails the PR check on drift so the drift gate cannot land broken.
- On scheduled runs with drift, opens or updates a single tracking
issue labeled tree-sitter-drift. On scheduled runs that come back
clean, closes the open tracking issue (if any) with a comment.
* refactor(deps): rewrite drift check as tree-sitter 0.25 upgrade readiness monitor
Replace the ABI drift pass/fail gate with a daily upgrade readiness
dashboard that tracks peer-dep compatibility of all 14 grammars with
tree-sitter@0.25.0 and reports which are ready, unreleased, or blocking.
Key changes:
- Rename drift-check → upgrade-readiness (script, workflow, job id)
- Fix P0: pass report via env var, not ${{ }} template interpolation
- Fix P1: npm fetch failure now adds a blocker instead of false-green
- Fix P1: pass GITHUB_TOKEN for authenticated GitHub API calls
- Switch Dependabot to daily for tree-sitter grammars
- Use dict for blockers (no prefix collision), derive TARGET_RUNTIME
constant, reuse GRAMMARS parser_path, normalize CRLF in comparisons
- Reduce per-call HTTP timeout from 15s to 8s for workflow budget
- PR runs warn on blockers instead of hard-failing
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* chore(ci): remove global-upgrade smoke test workflow
The ci-global-upgrade.yml workflow tested npm global install upgrades
over a specific release candidate (1.6.2-rc.8). That RC has shipped
and the workflow is no longer needed. Remove it and all references
from ci.yml (needs, env vars, gate check).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat(ci): add changelog comments to upgrade readiness tracking issue
Each daily run now posts a comment summarizing what changed before
updating the issue body. Comments include the ready/blocker counts
and a diff of grammar status changes (e.g. tree-sitter-cpp:
Unreleased -> Ready). Gives a timeline of how the upgrade unblocks.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
121 lines
4.8 KiB
YAML
121 lines
4.8 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
paths-ignore: ['**.md', 'docs/**', 'LICENSE']
|
|
pull_request:
|
|
branches: [main]
|
|
paths-ignore: ['**.md', 'docs/**', 'LICENSE']
|
|
workflow_call:
|
|
|
|
# Concurrency convention: see CONTRIBUTING.md → "GitHub Actions — Concurrency Convention".
|
|
# Hardcoded `CI-` prefix (not `${{ github.workflow }}`) because this workflow is
|
|
# invoked as a reusable workflow from publish.yml and release-candidate.yml. In
|
|
# called-workflow context `github.workflow` evaluation is ambiguous across GitHub
|
|
# Actions versions, and a prefix that could resolve to the caller's name would
|
|
# share a concurrency group with the caller → deadlock. A literal prefix is
|
|
# immune. Direct `push`/`pull_request` invocations use `CI-<ref>`; invocations
|
|
# from a reusable-workflow caller fall into a per-run-unique group that never
|
|
# serializes with the caller.
|
|
# cancel-in-progress is event-aware: cancel superseded PR runs, queue every other
|
|
# event (push to main, workflow_call from publish.yml, etc.).
|
|
concurrency:
|
|
group: ${{ (github.event_name == 'pull_request' || github.event_name == 'push') && format('CI-{0}', github.ref) || format('CI-nested-{0}', github.run_id) }}
|
|
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
|
|
|
# ── Reusable workflow orchestration ─────────────────────────────────
|
|
# Each concern lives in its own workflow file for maintainability:
|
|
# ci-quality.yml — typecheck (tsc --noEmit)
|
|
# ci-tests.yml — unit + integration tests with coverage + cross-platform
|
|
# ci-e2e.yml — E2E tests (only when gitnexus-web/ changes)
|
|
#
|
|
# Shared setup is DRY via .github/actions/setup-gitnexus composite action.
|
|
|
|
jobs:
|
|
quality:
|
|
uses: ./.github/workflows/ci-quality.yml
|
|
permissions:
|
|
contents: read
|
|
|
|
tests:
|
|
uses: ./.github/workflows/ci-tests.yml
|
|
permissions:
|
|
contents: read
|
|
|
|
e2e:
|
|
uses: ./.github/workflows/ci-e2e.yml
|
|
permissions:
|
|
contents: read
|
|
|
|
# ── Save PR metadata for the reporting workflow ─────────────────
|
|
# The ci-report.yml workflow (triggered by workflow_run) needs the
|
|
# PR number and job results to post a comment. We save them as an
|
|
# artifact because workflow_run context doesn't reliably carry PR
|
|
# info for fork PRs.
|
|
save-pr-meta:
|
|
name: Save PR Metadata
|
|
if: always() && github.event_name == 'pull_request'
|
|
needs: [quality, tests, e2e]
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- name: Write metadata
|
|
shell: bash
|
|
env:
|
|
PR_NUMBER: ${{ github.event.number }}
|
|
QUALITY: ${{ needs.quality.result }}
|
|
TESTS: ${{ needs.tests.result }}
|
|
E2E: ${{ needs.e2e.result }}
|
|
run: |
|
|
mkdir -p pr-meta
|
|
echo "$PR_NUMBER" > pr-meta/pr_number
|
|
echo "$QUALITY" > pr-meta/quality_result
|
|
echo "$TESTS" > pr-meta/tests_result
|
|
echo "$E2E" > pr-meta/e2e_result
|
|
# TODO(post-merge): remove backward-compat copies once ci-report.yml
|
|
# on main reads underscore names.
|
|
# Backward-compat: ci-report.yml on main still reads hyphenated
|
|
# names. workflow_run always executes from the default branch, so
|
|
# the main-branch reader won't find the underscore variants until
|
|
# this PR is merged. Write both until then.
|
|
cp pr-meta/pr_number pr-meta/pr-number
|
|
cp pr-meta/quality_result pr-meta/quality-result
|
|
cp pr-meta/tests_result pr-meta/tests-result
|
|
cp pr-meta/e2e_result pr-meta/e2e-result
|
|
|
|
- name: Upload PR metadata
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: pr-meta
|
|
path: pr-meta/
|
|
retention-days: 1
|
|
|
|
# ── Unified CI gate ──────────────────────────────────────────────
|
|
# Single required check for branch protection.
|
|
ci-status:
|
|
name: CI Gate
|
|
needs: [quality, tests, e2e]
|
|
if: always()
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- name: Check all jobs passed
|
|
shell: bash
|
|
env:
|
|
QUALITY: ${{ needs.quality.result }}
|
|
TESTS: ${{ needs.tests.result }}
|
|
E2E: ${{ needs.e2e.result }}
|
|
run: |
|
|
echo "Quality: $QUALITY"
|
|
echo "Tests: $TESTS"
|
|
echo "E2E: $E2E"
|
|
if [[ "$QUALITY" != "success" ]] ||
|
|
[[ "$TESTS" != "success" ]]; then
|
|
echo "::error::Quality or test jobs failed"
|
|
exit 1
|
|
fi
|
|
if [[ "$E2E" != "success" && "$E2E" != "skipped" ]]; then
|
|
echo "::error::E2E job failed"
|
|
exit 1
|
|
fi
|