mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-09-17 23:52:36 +00:00
* fix(build): build the web UI from prepack, not from every npm ci gitnexus-web is a separate ~650-package tree (React, Vite, LangChain, Mermaid). Because `prepare` built it, every `npm ci` in gitnexus/ also installed and Vite-built a second product. On CI that install ran uncached inside an execSync timeout, so a healthy-but-slow install was SIGTERM'd mid-flight and surfaced as `spawnSync /bin/sh ETIMEDOUT` -- repeatedly killing node floor compat, a job that only import-links the CLI dist and never needs the UI. The UI is only needed inside the published tarball, so build it from prepack instead. `npm run build` and `prepare` are now CLI-only; pass --web (or npm run build:web) to include it. Jobs that pack or publish install gitnexus-web in their own visible step, and the in-script fallback install is untimed so a slow install can no longer be killed halfway and reported as a build failure. The tsc/vite timeout default goes 300s -> 600s so the remaining bounded steps have headroom. Default build on this machine: 30s, no gitnexus-web work. * fix(build): enforce web package artifact integrity Co-authored-by: Cursor <cursoragent@cursor.com> * refactor(build): clarify web packaging helpers without changing behavior Keep the same opt-in, fail-closed, and pack/publish preserve rules while trimming comments, sharing the test harness, and reading index.html directly instead of probing it first. Co-authored-by: Cursor <cursoragent@cursor.com> * ci: skip prepare on typecheck so a cold shared install cannot cancel the job quality/typecheck's 10-minute budget was spent on an uncached gitnexus-shared npm install plus a full prepare tsc that tsc --noEmit does not need. Co-authored-by: Cursor <cursoragent@cursor.com> * ci: stop typecheck-web from canceling before the npm cache can save Hashing gitnexus-shared into the web cache key forced a cold 650-package install; the 10-minute job then canceled and never wrote a warm cache. Co-authored-by: Cursor <cursoragent@cursor.com> * ci: give format the same 10-minute budget as lint A cold root npm ci already took 4m19s and canceled prettier at the 5-minute cap. Lint does the same install and needed 7m41s on that run. Co-authored-by: Cursor <cursoragent@cursor.com> * ci: stop installing TypeScript 7 just to compile gitnexus-shared A dedicated npm ci in gitnexus-shared took 7 minutes to add two packages (TypeScript 7's optional per-platform binaries) and cancelled typecheck, Windows pack, and coverage shard 1. Compile shared with gitnexus's tsc. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3166) - Run tsc via execFileSync so the compiler path is never interpolated into a shell. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3166) - Run tsc as node typescript/bin/tsc so Windows never has to execFile a .cmd shim. Co-authored-by: Cursor <cursoragent@cursor.com> * Launch tsc via node and lib/tsc.js on every OS. The npm .bin/tsc shim is tsc.cmd on Windows, which execFileSync cannot spawn. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ci): lock eval containment against a dedicated shared npm ci Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
68 lines
2.5 KiB
YAML
68 lines
2.5 KiB
YAML
# Drift guard for the shipped engineering-skill copies (#2431).
|
|
# ci.yml carries `paths-ignore: ['**.md', ...]`, so an md-only skill edit —
|
|
# the most common future edit to these trees — would otherwise merge without
|
|
# gitnexus/test/unit/shipped-skills-sync.test.ts ever running, and the drift
|
|
# would first surface in someone else's CI run. This workflow triggers
|
|
# exactly on the guarded trees.
|
|
name: Skill copy sync
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- '.claude/skills/gitnexus-*/**'
|
|
- '.claude/skills/gitnexus/**'
|
|
- 'gitnexus/skills/**'
|
|
- 'gitnexus-claude-plugin/skills/**'
|
|
- 'gitnexus-cursor-integration/skills/**'
|
|
- 'gitnexus/test/unit/shipped-skills-sync.test.ts'
|
|
- 'gitnexus/test/unit/skills-steering.test.ts'
|
|
- 'gitnexus/test/unit/engineering-skills-contract.test.ts'
|
|
- 'gitnexus/test/unit/evidence-provenance-helper.test.ts'
|
|
- '.github/workflows/skill-sync.yml'
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- '.claude/skills/gitnexus-*/**'
|
|
- '.claude/skills/gitnexus/**'
|
|
- 'gitnexus/skills/**'
|
|
- 'gitnexus-claude-plugin/skills/**'
|
|
- 'gitnexus-cursor-integration/skills/**'
|
|
- 'gitnexus/test/unit/shipped-skills-sync.test.ts'
|
|
- 'gitnexus/test/unit/skills-steering.test.ts'
|
|
- 'gitnexus/test/unit/engineering-skills-contract.test.ts'
|
|
- 'gitnexus/test/unit/evidence-provenance-helper.test.ts'
|
|
- '.github/workflows/skill-sync.yml'
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
skill-sync:
|
|
name: shipped skills drift guard
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
# persist-credentials: false — runs a read-only test, never pushes.
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
with:
|
|
persist-credentials: false
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: '22'
|
|
cache: npm
|
|
cache-dependency-path: gitnexus/package-lock.json
|
|
- name: Install gitnexus
|
|
run: npm ci
|
|
working-directory: gitnexus
|
|
- name: Run distribution, steering, and engineering-contract guards
|
|
run: >-
|
|
npx vitest run
|
|
test/unit/shipped-skills-sync.test.ts
|
|
test/unit/skills-steering.test.ts
|
|
test/unit/engineering-skills-contract.test.ts
|
|
test/unit/evidence-provenance-helper.test.ts
|
|
working-directory: gitnexus
|