Repository navigation
ci: harden GitHub-hosted checks and publishing - #12
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Run pull-request checks directly on GitHub-hosted
ubuntu-latestwithpull_request, read-only repository permissions, and credential-free checkout. The tests and Docker build use public dependencies and local services, so remove the obsolete Cloudflare approval jobs. CI and publishing use Node 26, with a matching CI dependency cache key. Publishing stays restricted to successful pushes onmainafter both CI jobs and the runner image check succeed.ubuntu-latestand replace the bundled Corepack dependency in CI with a SHA-pinned pnpm setup action that uses the version inpackage.json.biw/npm-trusted-publish-workflows@v1, currently pointing to the releasedv1.1.0, so future v1 releases are picked up across repositories. The shared workflows use Node 26 onubuntu-latest, supportprepublishOnly, reject stale or mismatched tested commits, and tag the exact published revision. Keep the existing local workflow names and pass the tested SHA explicitly.Repository protection is already active:
mainrequires a PR, with no mandatory reviewer or additional approval gate. A maintainer's merge is the approval to publish. The existing admin bypass is restricted to PR merges; direct pushes cannot use that bypass. Deletion and force-push protections are preserved.Validation: on the latest head
a448b19, both GitHub-hosted CI jobs passed all 303 tests across 30 files, formatting, lint, type checks, and package builds on Node 26 andubuntu-latest, including all five installer regression tests. The Docker image is 1,249,803,889 bytes, below the 1,500,000,000-byte limit. Local workflow actionlint, formatting, and diff checks passed. The released shared publisher passed its 20 regression tests and package-manager bootstrap checks on Node 24 and 26. Publishing remains skipped for pull requests. Package version1.0.10is already on npm, so the merge should skip republishing; actual OIDC authentication in the shared publisher will be exercised on the next unpublished package version. The existingci.ymlcaller identity is preserved and matches the published package's provenance.This PR contains CI and publishing hardening and can be merged independently of the scheduler changes in #11.