fix(codegen): pin openapi-generator 7.25.0 and guard codegen in CI (PER-16500) - #135
Merged
Merged
Conversation
…in CI The pinned generator 6.2.1 cannot read the OpenAPI 3.1.0 spec served at api.permit.io: it regenerates an all-`any`, type-erased client (247 of 319 type files) yet exits 0, masked by --skip-validate-spec. Running `yarn generate-openapi-client` today silently replaces the typed client with `any`. Re-pin the generator to 7.12.0, the first 3.1-native line that regenerates a typed client (named properties instead of `any`; 2 known allOf+default residuals remain, allow-listed and tracked for the re-baseline), and add a CI codegen guard that regenerates from a pinned 3.1.0 fixture through the real pipeline and fails if any type collapses to all-`any`. The guard runs in its own Java-provisioned job, off the test suite. The committed client under src/openapi/ is intentionally left unchanged: this restores and guards the toolchain. Re-baselining the generated client against the current spec is a separate, larger follow-up. Fixes permitio#130
Co-Authored-By: Codex <noreply@openai.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Codex <noreply@openai.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Type-shape failures did not say which generator produced the models, so a bad pin such as 6.2.1 was reported without its version. Print the pinned version on every failure after the pin is resolved, and cover it with a test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Codex <noreply@openai.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
generate-openapi-clientexits 0 and emits an all-anyclient (generate-openapi-client silently emits an all-any client: pinned generator 6.2.1 cannot read the now-3.1 spec #130).scripts/check-codegen.mjs(yarn check:codegen). It generates a client from a committed 3.1 spec fixture, using the pinned generator and the options fromgenerate-openapi-client. It fails if models degrade toanyor if specific property types change.scripts/check-codegen.spec.mjs(yarn test:codegen): 43 AVA tests for the guard's failure paths. They don't need Java.codegen-guardCI job: SHA-pinned actions, a read-only token, no secrets, so it works on fork PRs. Also sets workflow-levelpermissions: contents: read.src/openapi/. That is PER-16500's semver-major follow-up.Linear
Closes #130.
Details
Generator pin (
openapitools.json)typescript-axiosoptions the generate script uses:useSingleRequestParameter,withSeparateModelsAndApi,apiPackageandmodelPackage.Guard (
scripts/check-codegen.mjs)openapitools.jsonand the options fromgenerate-openapi-client. It rejects options it can't reproduce, and it works from any working directory.VERSION,FILES) doesn't match the pin or the files on disk;any(20 named free-form fields are allowed);RoleCreate.extends,ResourceRoleCreate.extendsand nullable 3.1 unions, which two synthetic probe schemas cover.Fixture (
src/tests/codegen/fixtures/)openapi-3.1.0.jsonis a snapshot of the API spec (329 schemas, 160 paths) plus theCodegenProbeandCodegenProbeInnerschemas. The README records the source, the known limitations and the refresh steps.CI (
.github/workflows/ci.yaml)codegen-guardjob runs checkout (persist-credentials: false), setup-node (Node 22, yarn cache) and setup-java (Temurin 17). All three are pinned to commit SHAs with version comments.yarn install --frozen-lockfile --ignore-scripts,yarn test:codegenandyarn check:codegen, with a 15-minute timeout.yarn testandyarn lintalso run the new tests and lint throughtest:*andlint:*.permissions: contents: read: the existingtest-and-lintjob only reads the repo.Testing
yarn build: passesyarn lint: 0 errors (7 existing warnings)yarn test:unit: 48 passedyarn test:module-imports: 9 passedyarn test:codegen: 43 passedyarn check:codegen: passes with 7.25.0 (346 models)actionlint: cleanzizmor: nothing incodegen-guard. The remaining findings are in the existingtest-and-lintjob, which ci: pin actions to SHA and run full test suite on PRs #131 addresses.Notes
ci.yamlconflicts textually with ci: pin actions to SHA and run full test suite on PRs #131's rewrite, which is being folded into permitio 3.0.0: refactor SDK APIs, tests, and release validation #134. Whichever lands second should keep this job as-is.conststill becomesany;Secretinterface;src/openapi/with 7.25.0 in a semver-major release;Secretschema;@openapitools/openapi-generator-cliwrapper from 2.7.0 to the current version.Original change by @Kyzgor; the guard hardening, generator bump and CI commits were added by the maintainers.
🤖 Generated with Claude Code
https://claude.ai/code/session_01PSoip6dghQ62bLQ6GBMwTA