ci: run typecheck, tests and builds from a root workflow - #1
Merged
Merged
Conversation
The test flipped the LAST base64url character of the JWS to simulate tampering. For a 256-byte RS256 signature the final group encodes a single byte, so that character carries only two significant bits plus discarded padding — flipping it decoded to identical bytes roughly 25% of the time, leaving the signature valid and failing the assertion. Tamper with the first signature character instead, which always carries six significant bits. Verified over 12 consecutive runs (previously ~3 failures expected). Pre-existing flake, unrelated to any dependency change. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
The ci.yml files under packages/*/.github (and example/.github in scorm) were never executed: GitHub Actions only reads .github/workflows from the repository root. They were leftovers from when those directories were standalone repos, so typecheck, tests and builds had no CI coverage at all — only the Angular smoke test ran. Consolidate them into a single root workflow across Node 20 and 22. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
ci.ymlunderpackages/xapi/.github/was never executed: GitHub Actions only reads.github/workflowsfrom the repository root. It was a leftover from when that directory was a standalone repo, which means typecheck, tests and builds have had no CI coverage at all — only the Angular smoke test ran.This consolidates it into a single root workflow (Node 20 and 22) and deletes the inert one.
It also fixes a pre-existing flaky test that this new CI would otherwise have caught intermittently:
rejects a tampered signaturesimulated tampering by flipping the last base64url character of the JWS. In a 256-byte RS256 signature the final group encodes a single byte, so that character carries only two significant bits plus discarded padding — flipping it decoded to identical bytes ~25% of the time, leaving the signature valid and the assertion failing. It now tampers with the first signature character, which always carries six significant bits. Verified over 12 consecutive runs.Groundwork for the upcoming npm → pnpm migration: the CI is introduced here, still on npm, so that pre-existing failures surface now and aren't mistaken for pnpm regressions later.
Test plan
angular-smokestill passes🤖 Generated with Claude Code
https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez