Skip to content

ci: run typecheck, tests and builds from a root workflow - #1

Merged
studiolxd merged 2 commits into
mainfrom
chore/ci-baseline
Sep 20, 2026
Merged

studiolxd merged 2 commits into
mainfrom
chore/ci-baseline

Conversation

@studiolxd

Copy link
Copy Markdown
Owner

Summary

The ci.yml under packages/xapi/.github/ was never executed: GitHub Actions only reads .github/workflows from the repository root. It was a leftover from when that directory was a standalone repo, which means typecheck, tests and builds have had no CI coverage at all — only the Angular smoke test ran.

This consolidates it into a single root workflow (Node 20 and 22) and deletes the inert one.

It also fixes a pre-existing flaky test that this new CI would otherwise have caught intermittently: rejects a tampered signature simulated tampering by flipping the last base64url character of the JWS. In a 256-byte RS256 signature the final group encodes a single byte, so that character carries only two significant bits plus discarded padding — flipping it decoded to identical bytes ~25% of the time, leaving the signature valid and the assertion failing. It now tampers with the first signature character, which always carries six significant bits. Verified over 12 consecutive runs.

Groundwork for the upcoming npm → pnpm migration: the CI is introduced here, still on npm, so that pre-existing failures surface now and aren't mistaken for pnpm regressions later.

Test plan

  • CI workflow runs and passes on Node 20 and 22
  • angular-smoke still passes
  • Locally verified: typecheck clean, 122 tests passing across 3 consecutive runs, example lints and builds

🤖 Generated with Claude Code

https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez

studiolxd and others added 2 commits September 20, 2026 11:05
The test flipped the LAST base64url character of the JWS to simulate
tampering. For a 256-byte RS256 signature the final group encodes a single
byte, so that character carries only two significant bits plus discarded
padding — flipping it decoded to identical bytes roughly 25% of the time,
leaving the signature valid and failing the assertion.

Tamper with the first signature character instead, which always carries six
significant bits. Verified over 12 consecutive runs (previously ~3 failures
expected). Pre-existing flake, unrelated to any dependency change.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
The ci.yml files under packages/*/.github (and example/.github in scorm) were
never executed: GitHub Actions only reads .github/workflows from the repository
root. They were leftovers from when those directories were standalone repos, so
typecheck, tests and builds had no CI coverage at all — only the Angular smoke
test ran.

Consolidate them into a single root workflow across Node 20 and 22.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
@studiolxd
studiolxd merged commit d41b819 into main Sep 20, 2026
3 checks passed
@studiolxd
studiolxd deleted the chore/ci-baseline branch September 20, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant