openpencil/.github/workflows/ci.yml
Danila Poyarkov c2aec9bacb
fix(packages): make packed exports runtime-safe (#665)
* fix(packages): make packed exports runtime-safe

Make checked-in package manifests truthful for ordinary npm and Bun packing, and verify installed artifacts under both runtimes. Centralize package discovery, artifact inspection, and bounded process execution so CI and release publication share the same contracts.

* ci: build package dependencies before checks

Keep workspace jobs independent of ignored dist output now that public package exports consistently resolve built artifacts.

* ci: preserve source-first engine tests

Keep the broader dependency build for package and repository validation, but retain Core-only setup for engine shards so workspace tests continue exercising source modules.

* ci: build engine shard dependencies

Build the seven workspace packages imported by engine tests in dependency order. This preserves a single module instance per package and keeps each clean CI shard independent of ignored dist output.

* ci: restore established package build boundaries

Keep the original repository and engine job setup, and add installed artifact verification only after the existing package build. Avoid changing which module copies unrelated tests execute.

* fix(packages): preserve Bun source identity in tarballs

Retain source-first workspace resolution and ship complete source trees for Bun conditions. Verify clean installed consumers without overlaying archives, reuse consumer validation before release publication, and repair Bun 1.3.10 private source alias resolution.

* refactor(tooling): reuse package and process utilities

Use pkg-types for manifest I/O and types, tinyexec for subprocess lifecycle, and npm's pack listing for release staging. Preserve archive verification and project release invariants rather than reimplementing package-manager file selection.

* refactor(tooling): resolve workspace roots at CLI boundaries

Discover and validate the nearest workspace once, support explicit roots, and pass roots to reusable checks. Replace subprocess entrypoint dispatch with direct calls and preserve aggregate package diagnostics without adding arbitrary test timeout increases.

* fix(release): enforce publication boundaries

Use root version alignment and shared validated npm output parsing. Enforce the public npm registry policy and test verification-before-publication, mismatched artifacts, and partial retries without registry writes.

* refactor(tooling): validate package responses with Valibot

Express npm pack and manifest identity contracts as schemas, infer parsed output types, and preserve contextual failures and relative-path safety. Document Valibot as the first-party validation convention while retaining Zod at SDK boundaries.

* refactor(tooling): validate manifests at input boundaries

Share Valibot schemas for consumed manifest fields, recursive exports, supported workspace declarations, and npm registry responses. Infer domain types and reject malformed metadata instead of silently skipping it downstream.

* refactor(tooling): group package helpers by ownership

Colocate manifest and workspace contracts, separate npm response parsing from generic JSON handling, and split smoke packing, installation, and runtime checks. Remove the release tarball forwarding shim and consolidate its coverage in package-artifacts. Preserve public tooling exports and CLI commands.
2026-09-09 18:25:22 +03:00

175 lines
4.5 KiB
YAML

name: CI
on:
pull_request:
branches: [master]
paths-ignore:
- 'packages/docs/**'
- 'openspec/**'
- '*.md'
permissions:
contents: read
packages: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
source-quality:
name: Code quality
timeout-minutes: 10
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false
- uses: ./.github/actions/setup-bun
- name: Generate package declarations
run: bun run build:packages
- name: Verify formatting
run: bun run format:check
- name: Lint TypeScript and Vue
run: bun run lint
- name: Typecheck application and SDKs
run: bun run typecheck
- name: Enforce architecture and type-shape boundaries
run: bun run check:arch && bun run test:type-shapes
package-quality:
name: Package integrity
timeout-minutes: 10
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false
- uses: ./.github/actions/setup-bun
- name: Build publishable packages
run: bun run build:packages
- name: Validate installed package artifacts with Node and Bun
run: bun run test:packages
- name: Detect unused dependencies and files
run: bun run check:deps
- name: Validate workspace dependency policy
run: bun run check:monorepo
repository-quality:
name: Repository hygiene
timeout-minutes: 10
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false
- uses: ./.github/actions/setup-bun
- name: Validate translations
run: bun run check:i18n
- name: Validate documentation links and structure
run: bun run check:docs
- name: Audit critical dependency vulnerabilities
run: bun run check:audit
- name: Scan for committed secrets
run: bun run check:secrets
- name: Test repository tooling
run: bun run test:tools
- name: Detect duplicated product code
run: bun run test:dupes
storybook:
name: Component workshop
timeout-minutes: 10
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false
- uses: ./.github/actions/setup-bun
- name: Build component dependencies
run: bun run build:packages
- name: Build static Storybook
run: bun run build-storybook
native-test-contracts:
name: Native app contracts
timeout-minutes: 8
runs-on: ubuntu-24.04
container:
image: ghcr.io/open-pencil/native-contracts-ci@sha256:64e6b1b50a988c1cefe2b69ac9d58076fd743b18391fa2dbd1d153eba2be9521
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
with:
workspaces: desktop -> target
key: native-test
- uses: ./.github/actions/setup-bun
- name: Typecheck native interaction tests
run: bun run check:native-test
- name: Compile native-test Tauri feature
run: cargo check --manifest-path desktop/Cargo.toml --features native-test
unit-tests:
timeout-minutes: 10
runs-on: ubuntu-latest
strategy:
fail-fast: true
matrix:
group: [app, dom, editor, fig, render, scene, vue]
name: Engine tests — ${{ matrix.group }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false
- uses: ./.github/actions/setup-bun
with:
lfs: 'true'
- name: Build shared Core test dependency
run: bun --filter @open-pencil/core build
- name: Run ${{ matrix.group }} engine tests
shell: bash
run: |
mapfile -t test_files < <(bun tools/unit-tests/src/list.ts "${{ matrix.group }}")
if [ "${#test_files[@]}" -eq 0 ]; then
echo "No tests found for shard ${{ matrix.group }}"
exit 0
fi
bun test "${test_files[@]}"
env:
BUN_HEAVY_TESTS: 'false'