-
Notifications
You must be signed in to change notification settings - Fork 1
163 lines (137 loc) · 4.82 KB
/
Copy pathci.yml
File metadata and controls
163 lines (137 loc) · 4.82 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
concurrency:
group: ci-${{ github.workflow }}-${{ github.event_name == 'push' && github.sha || github.ref }}
cancel-in-progress: ${{ github.event_name != 'push' }}
jobs:
# oxfmt, oxlint, and typecheck share one runner: one checkout and one
# install instead of three of each. Dummy job names prettier and eslint
# stay for protect-main.
static-analysis:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: "1.3.14"
- name: Cache dependencies
uses: actions/cache@v4
with:
path: node_modules
# Exact-key-only: a restore-keys prefix of bun- would hydrate
# node_modules from a different lockfile. bun install then has to
# reconcile a stale tree; missing that step leaves wrong deps.
key: bun-${{ hashFiles('bun.lock') }}
- name: Install dependencies
run: bun install --frozen-lockfile
- name: oxfmt
run: bunx oxfmt --check .
- name: oxlint
run: bunx oxlint .
- name: Typecheck
run: bun run typecheck
# Build runs beside the suite instead of before it: tests import ./src
# directly and never read ./dist, so serializing build ahead of test put
# build time on the critical path for no dependency reason.
build:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "24"
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: "1.3.14"
- name: Cache dependencies
uses: actions/cache@v4
with:
path: node_modules
key: bun-${{ hashFiles('bun.lock') }}
- name: Install dependencies
run: bun install --frozen-lockfile
- name: Build
run: bun run build
# The suite is sharded so the slowest slice, not the whole suite, sets the
# wall clock. Every shard still goes through check:projects-dir-guard: the
# guard forwards these path filters to the suite it wraps, and the union of
# the shards' filters is exactly ./src ./tests ./evals ./scripts, so the gate covers
# the same tests as before, all of them sandboxed.
test:
runs-on: ubuntu-latest
strategy:
# A red shard must not cancel the other; both results are the signal.
fail-fast: false
matrix:
shard:
- name: src
paths: ./src
- name: tests-evals-and-scripts
paths: ./tests ./evals ./scripts
name: test (${{ matrix.shard.name }})
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "24"
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: "1.3.14"
# The runner image has no ripgrep, so the grep plugin silently exercised
# its fallback walker and left the ripgrep path untested.
- name: Install ripgrep
run: sudo apt-get install -y ripgrep
- name: Cache dependencies
uses: actions/cache@v4
with:
path: node_modules
key: bun-${{ hashFiles('bun.lock') }}
- name: Install dependencies
run: bun install --frozen-lockfile
# The same script the local `bun run check` gate runs, with the shard's
# path filters forwarded through the guard to the suite. The guard
# routes a filtered run through test:paths, which carries the same
# seeded flags as the `test` script; bun test filters are additive, so
# appending filters to `bun run test` could not narrow it. Randomized
# order catches tests that only pass in the default file order (shared
# module-level state, an unrestored global mock, a leaked env var).
# The seed stays 424242 in every shard rather than varying per shard:
# the shards already run disjoint file sets, and a fixed seed keeps
# any failure reproducible locally with the same
# `bun run test:paths <paths>`.
- name: Test
run: bun run check:projects-dir-guard ${{ matrix.shard.paths }}
# protect-main still requires the pre-restructure check names. These jobs
# exist only to publish those contexts after the real work succeeds.
prettier:
needs: static-analysis
runs-on: ubuntu-latest
steps:
- run: "true"
eslint:
needs: static-analysis
runs-on: ubuntu-latest
steps:
- run: "true"
typecheck:
needs: static-analysis
runs-on: ubuntu-latest
steps:
- run: "true"
build-and-test:
needs: [build, test]
runs-on: ubuntu-latest
steps:
- run: "true"