Files
ansiblings/.gitea/workflows/ci.yml
T
Benjamin Diedrichsen 587ff2cf47
Publish snapshot / snapshot (push) Failing after 1m58s
Add release pipeline and upgrade toolchain to TypeScript 7
Publishing infrastructure
- Three Gitea workflows: ci.yml (PRs, non-main pushes), publish-snapshot.yml
  (main -> Gitea under dist-tag @main) and release.yml (tags -> Gitea + npmjs)
- Tag-driven releases as <package-dir>-v<version>; the manifest stays the
  source of truth and release.yml refuses to run if tag and manifest disagree
- Every publish is idempotent: each step checks the registry first, so a run
  that fails on the second registry can simply be re-run
- Hard coverage gate (85% branches) shared by CI, the pre-push hook and local
  runs, since the thresholds live in vitest.config.ts rather than a CI flag
- README.PUBLISH.md documents the whole mechanism

Toolchain
- TypeScript 7 native compiler; drop tsgo and ts-node, use tsx for dev runs
- Biome 1.9 -> 2.x, Vitest 1 -> 4, zod 3 -> 4, inquirer 8 -> 14, pnpm 11.17.0
- Replace inquirer-checkbox-plus-prompt, which is peer-capped at inquirer <9,
  with enquirer's AutoComplete; the CubeSelection contract is unchanged
- Stand in for zod 4's removed z.AnyZodObject with a local AnyObjectSchema

Repo hygiene
- Stop tracking dist/; ignore coverage/, *.tsbuildinfo, .npmrc* and release.json
- Drop package-lock.json in favour of pnpm-lock.yaml

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-27 15:17:14 +02:00

92 lines
2.4 KiB
YAML

# Verification gate for everything that is not a `main` push.
#
# `main` is covered by publish-snapshot.yml, which runs the identical gate
# before it publishes — running both here would just duplicate the work.
name: CI
on:
pull_request:
push:
branches-ignore:
- main
tags-ignore:
- '**'
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
verify:
runs-on: ubuntu-latest
steps:
- name: Check out
uses: actions/checkout@v4
- name: Set up pnpm
# Version comes from `packageManager` in the root package.json.
uses: pnpm/action-setup@v4
- name: Set up Node
uses: actions/setup-node@v4
with:
node-version-file: .nvmrc
- name: Locate the pnpm store
id: pnpm-store
run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- name: Restore the pnpm store
# A runner without a cache server should be slow, not broken.
continue-on-error: true
uses: actions/cache@v4
with:
path: ${{ steps.pnpm-store.outputs.path }}
key: pnpm-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}
restore-keys: pnpm-${{ runner.os }}-
- name: Install
run: pnpm install --frozen-lockfile
- name: Lint
run: pnpm run lint:ci
- name: Typecheck
run: pnpm run typecheck
- name: Test with coverage
# Fails the job below 85% branch coverage — see the `thresholds` block
# in each package's vitest.config.ts.
run: pnpm run test:coverage
- name: Summarise coverage
# Reporting only — the gate is the step above.
if: always()
continue-on-error: true
run: pnpm run coverage:summary
- name: Build
run: pnpm run build
- name: Check the published file lists
# Scripts are off because the build already ran; `prepack` would only
# repeat it. Catches a `files`/`bin` entry that no longer exists.
run: |
set -euo pipefail
for pkg in packages/*/; do
echo "::group::npm pack $pkg"
(cd "$pkg" && npm pack --dry-run --ignore-scripts)
echo "::endgroup::"
done
- name: Upload coverage reports
if: always()
continue-on-error: true
uses: actions/upload-artifact@v3
with:
name: coverage
path: packages/*/coverage
retention-days: 7