From 303544796e2f3de47a2b6ac6b94eb15700af8c7f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BCller?= Date: Thu, 10 Sep 2026 23:03:14 +0000 Subject: [PATCH] :construction_worker: Run publint in the CI build job publish:publint and publish:attw only ran in the tag-triggered publish job, so a packaging break stayed green until release. Add publint to build (offline, fast, packs the built dist). attw stays in publish, where the full resolution matrix is worth the cost. --- .gitea/workflows/ci.yml | 5 +++++ backlog.tasks | 4 ++-- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 189cdd8..7043ce4 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -20,6 +20,11 @@ jobs: - run: npm run build - run: npm run check - run: npm run test:ci + # Fast, offline packaging gate. `attw` stays in `publish` (it needs + # a pack + full resolution matrix); `publint` packs too but is cheap + # enough to run on every push so a packaging break fails here, not + # at release time. + - run: npm run publish:publint # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in # the Actions tab for visibility, but must never gate a merge — so diff --git a/backlog.tasks b/backlog.tasks index 954409e..aae3436 100644 --- a/backlog.tasks +++ b/backlog.tasks @@ -28,9 +28,9 @@ Setup: - AGENTS.md only warns that empty LSP output is inconclusive, not that it can emit false errors ☐ Add a line to AGENTS.md: ignore LSP errors that `check:tsc` does not reproduce ☐ Or fix the LSP server configuration so it picks up `tsconfig.json` -☐ Run packaging checks in CI `build` +✔ Run packaging checks in CI `build` @done - `publish:publint` / `publish:attw` only run in the tag-triggered `publish` job, so a PR that breaks packaging stays green until release - ☐ At minimum add `publish:publint` to the `build` job (offline, fast); `attw` needs a pack + ✔ At minimum add `publish:publint` to the `build` job (offline, fast); `attw` needs a pack @done ☐ Publish the exact artifact CI tested - `publish: needs: build`, then re-runs `npm ci` + `build` from scratch, discarding the tested output - tag push pays a double build and the two builds could differ