diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 7043ce4..b4e9c68 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -25,6 +25,13 @@ jobs: # enough to run on every push so a packaging break fails here, not # at release time. - run: npm run publish:publint + # Persist the exact dist/ that `check`, `test:ci` and `publint` were + # run against, so `publish` ships those bytes instead of rebuilding + # (which could in principle differ and would pay the build twice). + - uses: actions/upload-artifact@v4 + with: + name: dist + path: dist/ # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in # the Actions tab for visibility, but must never gate a merge — so @@ -61,7 +68,12 @@ jobs: node-version-file: .node-version registry-url: "https://registry.npmjs.org/" - run: npm ci - - run: npm run build + # Consume the dist/ that `build` produced and gated, instead of + # rebuilding here — `publish` must ship the tested artifact. + - uses: actions/download-artifact@v4 + with: + name: dist + path: dist/ - run: npm run publish:publint - run: npm run publish:attw - run: npm publish --access public diff --git a/backlog.tasks b/backlog.tasks index aae3436..235954d 100644 --- a/backlog.tasks +++ b/backlog.tasks @@ -31,10 +31,10 @@ Setup: ✔ Run packaging checks in CI `build` @done - `publish:publint` / `publish:attw` only run in the tag-triggered `publish` job, so a PR that breaks packaging stays green until release ✔ At minimum add `publish:publint` to the `build` job (offline, fast); `attw` needs a pack @done -☐ Publish the exact artifact CI tested +✔ Publish the exact artifact CI tested @done - `publish: needs: build`, then re-runs `npm ci` + `build` from scratch, discarding the tested output - tag push pays a double build and the two builds could differ - ☐ Persist `dist/` as an artifact in `build` and consume it in `publish` + ✔ Persist `dist/` as an artifact in `build` and consume it in `publish` @done ☐ Confirm pre-push gate strength - pre-push runs `npm test` (`check:tsc` + tests), not full `check`; oxlint/oxfmt/cspell drift on unstaged content is only caught per-staged-file at commit or whole-project in CI ☐ Confirm this is intended per the feedback-tier table, or point pre-push at `verify`