`npm run check` should be the fast, offline correctness ladder only (tsc + oxlint + oxfmt + cspell, ~3s), so an agent can run it as a confirmation gate during feature work. check:knip / check:outdated were advisory whole-project / network scans, and check-outdated exits non-zero whenever any dep is behind. Keeping them in check made `npm run check` (and the CI build gate) fail on dependency freshness, which must not block an unrelated feature PR. Rename them to maintain:knip / maintain:outdated, aggregate under `npm run maintain`, and run it in CI as a dedicated non-blocking job (continue-on-error) that surfaces findings without ever gating a merge. Update the script-prefix convention, the feedback-tier table, and AGENTS.md: the agent may now run `npm run check`; only `maintain` stays out of the feature loop.
61 lines
1.8 KiB
YAML
61 lines
1.8 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
branches: [main]
|
|
workflow_dispatch: {}
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: .node-version
|
|
cache: "npm"
|
|
- run: npm ci
|
|
- run: npm run build
|
|
- run: npm run check
|
|
- run: npm run test:ci
|
|
- name: Upload coverage
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: coverage
|
|
path: coverage
|
|
|
|
# Advisory scans (dead code, dependency freshness). Non-blocking: surfaced on
|
|
# the PR for visibility, but must never gate a merge — so continue-on-error and
|
|
# intentionally NOT in `publish`'s `needs`.
|
|
maintain:
|
|
runs-on: ubuntu-latest
|
|
continue-on-error: true
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: .node-version
|
|
cache: "npm"
|
|
- run: npm ci
|
|
- run: npm run maintain
|
|
|
|
publish:
|
|
if: startsWith(github.ref, 'refs/tags/')
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: .node-version
|
|
registry-url: "https://registry.npmjs.org/"
|
|
- run: npm ci
|
|
- run: npm run build
|
|
- run: npm run publish:publint
|
|
- run: npm run publish:attw
|
|
- run: npm publish --access public
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|