chore(release): delivery hygiene — pinned dogfood engine, lint gate, node matrix, idempotent write-back #126
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: ["**"] | |
| pull_request: | |
| # CI needs to read the repo, nothing more. | |
| permissions: | |
| contents: read | |
| jobs: | |
| build: | |
| name: typecheck · lint · test · build (node ${{ matrix.node }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # engines says >=20 and the release workflow builds on 24 — test what | |
| # users actually run, not only the floor. | |
| node: ["20", "22", "24"] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: ${{ matrix.node }} | |
| cache: npm | |
| - run: npm ci | |
| - run: npm run typecheck | |
| - run: npm run lint | |
| - run: npm test | |
| - run: npm run build | |
| e2e: | |
| name: runner e2e (real browser) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: npm | |
| - run: npm ci | |
| - run: npx playwright install --with-deps chromium | |
| - name: Seed spec in a real browser | |
| run: npx playwright test | |
| - name: Runner, fidelity, compiler, drive, terminal, and qa-loop integration tests | |
| run: >- | |
| npx vitest run | |
| tests/runner.integration.test.ts | |
| tests/compiler.integration.test.ts | |
| tests/drive.integration.test.ts | |
| tests/drive.claude.integration.test.ts | |
| tests/terminal.integration.test.ts | |
| tests/http.integration.test.ts | |
| tests/qa.integration.test.ts | |
| tests/plan.integration.test.ts | |
| tests/observe.integration.test.ts | |
| tests/extension.integration.test.ts | |
| env: | |
| PROOFKEEPER_E2E: "1" | |
| dco: | |
| name: DCO sign-off | |
| runs-on: ubuntu-latest | |
| if: github.event_name == 'pull_request' | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Verify every commit has a Signed-off-by trailer | |
| run: | | |
| range="${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }}" | |
| missing=0 | |
| while read -r sha; do | |
| [ -z "$sha" ] && continue | |
| if ! git show -s --format=%B "$sha" | grep -qiE '^Signed-off-by: .+ <.+@.+>'; then | |
| echo "::error::commit $sha is missing a DCO Signed-off-by trailer" | |
| missing=1 | |
| fi | |
| done < <(git rev-list "$range") | |
| if [ "$missing" -ne 0 ]; then | |
| echo "All commits must be signed off (git commit -s). See CONTRIBUTING.md." | |
| exit 1 | |
| fi | |
| echo "All commits carry a DCO sign-off." |