chore: make the setup-node contract assertion version-agnostic - #154
Merged
Conversation
The tooling contract hardcoded `uses: actions/setup-node@v6`, so every setup-node major bump failed the gate — which is exactly what blocked #138 (v6 -> v7). The contract's intent is that Node is set up for registry trusted publishing, not which release of the action does it; node-version: 24 and the registry URL stay asserted because those are the parts that actually matter. Verified the relaxed assertion still fails when setup-node is absent entirely.
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The regex form had no regex features, so oxlint's prefer-includes flagged it. Prefix matching on 'uses: actions/setup-node@' is simpler and equally version-agnostic; re-verified it still fails when setup-node is absent.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Unblocks #138 (actions/setup-node v6 → v7).
check-tooling-contract.mjsasserted the literal stringuses: actions/setup-node@v6, so any setup-node major bump fails the gate regardless of whether anything is actually wrong. That is what #138 tripped over.The contract's intent is that Node is set up for registry trusted publishing — not which release of the action does it.
node-version: 24, the registry URL, the OIDC permission and the publish command all stay asserted, because those are the parts that carry meaning.Verified the relaxed assertion still fails when
setup-nodeis removed from the workflow entirely, so it has not become vacuous.bun run checkgreen.