Repository navigation
92 lines (83 loc) · 3.5 KB
/
Copy pathbuild.yml
File metadata and controls
92 lines (83 loc) · 3.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
name: build
# Verifies `bun run build` produces a usable `dist/` (entry point +
# type declarations) and that the committed DevTools UI bundle was
# generated from the sources in the tree. Only needs to run when
# something in the build inputs changes — source, the DevTools UI
# sources that get embedded into `src/devtools/generated/UiAssets.ts`,
# tsconfig, dependency manifest, or the workflow itself. Skips on
# docs-only / test-only / README changes so the actions queue stays
# focused.
on:
# Run on every branch push (feature work merges locally, so a branch push
# is often the only pre-merge signal), not just `develop`.
push:
branches: ['**']
paths:
- 'src/**'
- 'devtools-ui/**'
- 'scripts/**'
- 'package.json'
- '.bun-version'
- 'bun.lock'
- 'tsconfig.json'
- '.github/workflows/build.yml'
pull_request:
branches: [main, develop]
paths:
- 'src/**'
- 'devtools-ui/**'
- 'scripts/**'
- 'package.json'
- '.bun-version'
- 'bun.lock'
- 'tsconfig.json'
- '.github/workflows/build.yml'
workflow_dispatch:
# Least privilege, stated rather than inherited: the repository default is
# read-only today, but a settings flip would otherwise hand a write token to
# a job that installs and runs the whole dependency tree. #621
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version-file: .bun-version
# Frozen: `dependencies` feed the bundle's source-hash below, so a
# drifting install would move the fingerprint the check compares.
- name: Install
run: bun install --frozen-lockfile
# The generated bundle is committed on purpose, so a fresh clone
# can typecheck, test and smoke without running the UI build —
# which is exactly what made staleness invisible: the file is
# valid TypeScript whether or not its contents are current, so a
# stale one sailed through typecheck and the entire test suite.
#
# It runs before the build out of habit rather than necessity now. That
# ordering used to be load-bearing: `bun run build` was `build:ui && tsc`,
# so it regenerated the very file under test and any check after it passed
# by construction. This job builds with `build:lib` (tsc only) since
# #483, which removes the hazard structurally instead of relying on step
# order — and keeps this job free of the nested Angular install, because
# the check reads the committed module rather than rebuilding it.
#
# It compares the `source-hash` in the committed module's header
# against a fresh one, rather than rebuilding and diffing bytes.
# The bytes are not a function of the sources alone — gzip stamps
# the OS into every member and every Bun-version bump moves the
# minifier under us — so a byte diff fires on bundles that are
# perfectly current (#521). See scripts/build-devtools-ui.mjs.
- name: Verify the embedded DevTools UI bundle is current
run: bun run check:ui
- name: Build (tsc → dist/)
run: bun run build:lib
- name: Verify dist/ produced
run: |
test -f dist/index.js
test -f dist/index.d.ts
echo "dist/ artifacts present"