ci: daily package-currency check against npm and the live site - #3
Merged
Merged
Conversation
Leo's agent-first order (2026-09-26) makes this package the first surface of every UrbanKit Studio change, so a lag between the monorepo, npm and urbankitstudio.com must show up the day it happens. The facts that show one live on npm and on the live site, where no hermetic test can look. .github/workflows/package-currency.yml runs daily at 07:25 UTC and on dispatch, never on push or pull_request: it needs the network, and a network flake must never become a required check. It runs the script's own tests first, then scripts/check-package-currency.mjs: - PUBLISH LAG: package.json here vs npm latest. Repo ahead means the publish did not happen; npm ahead means the mirror lags. - DATA LAG: data/index.json here vs the live /data/atlas/index.json on totals.counties, totals.endpoints and lastUpdated. The site ahead is red; the site behind is a warning. - UNBUMPED DATA: data/ changed after the commit that set the version. Remedy: bump packages/atlas version + CHANGELOG in the UKS monorepo; the mirror and the publish follow. Every check runs every time, and "could not ask" is red with its own message. A shallow checkout is refused rather than walked to its graft. The tests are node:test under scripts/ because the mirror sync owns test/ and the vitest config; .github/ and scripts/ are the paths atlas-sync-push.yml excludes from its rsync --delete. Verified: 22/22 node tests; npm test still 5 files / 35 tests and typecheck clean; a real run green on all three (0.6.8 = npm; 234 counties, 246 endpoints, lastUpdated 2026-09-26 = site); a replay at aa5336d red on all three, naming the five data files that moved after 595e9b6 set 0.6.6. Sabotage, one mutation at a time, each restored: inverted PUBLISH LAG direction (3 predicted reds), renamed script path in the workflow (shape test red), added a push trigger (shape test red). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017bBpvg7AZrpRoXAsaAGovU
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Leo's agent-first order (2026-09-26): the npm data package is updated first whenever the atlas ships counties, tools or fixes. This repo is the mirror the registry publishes from, and nothing here said when the published package fell behind the data the site serves. Real history holds the miss: 59d3bee and aa5336d moved
data/(Alaska, Connecticut, Maine, New York, West Virginia) at 0.6.6 with no version bump, so npm kept serving the 0.6.6 data under the same number until 0.6.7.What
.github/workflows/package-currency.yml: daily 07:25 UTC (after the UKS repo's 06:25 / 06:40 / 06:55 jobs and mcp-atlas's 07:10) and on dispatch; read-only; ci.yml's action SHAs, Node 24.19.0,fetch-depth: 0(the history walk refuses a shallow clone), nonpm ci. Not on push or pull_request: it needs the network and a flake must never become a required check.scripts/check-package-currency.mjs, three verdicts in one run:package.jsonversion vs npmlatest(repo ahead = the publish did not happen; npm ahead = this mirror lags the release).data/index.jsontotals vs the live site's/data/atlas/index.json(site ahead on counties, endpoints or lastUpdated = red; site behind = a warning, exit 0).data/changed on main since the commit that last set the version (a description-only commit at the same version is not a release) = red, with the remedy (bumppackages/atlasversion + CHANGELOG in the UKS monorepo; the mirror and the publish follow).rev-list,cat-file,diff-tree), so user config cannot bend the output; env seamsATLAS_CURRENCY_REGISTRY_URL/ATLAS_CURRENCY_SITE_URLexist for the end-to-end test only and the shape test asserts the workflow sets neither.scripts/package-currency.test.mjs(node:test, 22 cases): the pure verdicts, semver edges, a history walk in a throwaway repo, the shallow-clone refusal with a full-clone control, four end-to-end runs against a local HTTP server (all green; site behind = warning; 503 and an HTML body = two could-not-ask reds while UNBUMPED DATA still runs; all three red), and the workflow's shape last. The mirrored vitest collects onlytest/**/*.test.ts, so this file runs bynode --test, which the workflow does first.Verification
git diff --name-only 595e9b6..aa5336d -- data/lists the same five files.node --test scripts/package-currency.test.mjs: 22/22. The repo's own gates untouched:npm test35/35,npm run typecheck0.push:trigger added (shape test only).atlas-sync-push.yml) rsyncs with--exclude '.github/'and--exclude 'scripts/', so these files survive every sync. The UKS-side "publish repo kept the files it owns" post-check will name them in the agent-first PR that follows this one; merge THIS PR first, since that check fails when the named files are absent.🤖 Generated with Claude Code
https://claude.ai/code/session_017bBpvg7AZrpRoXAsaAGovU