Skip to content

ci: daily package-currency check against npm and the live site - #3

Merged
LEOyrh merged 1 commit into
mainfrom
claude/hana-agent-first-2026-09
Sep 26, 2026
Merged

LEOyrh merged 1 commit into
mainfrom
claude/hana-agent-first-2026-09

Conversation

@LEOyrh

@LEOyrh LEOyrh commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator

Why

Leo's agent-first order (2026-09-26): the npm data package is updated first whenever the atlas ships counties, tools or fixes. This repo is the mirror the registry publishes from, and nothing here said when the published package fell behind the data the site serves. Real history holds the miss: 59d3bee and aa5336d moved data/ (Alaska, Connecticut, Maine, New York, West Virginia) at 0.6.6 with no version bump, so npm kept serving the 0.6.6 data under the same number until 0.6.7.

What

  • .github/workflows/package-currency.yml: daily 07:25 UTC (after the UKS repo's 06:25 / 06:40 / 06:55 jobs and mcp-atlas's 07:10) and on dispatch; read-only; ci.yml's action SHAs, Node 24.19.0, fetch-depth: 0 (the history walk refuses a shallow clone), no npm ci. Not on push or pull_request: it needs the network and a flake must never become a required check.
  • scripts/check-package-currency.mjs, three verdicts in one run:
    • PUBLISH LAG: package.json version vs npm latest (repo ahead = the publish did not happen; npm ahead = this mirror lags the release).
    • DATA LAG: data/index.json totals vs the live site's /data/atlas/index.json (site ahead on counties, endpoints or lastUpdated = red; site behind = a warning, exit 0).
    • UNBUMPED DATA: files under data/ changed on main since the commit that last set the version (a description-only commit at the same version is not a release) = red, with the remedy (bump packages/atlas version + CHANGELOG in the UKS monorepo; the mirror and the publish follow).
    • Plumbing git (rev-list, cat-file, diff-tree), so user config cannot bend the output; env seams ATLAS_CURRENCY_REGISTRY_URL / ATLAS_CURRENCY_SITE_URL exist for the end-to-end test only and the shape test asserts the workflow sets neither.
  • scripts/package-currency.test.mjs (node:test, 22 cases): the pure verdicts, semver edges, a history walk in a throwaway repo, the shallow-clone refusal with a full-clone control, four end-to-end runs against a local HTTP server (all green; site behind = warning; 503 and an HTML body = two could-not-ask reds while UNBUMPED DATA still runs; all three red), and the workflow's shape last. The mirrored vitest collects only test/**/*.test.ts, so this file runs by node --test, which the workflow does first.

Verification

  • Real run today (2026-09-26 21:4xZ): all three green: package.json 0.6.8 = npm 0.6.8; data/index.json = live site (234 counties, 246 endpoints, lastUpdated 2026-09-26); data/ unchanged since 8b9ac29, the commit that set 0.6.8.
  • Control on real history: the unmodified script against a clone detached at aa5336d exits 1 with all three red (npm 0.6.8 ahead of 0.6.6; site 234/246 ahead of 227/241; five data files changed after 595e9b6, the commit that set 0.6.6), and git diff --name-only 595e9b6..aa5336d -- data/ lists the same five files.
  • node --test scripts/package-currency.test.mjs: 22/22. The repo's own gates untouched: npm test 35/35, npm run typecheck 0.
  • Three one-line sabotages, each anchored once, each turned only the predicted tests red and was restored by inverse edit: comparison direction in the publish-lag verdict (three tests); the workflow's run line renamed (shape test only); a push: trigger added (shape test only).
  • Mirror safety: the UKS sync (atlas-sync-push.yml) rsyncs with --exclude '.github/' and --exclude 'scripts/', so these files survive every sync. The UKS-side "publish repo kept the files it owns" post-check will name them in the agent-first PR that follows this one; merge THIS PR first, since that check fails when the named files are absent.

🤖 Generated with Claude Code

https://claude.ai/code/session_017bBpvg7AZrpRoXAsaAGovU

Leo's agent-first order (2026-09-26) makes this package the first surface
of every UrbanKit Studio change, so a lag between the monorepo, npm and
urbankitstudio.com must show up the day it happens. The facts that show
one live on npm and on the live site, where no hermetic test can look.

.github/workflows/package-currency.yml runs daily at 07:25 UTC and on
dispatch, never on push or pull_request: it needs the network, and a
network flake must never become a required check. It runs the script's
own tests first, then scripts/check-package-currency.mjs:

- PUBLISH LAG: package.json here vs npm latest. Repo ahead means the
  publish did not happen; npm ahead means the mirror lags.
- DATA LAG: data/index.json here vs the live /data/atlas/index.json on
  totals.counties, totals.endpoints and lastUpdated. The site ahead is
  red; the site behind is a warning.
- UNBUMPED DATA: data/ changed after the commit that set the version.
  Remedy: bump packages/atlas version + CHANGELOG in the UKS monorepo;
  the mirror and the publish follow.

Every check runs every time, and "could not ask" is red with its own
message. A shallow checkout is refused rather than walked to its graft.
The tests are node:test under scripts/ because the mirror sync owns
test/ and the vitest config; .github/ and scripts/ are the paths
atlas-sync-push.yml excludes from its rsync --delete.

Verified: 22/22 node tests; npm test still 5 files / 35 tests and
typecheck clean; a real run green on all three (0.6.8 = npm; 234
counties, 246 endpoints, lastUpdated 2026-09-26 = site); a replay at
aa5336d red on all three, naming the five data files that moved after
595e9b6 set 0.6.6. Sabotage, one mutation at a time, each restored:
inverted PUBLISH LAG direction (3 predicted reds), renamed script path
in the workflow (shape test red), added a push trigger (shape test red).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017bBpvg7AZrpRoXAsaAGovU
@LEOyrh
LEOyrh merged commit 8e5ade0 into main Sep 26, 2026
1 check passed
@LEOyrh
LEOyrh deleted the claude/hana-agent-first-2026-09 branch September 26, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant