ci: run the test suite on pull requests - #122
Merged
Merged
Conversation
The `build-test` job built and smoke-tested the packed CLI but never ran a test, so nothing in `src/**/*.spec.*` gated a merge — a regression test could go red and CI would stay green. Scope Vitest to the sources first. `tsc` copies every spec into `dist/`, and stale builds and git worktrees leave further copies behind, so an unscoped run collects the same test two or three times and fails on copies whose source no longer exists. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
|
| Topic | Details | |||
|---|---|---|---|---|
| Checkout security | Harden workflow checkouts by setting persist-credentials: false before running untrusted pull request code.Modified files (1)
Latest Contributors(0)
| |||
| CI test coverage | Gate pull requests on npm test and prevent duplicate or stale spec collection by limiting Vitest to src/**/*.spec.{ts,tsx}.Modified files (2)
Latest Contributors(0)
|
Contributor
|
Your organization's Advanced Security usage limit has been reached. To continue using Advanced Security reviews, please upgrade your plan or increase your usage limits in your account settings. |
actions/checkout stores the job token as an extraheader in .git/config by default. Both jobs then run code from the pull request - npm lifecycle scripts, the test suite, knip and the packaged CLI - which can read that config and use or exfiltrate the token. Neither job performs an authenticated Git operation, so the credential is not needed at all. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
nimrodkor
approved these changes
Aug 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The
build-testjob in.github/workflows/pr.ymlinstalls, builds, packs, installs the tarball and runsbaz -h— but never runs a test. Nothing undersrc/**/*.spec.*gates a merge today, so a regression test can go red while CI stays green.Split out of #120, where a new regression test would not have been run by CI.
Change
pr.yml: add aRun testsstep tobuild-test, before the build so it fails fast.vitest.config.ts: scope collection toinclude: ["src/**/*.spec.{ts,tsx}"].The Vitest scoping is needed for the CI step to be meaningful.
tsccopies every spec intodist/, and stale builds and git worktrees leave further copies around, so an unscoped run collects the same test two or three times — and fails outright on copies whose source no longer exists (adist/components/ScrollableViewport.spec.jswith no counterpart insrc/currently does exactly that locally).Verification
On this branch:
npx vitest runcollects 2 files / 60 tests fromsrc/only (was 12 files / 264, mostly duplicates of the same specs).npm run lintandnpm run format:checkpass.Note:
tscstill emits the specs intodist/, so they ship in the package. Excluding them from the build would also stop type-checking them, so I left that alone — worth a separate look if the packaged size matters.🤖 Generated with Claude Code