Sitelet https://github.com/actions/checkout/pull/2581
Skip to content

Add GitHub Actions workflow for Node.js with Webpack - #2581

Open
nangiasagar94 wants to merge 1 commit into
actions:mainfrom
nangiasagar94:main
Open

nangiasagar94 wants to merge 1 commit into
actions:mainfrom
nangiasagar94:main

Conversation

@nangiasagar94

Copy link
Copy Markdown

No description provided.

eleshar added a commit to lightspeedwp/.github that referenced this pull request Sep 23, 2026
Address CodeRabbit review on #3486: the base repository serves fork
head commits, so reading at pr.head.sha from context.repo works for
forks, including deleted ones, with a token scoped to the caller.
Verified against a live fork PR (actions/checkout#2581).
eleshar added a commit to lightspeedwp/.github that referenced this pull request Sep 24, 2026
* Clear workflow shellcheck debt and fix consumption examples (#3478)

- Quote GITHUB_OUTPUT/GITHUB_STEP_SUMMARY, group redirects, read -r.
- Metrics prune: NUL-delimited file listing instead of ls piped to
  xargs; the old form failed to delete files with spaces in their names.
- documentation.yml summary: expressions via env, not inline.
- workflow-lint: run shellcheck at default severity.
- Examples: drop calls to reusable workflows that do not exist (#3480),
  pin every action to a commit SHA, supported PHP, concurrency, timeouts.

Unused composite actions are kept: spec 011 tasks T032/T043/T052/T064
integrate them.

* Activate organisation reusable workflows (#3480)

Moves the GitHub Actions files out of the agentic-runbook folder
workflows/, where GitHub never ran them:

- ai-feedback-validation: on workflow_call, enforce input (default false:
  warn only). Checks out this repo at job.workflow_sha for its helpers,
  reads FEEDBACK_RESPONSE.md from the PR head via the API, never runs PR
  code, degrades to a log warning on read-only tokens. Fixes the invalid
  github.pull_request.number context and a job gated on a payload field
  that does not exist.
- orchestrate-phase-progression: on workflow_call, dry-run input. The
  handlers only logged ("GitHub API call would go here"); label writes now
  go through the new apply-label-changes module, which adds only labels
  that exist in the repo and never strips a phase it cannot replace.
  "PR opened" no longer fires on every push (synchronize); the sync
  handler now accepts the "opened" action GitHub sends.
- pr-creation-agent-integration-tests: archived; repo-wide tests are #3479.
- In-repo callers ai-feedback.yml and phase-progression.yml.

Also fixes two defects found on the way: the clipboard status marker was
never matched (character class without the u flag), and
validate-frontmatter dropped its final output line intermittently
(process.exit with piped stdout).

* Read FEEDBACK_RESPONSE.md through the base repository (#3480)

Address CodeRabbit review on #3486: the base repository serves fork
head commits, so reading at pr.head.sha from context.repo works for
forks, including deleted ones, with a token scoped to the caller.
Verified against a live fork PR (actions/checkout#2581).

* Only trusted authors can advance phases from PRs (#3480)

Under pull_request_target any fork PR could advance the phase of any
issue by naming it in its body. The PR job now requires a same-repository
branch or an OWNER/MEMBER/COLLABORATOR author. Raised by security review.

* fix(ci): fail artifact pruning on errors and order by filename (#3478)

CodeRabbit review on #3483: the find/sort pipeline ran in a process
substitution with || true, so a failure pruned nothing and still reported
success. It now runs synchronously into a NUL-delimited file under
pipefail, and a missing directory is handled explicitly.

It also sorted by mtime, which actions/checkout sets to the same value for
every file, so the 30 kept were arbitrary. Artifact names start with a UTC
timestamp, so order by name.

* fix(automation): add phase labels before removing the old ones (#3480)

applyLabelChanges removed the current label before adding the next one, so
a failed addLabels call (5xx, rate limit, permissions) left the issue with
no openspec phase label. Adding first means a failed removal leaves two
labels, which is visible and easy to fix. Tests cover the order and the
failed-add case.

docs: the Related Resources links in WORKFLOW_AI_FEEDBACK_VALIDATION.md
resolved against the wrong base; they now point at the real files.

* docs(examples): make the scaffold CI examples runnable on a clean repo (#3478)

- Theme: the scaffold's npm lint and test also run composer lint (phpcs)
  and composer test (phpunit), so set up PHP and run composer install
  first, matching the plugin example.
- Theme and plugin: both scaffolds gitignore package-lock.json, which
  npm ci and the npm cache need. Say to commit the lockfile first.
eleshar added a commit to lightspeedwp/.github that referenced this pull request Sep 25, 2026
* Clear workflow shellcheck debt and fix consumption examples (#3478)

- Quote GITHUB_OUTPUT/GITHUB_STEP_SUMMARY, group redirects, read -r.
- Metrics prune: NUL-delimited file listing instead of ls piped to
  xargs; the old form failed to delete files with spaces in their names.
- documentation.yml summary: expressions via env, not inline.
- workflow-lint: run shellcheck at default severity.
- Examples: drop calls to reusable workflows that do not exist (#3480),
  pin every action to a commit SHA, supported PHP, concurrency, timeouts.

Unused composite actions are kept: spec 011 tasks T032/T043/T052/T064
integrate them.

* Activate organisation reusable workflows (#3480)

Moves the GitHub Actions files out of the agentic-runbook folder
workflows/, where GitHub never ran them:

- ai-feedback-validation: on workflow_call, enforce input (default false:
  warn only). Checks out this repo at job.workflow_sha for its helpers,
  reads FEEDBACK_RESPONSE.md from the PR head via the API, never runs PR
  code, degrades to a log warning on read-only tokens. Fixes the invalid
  github.pull_request.number context and a job gated on a payload field
  that does not exist.
- orchestrate-phase-progression: on workflow_call, dry-run input. The
  handlers only logged ("GitHub API call would go here"); label writes now
  go through the new apply-label-changes module, which adds only labels
  that exist in the repo and never strips a phase it cannot replace.
  "PR opened" no longer fires on every push (synchronize); the sync
  handler now accepts the "opened" action GitHub sends.
- pr-creation-agent-integration-tests: archived; repo-wide tests are #3479.
- In-repo callers ai-feedback.yml and phase-progression.yml.

Also fixes two defects found on the way: the clipboard status marker was
never matched (character class without the u flag), and
validate-frontmatter dropped its final output line intermittently
(process.exit with piped stdout).

* Read FEEDBACK_RESPONSE.md through the base repository (#3480)

Address CodeRabbit review on #3486: the base repository serves fork
head commits, so reading at pr.head.sha from context.repo works for
forks, including deleted ones, with a token scoped to the caller.
Verified against a live fork PR (actions/checkout#2581).

* Only trusted authors can advance phases from PRs (#3480)

Under pull_request_target any fork PR could advance the phase of any
issue by naming it in its body. The PR job now requires a same-repository
branch or an OWNER/MEMBER/COLLABORATOR author. Raised by security review.

* Run Jest on every PR, failing only on new failures (#3479)

No active workflow ran the test suite, so regressions merged green (two
broke in #3477 and were found only by hand). tests.yml runs Jest on the
PR head and base in parallel and compare-jest-failures.cjs fails the
check only for failures the PR introduces, while develop still carries
known failures (#3472). Replayed against the saved #3477 reports it
reports the 5 regressed changelog-unified tests and exits 1.

Also warns (not fails) when the suite dirties the working tree (#3482).

* Keep the test comparison summary when new failures are found (#3479)

The default shell is bash -e, so a non-zero comparison aborted the step
before the job summary was written. Simulated under bash -eo pipefail:
regression exits 1 with the summary, no regression exits 0.

* Make the collection-duration test deterministic (#3479)

It slept 100 ms and asserted duration >= 100, but timers can fire up to
1 ms early relative to Date.now(), so it failed intermittently. Found by
the new Tests workflow reporting it as fixed since base on #3487.

* Use inclusive jitter bounds in the backoff test (#3479)

Jitter is +/-10% and rounded, so a delay can land exactly on 900/1100 ms;
the strict bounds failed intermittently. Found when the new Tests
workflow flagged it as a new failure on #3487. Adds deterministic
extreme cases (Math.random pinned) that hit both bounds exactly.

* fix(ci): fail artifact pruning on errors and order by filename (#3478)

CodeRabbit review on #3483: the find/sort pipeline ran in a process
substitution with || true, so a failure pruned nothing and still reported
success. It now runs synchronously into a NUL-delimited file under
pipefail, and a missing directory is handled explicitly.

It also sorted by mtime, which actions/checkout sets to the same value for
every file, so the 30 kept were arbitrary. Artifact names start with a UTC
timestamp, so order by name.

* fix(automation): add phase labels before removing the old ones (#3480)

applyLabelChanges removed the current label before adding the next one, so
a failed addLabels call (5xx, rate limit, permissions) left the issue with
no openspec phase label. Adding first means a failed removal leaves two
labels, which is visible and easy to fix. Tests cover the order and the
failed-add case.

docs: the Related Resources links in WORKFLOW_AI_FEEDBACK_VALIDATION.md
resolved against the wrong base; they now point at the real files.

* docs(examples): make the scaffold CI examples runnable on a clean repo (#3478)

- Theme: the scaffold's npm lint and test also run composer lint (phpcs)
  and composer test (phpunit), so set up PHP and run composer install
  first, matching the plugin example.
- Theme and plugin: both scaffolds gitignore package-lock.json, which
  npm ci and the npm cache need. Say to commit the lockfile first.

* fix(ci): harden Jest pull request gate

* fix(ci): keep tested Markdown in Jest

* fix(changelog): shorten Jest gate entry

* fix: apply CodeRabbit auto-fixes

* fix: reject testless Jest reports

* test: remove flaky timer lower bound

* test: stop two 100ms-boundary timing assertions flaking under load

Both assertions measured Date.now() across two reads with millisecond
granularity and sat exactly on the bound their setTimeout slept for, so
the elapsed value landed on 99ms and the suite failed intermittently.
Measured 1 failure in 6 full-suite runs on develop before this change,
with 281 suites competing for CPU.

Affected, both found by grepping the pattern rather than by chasing the
one failure I happened to see first:

- scripts/metrics/__tests__/integration.test.js
- scripts/workflows/__tests__/metrics-collection-orchestrator.test.js

Each sleep now carries 50ms of headroom above the asserted bound, which
the assertion still requires. Verified by fault injection that both
still fail when the work is skipped: forcing the sleep to 0 yields
elapsed 1 and 2 against the >=100 bound. 12 consecutive full-suite runs
with 0 failures afterwards.

Refs #3572. This is a precondition for the Jest gate in this branch:
#3487 fails on any new failure, so a 1-in-6 flake would turn roughly
every sixth pull request red for no reason.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant