Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/cache/releases">actions/cache's releases</a>.</em></p> <blockquote> <h2>v6.0.0</h2> <h2>What's Changed</h2> <ul> <li>Update packages, migrate to ESM by <a href="https://github.com/Samirat"><code>@Samirat</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1760">actions/cache#1760</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v6.0.0">https://github.com/actions/cache/compare/v5...v6.0.0</a></p> <h2>v5.1.0</h2> <h2>What's Changed</h2> <ul> <li>Bump <code>@actions/cache</code> to v5.1.0 - handle read-only cache access by <a href="https://github.com/jasongin"><code>@jasongin</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1775">actions/cache#1775</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v5.1.0">https://github.com/actions/cache/compare/v5...v5.1.0</a></p> <h2>v5.0.5</h2> <h2>What's Changed</h2> <ul> <li>Update ts-http-runtime dependency by <a href="https://github.com/yacaovsnc"><code>@yacaovsnc</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1747">actions/cache#1747</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v5.0.5">https://github.com/actions/cache/compare/v5...v5.0.5</a></p> <h2>v5.0.4</h2> <h2>What's Changed</h2> <ul> <li>Add release instructions and update maintainer docs by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1696">actions/cache#1696</a></li> <li>Potential fix for code scanning alert no. 52: Workflow does not contain permissions by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1697">actions/cache#1697</a></li> <li>Fix workflow permissions and cleanup workflow names / formatting by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1699">actions/cache#1699</a></li> <li>docs: Update examples to use the latest version by <a href="https://github.com/XZTDean"><code>@XZTDean</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li> <li>Fix proxy integration tests by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1701">actions/cache#1701</a></li> <li>Fix cache key in examples.md for bun.lock by <a href="https://github.com/RyPeck"><code>@RyPeck</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li> <li>Update dependencies & patch security vulnerabilities by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1738">actions/cache#1738</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/XZTDean"><code>@XZTDean</code></a> made their first contribution in <a href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li> <li><a href="https://github.com/RyPeck"><code>@RyPeck</code></a> made their first contribution in <a href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v5.0.4">https://github.com/actions/cache/compare/v5...v5.0.4</a></p> <h2>v5.0.3</h2> <h2>What's Changed</h2> <ul> <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li> <li>Bump <code>@actions/core</code> to v2.0.3</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v5.0.3">https://github.com/actions/cache/compare/v5...v5.0.3</a></p> <h2>v.5.0.2</h2> <h1>v5.0.2</h1> <h2>What's Changed</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/actions/cache/blob/main/RELEASES.md">actions/cache's changelog</a>.</em></p> <blockquote> <h1>Releases</h1> <h2>How to prepare a release</h2> <blockquote> <p>[!NOTE] Relevant for maintainers with write access only.</p> </blockquote> <ol> <li>Switch to a new branch from <code>main</code>.</li> <li>Run <code>npm test</code> to ensure all tests are passing.</li> <li>Update the version in <a href="https://github.com/actions/cache/blob/main/package.json"><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li> <li>Run <code>npm run build</code> to update the compiled files.</li> <li>Update this <a href="https://github.com/actions/cache/blob/main/RELEASES.md"><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a> with the new version and changes in the <code>## Changelog</code> section.</li> <li>Run <code>licensed cache</code> to update the license report.</li> <li>Run <code>licensed status</code> and resolve any warnings by updating the <a href="https://github.com/actions/cache/blob/main/.licensed.yml"><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a> file with the exceptions.</li> <li>Commit your changes and push your branch upstream.</li> <li>Open a pull request against <code>main</code> and get it reviewed and merged.</li> <li>Draft a new release <a href="https://github.com/actions/cache/releases">https://github.com/actions/cache/releases</a> use the same version number used in <code>package.json</code> <ol> <li>Create a new tag with the version number.</li> <li>Auto generate release notes and update them to match the changes you made in <code>RELEASES.md</code>.</li> <li>Toggle the set as the latest release option.</li> <li>Publish the release.</li> </ol> </li> <li>Navigate to <a href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml">https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a> <ol> <li>There should be a workflow run queued with the same version number.</li> <li>Approve the run to publish the new version and update the major tags for this action.</li> </ol> </li> </ol> <h2>Changelog</h2> <h3>6.1.0</h3> <ul> <li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a href="https://redirect.github.com/actions/toolkit/pull/2435">actions/toolkit#2435 Handle cache write error due to read-only token</a></li> <li>Switch redundant "Cache save failed" warning to debug log in save-only</li> </ul> <h3>6.0.0</h3> <ul> <li>Updated <code>@actions/cache</code> to ^6.0.1, <code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to ^3.0.0, <code>@actions/io</code> to ^3.0.2</li> <li>Migrated to ESM module system</li> <li>Upgraded Jest to v30 and test infrastructure to be ESM compatible</li> </ul> <h3>5.0.4</h3> <ul> <li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar patterns)</li> <li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)</li> <li>Bump <code>fast-xml-parser</code> to v5.5.6</li> </ul> <h3>5.0.3</h3> <ul> <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li> <li>Bump <code>@actions/core</code> to v2.0.3</li> </ul> <h3>5.0.2</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="55cc834586"><code>55cc834</code></a> Merge pull request <a href="https://redirect.github.com/actions/cache/issues/1768">#1768</a> from jasongin/readonly-cache</li> <li><a href="d8cd72f230"><code>d8cd72f</code></a> Bump <code>@actions/cache</code> to v6.1.0 - handle cache write error due to RO token</li> <li><a href="2c8a9bd745"><code>2c8a9bd</code></a> Merge pull request <a href="https://redirect.github.com/actions/cache/issues/1760">#1760</a> from actions/samirat/esm_migration_and_package_update</li> <li><a href="e9b91fdc3f"><code>e9b91fd</code></a> Prettier fixes</li> <li><a href="e4884b8ff7"><code>e4884b8</code></a> Rebuild dist</li> <li><a href="10baf0191a"><code>10baf01</code></a> Fixed licenses</li> <li><a href="e39b386c90"><code>e39b386</code></a> Fix test mock return order</li> <li><a href="b692820337"><code>b692820</code></a> PR feedback</li> <li><a href="60749128a4"><code>6074912</code></a> Rebuild dist bundles as ESM to match type:module</li> <li><a href="5a912e8b4a"><code>5a912e8</code></a> Fix lint and jest issues</li> <li>Additional commits viewable in <a href="https://github.com/actions/cache/compare/v4...v6">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
248 lines
10 KiB
YAML
248 lines
10 KiB
YAML
name: PR Checks
|
|
|
|
# The thin trusted merge gate (docs/plans/2026-06-04-001-refactor-fast-trusted-test-gate-plan.md).
|
|
# Blocking checks are exactly: Lint, Typecheck, Build, Gate.
|
|
#
|
|
# BRANCH-PROTECTION CUTOVER: required status checks are matched by job name.
|
|
# When this file changes job names, update the repo's branch-protection
|
|
# required checks to exactly [Lint, Typecheck, Build, Gate] — a stale required
|
|
# name (e.g. "Test shard 1/4") that no longer reports will block every PR
|
|
# with "Expected — waiting for status". Open PRs must rebase onto main after
|
|
# the cutover so they run this workflow shape.
|
|
#
|
|
# Everything that used to run here as shards / slow tier / inventory guard is
|
|
# non-blocking and lives in full-suite.yml (push to main).
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
concurrency:
|
|
group: pr-checks-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
# Least-privilege token: every job here only reads the repo (checkout + cache).
|
|
permissions:
|
|
contents: read
|
|
|
|
# FN-4863: Opt JavaScript actions into Node 24 ahead of GitHub's forced cutover on 2026-06-02.
|
|
env:
|
|
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
|
|
|
|
jobs:
|
|
lint:
|
|
name: Lint
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Node.js and pnpm
|
|
uses: ./.github/actions/setup-node-pnpm
|
|
|
|
- name: Lint
|
|
run: pnpm lint
|
|
|
|
- name: Changeset format
|
|
run: pnpm check:changesets
|
|
|
|
- name: Dashboard route modularity
|
|
run: pnpm check:routes-modular
|
|
|
|
typecheck:
|
|
name: Typecheck
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Node.js and pnpm
|
|
uses: ./.github/actions/setup-node-pnpm
|
|
|
|
# FNXC:CIGateSpeed 2026-07-23-00:05:
|
|
# tsc incremental buildinfo cache. tsconfig.base.json enables
|
|
# `incremental` with per-package dist/.tsbuildinfo; a restored buildinfo
|
|
# is SELF-VALIDATING (tsc hashes every input against it and re-checks
|
|
# whatever changed), so restore-keys can never let a stale check through
|
|
# — it only shrinks the re-checked set. Cold typecheck was ~4 min of the
|
|
# PR critical path. Keyed by SHA so every commit saves a fresh snapshot;
|
|
# restore-keys picks the nearest prior one (same PR, or main via the
|
|
# warm-gate-build-cache job in full-suite.yml, which must keep an
|
|
# identical path list — actions/cache versions caches by path list).
|
|
- name: Cache TypeScript incremental buildinfo
|
|
uses: actions/cache@v6
|
|
with:
|
|
path: |
|
|
packages/*/dist/.tsbuildinfo
|
|
packages/dashboard/dist/.tsbuildinfo-app
|
|
plugins/*/dist/.tsbuildinfo
|
|
key: typecheck-tsbuildinfo-${{ runner.os }}-${{ github.sha }}
|
|
restore-keys: |
|
|
typecheck-tsbuildinfo-${{ runner.os }}-
|
|
|
|
- name: Typecheck
|
|
run: pnpm typecheck
|
|
|
|
build:
|
|
name: Build
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Node.js and pnpm
|
|
uses: ./.github/actions/setup-node-pnpm
|
|
|
|
# FNXC:CIGateSpeed 2026-07-23-00:05:
|
|
# RESTORE-ONLY tap of the gate's incremental dist cache (see the gate
|
|
# job's cache block for the full safety rationale: `pnpm build` always
|
|
# runs and reconciles a near-match restore per package by content hash).
|
|
# Restore-only (actions/cache/restore, never save) because this job runs
|
|
# FULL CLI packaging (CI=true → desktop + bundled plugins + DTS), and
|
|
# saving that shape would swap the cache's canonical fast-CLI contents
|
|
# out from under the Gate job. Full CLI packaging itself is never skipped
|
|
# regardless of cache state (ensureFullPackageCliPlanned force-plans the
|
|
# CLI in full mode), so this job's distinctive coverage is preserved.
|
|
# Path list must stay byte-identical to the gate job's block.
|
|
- name: Compute dist source hash
|
|
id: dist-hash
|
|
run: echo "hash=$(node scripts/ensure-test-artifacts.mjs --print-source-hash)" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Restore built dist artifacts (incremental, restore-only)
|
|
uses: actions/cache/restore@v6
|
|
with:
|
|
path: |
|
|
packages/core/dist
|
|
packages/dashboard/dist
|
|
packages/engine/dist
|
|
packages/plugin-sdk/dist
|
|
packages/cli/dist
|
|
plugins/fusion-plugin-dependency-graph/dist
|
|
plugins/fusion-plugin-hermes-runtime/dist
|
|
plugins/fusion-plugin-openclaw-runtime/dist
|
|
plugins/fusion-plugin-paperclip-runtime/dist
|
|
.fusion/cache/plugin-build-cache.json
|
|
key: gate-dist-${{ runner.os }}-${{ steps.dist-hash.outputs.hash }}
|
|
restore-keys: |
|
|
gate-dist-${{ runner.os }}-
|
|
|
|
- name: Build
|
|
run: pnpm build
|
|
|
|
# The only merge-blocking TEST signal (R3). Runs the boot smoke (the app
|
|
# starts and serves) plus the curated engine-core suite and the CI-shape
|
|
# test — see `test:gate` in the root package.json. Gate membership is the
|
|
# explicit allow-list in packages/engine/vitest.config.ts (engine-core
|
|
# project); a flaky gate test is evicted by removing it from that list.
|
|
gate:
|
|
name: Gate
|
|
runs-on: ubuntu-latest
|
|
# FNXC:FixPgTestsAndCi 2026-06-26-09:10:
|
|
# Provision a PostgreSQL service container so the postgres/*.pg.test.ts
|
|
# suites (pgDescribe) run in the merge gate. The pg-test-harness probe
|
|
# detects reachability via a TCP probe on localhost:5432 and skips when
|
|
# unavailable, so this service is what makes the 57 PG twin tests actually
|
|
# execute instead of being silently skipped.
|
|
services:
|
|
postgres:
|
|
image: postgres:15
|
|
env:
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_PASSWORD: postgres
|
|
POSTGRES_DB: postgres
|
|
ports:
|
|
- 5432:5432
|
|
# Mark the service healthy only when pg_isready succeeds on the mapped
|
|
# port, so job steps don't start before Postgres accepts connections.
|
|
options: >-
|
|
--health-cmd "pg_isready -h localhost -p 5432 -U postgres"
|
|
--health-interval 5s
|
|
--health-timeout 5s
|
|
--health-retries 10
|
|
env:
|
|
# Point the PG test harness at the service container. psql admin DDL
|
|
# (CREATE/DROP DATABASE) runs against this URL's maintenance database.
|
|
FUSION_PG_TEST_URL_BASE: "postgresql://postgres:postgres@localhost:5432"
|
|
PGPASSWORD: "postgres"
|
|
# The gate's value is speed; without a job timeout a hung build or
|
|
# deadlocked vitest worker blocks every PR for GitHub's default 6 hours.
|
|
# Expected runtime is ~3-5 min.
|
|
timeout-minutes: 15
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Node.js and pnpm
|
|
uses: ./.github/actions/setup-node-pnpm
|
|
|
|
# FNXC:CIGateSpeed 2026-07-22-23:30:
|
|
# Gate-scoped INCREMENTAL dist cache (`gate-dist-*` namespace, distinct from
|
|
# the shard jobs' exact-match `dist-*` contract). Unlike the shard jobs —
|
|
# where restore-keys is forbidden because tests consume restored dist
|
|
# WITHOUT a build (stale dist was the FN-4232/FN-4605 failure mode) — the
|
|
# gate always runs `pnpm build` after restore. build-workspace.mjs verifies
|
|
# every package's git content hash against .fusion/cache/plugin-build-cache.json
|
|
# (cached below alongside dist) and rebuilds anything changed, missing, or
|
|
# unhashed, so a near-match restore can only speed the build up, never let
|
|
# stale dist through. Measured before this change: every PR missed the
|
|
# exact key and paid a full ~6-8 min build for ~45s of actual gate tests.
|
|
# NEVER add node_modules here (breaks Windows pnpm junctions elsewhere).
|
|
# The warm-gate-build-cache job in full-suite.yml saves this same cache
|
|
# (identical path list — actions/cache versions caches by path list, so
|
|
# the two blocks must stay in sync) on every push to main so a PR's FIRST
|
|
# gate run restores main's build instead of building cold.
|
|
- name: Compute dist source hash
|
|
id: dist-hash
|
|
run: echo "hash=$(node scripts/ensure-test-artifacts.mjs --print-source-hash)" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Cache built dist artifacts (incremental)
|
|
id: dist-cache
|
|
uses: actions/cache@v6
|
|
with:
|
|
path: |
|
|
packages/core/dist
|
|
packages/dashboard/dist
|
|
packages/engine/dist
|
|
packages/plugin-sdk/dist
|
|
packages/cli/dist
|
|
plugins/fusion-plugin-dependency-graph/dist
|
|
plugins/fusion-plugin-hermes-runtime/dist
|
|
plugins/fusion-plugin-openclaw-runtime/dist
|
|
plugins/fusion-plugin-paperclip-runtime/dist
|
|
.fusion/cache/plugin-build-cache.json
|
|
key: gate-dist-${{ runner.os }}-${{ steps.dist-hash.outputs.hash }}
|
|
restore-keys: |
|
|
gate-dist-${{ runner.os }}-
|
|
|
|
# Only seed the mtime-defeating artifact hash-cache on an EXACT hit; on a
|
|
# restore-keys near-hit the restored dist may be stale for changed
|
|
# packages, and `pnpm build` below is what reconciles it.
|
|
- name: Seed artifact hash-cache on cache hit
|
|
if: steps.dist-cache.outputs.cache-hit == 'true'
|
|
run: node scripts/ensure-test-artifacts.mjs --seed-artifact-cache
|
|
|
|
# FNXC:CIGateSpeed 2026-07-22-23:30:
|
|
# Boot smoke needs the built workspace including the CLI. Fast CLI
|
|
# packaging (bin.js + extension.js, no desktop/bundled-plugin/DTS staging)
|
|
# is sufficient for boot smoke + test:gate and is the same shape
|
|
# `pnpm verify:fast` proves locally; CI=true would otherwise force the
|
|
# multi-minute full packaging tail on every gate run. Full CLI packaging
|
|
# coverage stays blocking in the separate Build job.
|
|
- name: Build
|
|
run: pnpm build
|
|
env:
|
|
FUSION_CLI_FULL_PACKAGE: "0"
|
|
|
|
- name: Boot smoke (app starts and serves)
|
|
run: node scripts/boot-smoke.mjs
|
|
|
|
- name: Gate tests (curated engine-core + CI-shape)
|
|
run: pnpm test:gate
|
|
|
|
# Advisory desktop-packaging validation lives in its OWN workflow (desktop-packaging.yml) so this
|
|
# thin gate stays exactly [Lint, Typecheck, Build, Gate] — the job set here maps 1:1 to the
|
|
# branch-protection required checks (CI-shape test enforces the invariant).
|