ci.yml 3.4 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091
  1. name: CI
  2. on:
  3. push:
  4. branches: [main, master]
  5. pull_request:
  6. concurrency:
  7. group: ${{ github.workflow }}-${{ github.ref }}
  8. cancel-in-progress: true
  9. jobs:
  10. checks:
  11. runs-on: ubuntu-latest
  12. strategy:
  13. fail-fast: false
  14. matrix:
  15. node: [24, 26]
  16. name: node ${{ matrix.node }}
  17. steps:
  18. - uses: actions/checkout@v6
  19. - uses: actions/setup-node@v6
  20. with:
  21. node-version: ${{ matrix.node }}
  22. - name: Enable corepack (pnpm)
  23. run: corepack enable
  24. - name: Install (immutable)
  25. run: pnpm install --frozen-lockfile
  26. - name: Constraints
  27. run: pnpm run constraints
  28. # Before lint: the type-aware ESLint config resolves vendor packages via
  29. # their built declarations (tsconfig.typecheck.json -> vendor/*/lib),
  30. # which `pnpm run typecheck` emits. Lint on a fresh checkout would otherwise
  31. # see unresolved types and erupt with no-unsafe-* errors.
  32. - name: Typecheck (src + tests + examples)
  33. run: pnpm run typecheck
  34. - name: Lint
  35. run: pnpm run lint
  36. # Doc-sync gates (doc-sync-enforcement RFC). doc-typecheck compiles the fenced ts blocks in
  37. # the docs and resolves vendor packages via their built declarations, which
  38. # the typecheck step above emits — so it runs after typecheck. The cordis
  39. # catalog freshness check, type-equiv check, and markdown wrap/link checks
  40. # only read source. Same `doc-sync` script the pre-push hook runs
  41. # (quality-gates RFC: one source of truth).
  42. - name: Doc-sync gates (doc code blocks + cordis catalog + type-equiv + markdown wrap/links)
  43. run: pnpm run doc-sync
  44. # Module-graph freshness: regenerate docs/module-graph.md from the
  45. # packages' peerDependencies and fail if it differs from the committed
  46. # file. Only reads source package.json — no build needed.
  47. - name: Module-graph freshness
  48. run: pnpm run verify-module-graph
  49. - name: Tests with coverage gate (per-file 100%)
  50. run: pnpm run test:coverage
  51. # ACP snapshot tests (acp-snapshot-tests RFC): boot the real acp-agent
  52. # subprocess and replay recorded session-log fixtures, diffing the
  53. # normalized stdout transcript + re-persisted log against committed
  54. # goldens. KEYLESS by design — the same `test:snapshot` script the pre-push
  55. # hook runs (one source of truth), so the full-transcript regression net
  56. # is part of every PR gate, not just local pre-push.
  57. - name: Snapshot tests (ACP transcript replay)
  58. run: pnpm run test:snapshot
  59. # Before hygiene: publint validates the packed artifacts (lib/index.js),
  60. # which only the tsdown bundling step emits.
  61. - name: Build (tsc -b + tsdown bundles)
  62. run: pnpm run build
  63. - name: Hygiene (knip + publint)
  64. run: pnpm run knip && pnpm run publint
  65. - name: Demo smoke test
  66. run: |
  67. set -euo pipefail
  68. out=$(printf 'echo ci smoke\n' | timeout 60 node --expose-internals --import tsx examples/echo-agent/start.ts 2>&1)
  69. echo "$out"
  70. echo "$out" | grep -q '\[tool call\] echo({"text":"ci smoke"})'
  71. echo "$out" | grep -q '\[tool result\] ECHO: CI SMOKE'
  72. # The JSONL backend (root ./.sessions, no cwd → _no-cwd bucket) writes a
  73. # per-run session log named main-session-<uuid>.jsonl. Assert one exists.
  74. ls .sessions/_no-cwd/main-session-*.jsonl >/dev/null
  75. rm -rf .sessions