Skip to content

Build changelog reader and JS tooling - #204

Open
kjanat wants to merge 22 commits into
stack/analysis-resultsfrom
jiggamariggama
Open

kjanat wants to merge 22 commits into
stack/analysis-resultsfrom
jiggamariggama

Conversation

@kjanat

@kjanat kjanat commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

The changelog page now bundles the reader from the checked-out workspace. Its dependency previously selected a nested registry copy of 0.0.0 while the browser loaded 0.0.3 separately from a CDN. Source exports, Vite/TypeScript resolution and the lockfile now agree on the local package. The build verifies the resolved reader belongs to this checkout, catching future version-range drift.

Sixth stack layer, based on #201; follows #182, #183, #184 and #185.

  • Add a dedicated JavaScript tooling CI job and a test:js aggregate, retaining npm test, the existing development commands, Biome coverage and the Node 24 Action checks.
  • Permit the existing root Git dependency under npm 12, update runner to 0.26.2, and scope the github-script dependency override. Fix type errors in the Action/release test scripts now covered by the tooling job.
  • Parallelize independent CI and Pages setup, use workspace-qualified playground tasks, and accept successful Release runs triggered by published releases when rebuilding Pages.
  • Preserve the candidate-based release implementation and update contributor commands.

Validation: clean npm installation; runner install --frozen test:js; playground build and tests; lint and typechecks; Action workspace tests and built entrypoint tests; focused release-script tests; workflow lint with ShellCheck; formatting and Comment Cop. The built site source map contains the workspace reader, and its HTML no longer contains the external package import map.

Share one versioned result between CLI JSON, Action JSON, and saved
reports. Publish its schema and TypeScript types with the npm package.
Keep completion status independent of advisory Action step outcomes.

BREAKING CHANGE: Action JSON wraps findings in diagnostics. Action JSONL
uses the canonical diagnostic fields and exclusive end positions.
Update runner and Docker assertions for the result object. Keep the
manual example checked against real CLI output and clarify result docs.
- Centralize tool versions (Go, Node, Pandoc) in workflow `env`
- Upgrade `runner-run` to v0.26.2 and Node.js to v26.8.2
- Refactor `package.json` scripts to use `runner` for workspace tasks
- Parallelize setup and build steps in `pages.yml`
- Remove `comment-cop` from Makefile in favor of npm scripts
- Add `.npmrc` to allow git operations from root
- Bump @kjlint/changelog-rss to v0.0.3 in playground
- Add "source" field to package exports in changelog-feed
- Configure Vite and TypeScript to resolve "source" conditions
- Clean up importmap and vite-ignore comments in playground HTML
Allow npm to install the declared Git dependency and typecheck the
Action and release test scripts exercised by the new JavaScript job.
Keep npm test available through the explicit test:js aggregate.
@kjanat kjanat added documentation Improvements or additions to documentation dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code area:ci This repository's own workflows, checks, and contributor tooling type:maintenance Upkeep: dependencies, tooling, documentation, and refactors dx Developer experience, for contributors and for people running the CLI area:release Release automation, versioning, aliases, and published artifacts github-actions Pull requests that update GitHub Actions code labels Sep 26, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T14:16:22.684143Z 2cf1ae9 New commits
🔒 Security Review ✅ Completed 2026-09-26T13:25:43.270405Z 71fbe33 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@socket-security

socket-security Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​runner-run@​0.26.1 ⏵ 0.26.276 +21009996 +1100

View full report

@kjanat kjanat self-assigned this Sep 26, 2026
@kjanat
kjanat added this pull request to stack #188 September 26, 2026 13:23
chatgpt-codex-connector[bot]

This comment was marked as resolved.

Expand package metadata consistently across the workspace and declare
Node/npm development requirements for the GitHub Action package.

Update dprint plugins and align the checks documentation formatting.
Build release-triggered Pages deployments from the default branch so
maintenance releases cannot redeploy an older checkout. Preserve the
triggering commit for pushes and manual runs.
@kjanat kjanat changed the title Build the workspace changelog reader and check JavaScript tooling Build changelog reader and JS tooling Oct 2, 2026
@kjanat
kjanat removed this pull request from stack #188 October 2, 2026 12:57
@kjanat
kjanat added this pull request to stack #217 October 2, 2026 12:57

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2cf1ae998a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread CONTRIBUTING.md
Comment on lines +297 to +298
run playground:make:build
run playground:preview

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use locally available commands in the build instructions

In a fresh checkout, installing this repository's npm dependencies places the runner-run executable in node_modules/.bin but does not expose a bare run command in the contributor's shell; only the workflows install it onto PATH via kjanat/runner. These prescribed local checks therefore fail with run: command not found unless contributors independently install extra global tooling. Use the existing root npm scripts (or npm exec) so the documented validation works from a normal project install.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

add to mise: [tool] runner-run = "latest" with [tool_alias] runner-run = "github:kjanat/runner"

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:ci This repository's own workflows, checks, and contributor tooling area:release Release automation, versioning, aliases, and published artifacts dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation dx Developer experience, for contributors and for people running the CLI github-actions Pull requests that update GitHub Actions code javascript Pull requests that update javascript code type:maintenance Upkeep: dependencies, tooling, documentation, and refactors

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant