diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 99ad018..0ef2cf9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -47,7 +47,5 @@ jobs: - name: Landing page loads nothing from the network run: npm run check:docs - name: Landing page bundle is in sync with src/ - run: | - npm run build:docs - git diff --exit-code -- docs/ \ - || (echo "docs/ is stale — run 'npm run build:docs' and commit the result" && exit 1) + # Also fails on NEW untracked files under docs/ — a plain `git diff` does not. + run: npm run check:docs-sync diff --git a/.github/workflows/junie-review.yml b/.github/workflows/junie-review.yml index a7d7cda..22a64e7 100644 --- a/.github/workflows/junie-review.yml +++ b/.github/workflows/junie-review.yml @@ -39,9 +39,11 @@ jobs: steps: - uses: actions/checkout@v4 - name: Review the pull request - # Pinned to the newest release rather than the moving v1 tag, so the version - # running is the version reviewed here. Bump deliberately. - uses: JetBrains/junie-github-action@v1.7.4 + # Pinned to the commit behind release v1.7.4. A tag is a mutable ref the + # publisher can repoint; only the SHA guarantees the version running is the + # version that was reviewed — this workflow handles a repo secret. Bump by + # resolving the new release's commit, not by moving the tag name alone. + uses: JetBrains/junie-github-action@c2ae82fc9fbe0eb81942ceb3d9bd3f89a6b17b95 # v1.7.4 with: junie_api_key: ${{ secrets.JUNIE_API_KEY }} # Built-in structured review prompt, as opposed to a free-form instruction. diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index 8802566..d9d2236 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -4,30 +4,28 @@ name: Deploy Pages # directly, so the page is rebuilt from src/ and checked before it goes live instead # of after. # -# REQUIRES A ONE-TIME SETTING. Settings → Pages → Build and deployment → Source must -# be "GitHub Actions", not "Deploy from a branch". Until it is, the deploy job fails -# with "Resource not accessible by integration" — the workflow is correct, the -# repository is still configured to serve the branch. The switch cannot be made from -# here: it needs a token with administration:write, which GITHUB_TOKEN is not. +# Triggered by CI completing on main rather than by the push itself, so a deploy +# implies the full suite passed — type-check, lint, tests, build, entry points, docs. +# A push that breaks a test turns main red and never reaches Pages; the previous +# wiring deployed on any docs push, green CI or not. workflow_dispatch stays as the +# manual escape hatch, and the deploy job refuses any ref that is not main. # -# It is reversible. Setting Source back to a branch restores the old behaviour and -# this workflow simply stops being able to deploy. +# REQUIRES A ONE-TIME SETTING. Settings → Pages → Build and deployment → Source must +# be "GitHub Actions", not "Deploy from a branch". Until it is, the first run fails — +# in the build job at configure-pages if Pages was never enabled, or in the deploy +# job with "Resource not accessible by integration" if Pages still serves a branch. +# Either way the workflow is correct; the repository setting is what needs to move. +# The switch cannot be made from here: it needs administration:write, which +# GITHUB_TOKEN is not. It is reversible — setting Source back to a branch restores +# the old behaviour and this workflow simply stops being able to deploy. on: - push: + workflow_run: + workflows: [ CI ] + types: [ completed ] branches: [ main ] - # docs/ holds both the page and its generated bundle, so a src/ change only - # matters here once it has been rebuilt into docs/ — which is what CI enforces. - paths: - - 'docs/**' - - '.github/workflows/pages.yml' workflow_dispatch: -permissions: - contents: read - pages: write - id-token: write - # Never cancel a deploy in flight: a half-published site is worse than a stale one. # Queue instead, so the last push wins without interrupting the one already going out. concurrency: @@ -38,6 +36,12 @@ jobs: build: name: Build and check runs-on: ubuntu-latest + # workflow_run fires on failure too — deploying is the one thing that must not. + if: github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' + # This job runs third-party code (npm postinstall scripts, the build toolchain), + # so it gets read-only. The Pages/OIDC grants live on the deploy job alone. + permissions: + contents: read steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 @@ -46,12 +50,10 @@ jobs: cache: 'npm' - name: Install dependencies run: npm ci - - name: Rebuild the page bundle from src/ - run: npm run build:docs - name: The committed page is in sync with src/ - run: | - git diff --exit-code -- docs/ \ - || (echo "docs/ is stale — run 'npm run build:docs' and commit the result" && exit 1) + # Rebuilds from src/ and fails on any difference, new untracked files included. + # Same script CI runs, so the two workflows cannot drift apart. + run: npm run check:docs-sync - name: The page loads nothing from the network run: npm run check:docs - uses: actions/configure-pages@v5 @@ -63,6 +65,11 @@ jobs: name: Deploy needs: build runs-on: ubuntu-latest + # workflow_dispatch can be pointed at any branch; production only ever serves main. + if: github.ref == 'refs/heads/main' + permissions: + pages: write + id-token: write environment: name: github-pages url: ${{ steps.deployment.outputs.page_url }} diff --git a/FRAMEWORKS.md b/FRAMEWORKS.md index 9525f58..f3e575a 100644 --- a/FRAMEWORKS.md +++ b/FRAMEWORKS.md @@ -331,9 +331,10 @@ await esbuild.build({ `cereale/min` is the whole library flattened into one minified ES module (33.9 KB, 9.6 KB gzipped) for import maps, `