diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 99ad018..0ef2cf9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -47,7 +47,5 @@ jobs: - name: Landing page loads nothing from the network run: npm run check:docs - name: Landing page bundle is in sync with src/ - run: | - npm run build:docs - git diff --exit-code -- docs/ \ - || (echo "docs/ is stale — run 'npm run build:docs' and commit the result" && exit 1) + # Also fails on NEW untracked files under docs/ — a plain `git diff` does not. + run: npm run check:docs-sync diff --git a/.github/workflows/junie-review.yml b/.github/workflows/junie-review.yml index 382fbcc..22a64e7 100644 --- a/.github/workflows/junie-review.yml +++ b/.github/workflows/junie-review.yml @@ -39,7 +39,11 @@ jobs: steps: - uses: actions/checkout@v4 - name: Review the pull request - uses: JetBrains/junie-github-action@v1 + # Pinned to the commit behind release v1.7.4. A tag is a mutable ref the + # publisher can repoint; only the SHA guarantees the version running is the + # version that was reviewed — this workflow handles a repo secret. Bump by + # resolving the new release's commit, not by moving the tag name alone. + uses: JetBrains/junie-github-action@c2ae82fc9fbe0eb81942ceb3d9bd3f89a6b17b95 # v1.7.4 with: junie_api_key: ${{ secrets.JUNIE_API_KEY }} # Built-in structured review prompt, as opposed to a free-form instruction. diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml new file mode 100644 index 0000000..d9d2236 --- /dev/null +++ b/.github/workflows/pages.yml @@ -0,0 +1,79 @@ +name: Deploy Pages + +# Publishes docs/ to GitHub Pages through Actions rather than by serving the branch +# directly, so the page is rebuilt from src/ and checked before it goes live instead +# of after. +# +# Triggered by CI completing on main rather than by the push itself, so a deploy +# implies the full suite passed — type-check, lint, tests, build, entry points, docs. +# A push that breaks a test turns main red and never reaches Pages; the previous +# wiring deployed on any docs push, green CI or not. workflow_dispatch stays as the +# manual escape hatch, and the deploy job refuses any ref that is not main. +# +# REQUIRES A ONE-TIME SETTING. Settings → Pages → Build and deployment → Source must +# be "GitHub Actions", not "Deploy from a branch". Until it is, the first run fails — +# in the build job at configure-pages if Pages was never enabled, or in the deploy +# job with "Resource not accessible by integration" if Pages still serves a branch. +# Either way the workflow is correct; the repository setting is what needs to move. +# The switch cannot be made from here: it needs administration:write, which +# GITHUB_TOKEN is not. It is reversible — setting Source back to a branch restores +# the old behaviour and this workflow simply stops being able to deploy. + +on: + workflow_run: + workflows: [ CI ] + types: [ completed ] + branches: [ main ] + workflow_dispatch: + +# Never cancel a deploy in flight: a half-published site is worse than a stale one. +# Queue instead, so the last push wins without interrupting the one already going out. +concurrency: + group: pages + cancel-in-progress: false + +jobs: + build: + name: Build and check + runs-on: ubuntu-latest + # workflow_run fires on failure too — deploying is the one thing that must not. + if: github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' + # This job runs third-party code (npm postinstall scripts, the build toolchain), + # so it gets read-only. The Pages/OIDC grants live on the deploy job alone. + permissions: + contents: read + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22.x + cache: 'npm' + - name: Install dependencies + run: npm ci + - name: The committed page is in sync with src/ + # Rebuilds from src/ and fails on any difference, new untracked files included. + # Same script CI runs, so the two workflows cannot drift apart. + run: npm run check:docs-sync + - name: The page loads nothing from the network + run: npm run check:docs + - uses: actions/configure-pages@v5 + - uses: actions/upload-pages-artifact@v3 + with: + path: ./docs + + deploy: + name: Deploy + needs: build + runs-on: ubuntu-latest + # workflow_dispatch can be pointed at any branch; production only ever serves main. + if: github.ref == 'refs/heads/main' + permissions: + pages: write + id-token: write + environment: + name: github-pages + url: ${{ steps.deployment.outputs.page_url }} + steps: + - name: Deploy to GitHub Pages + id: deployment + uses: actions/deploy-pages@v5 diff --git a/FRAMEWORKS.md b/FRAMEWORKS.md index 9525f58..f3e575a 100644 --- a/FRAMEWORKS.md +++ b/FRAMEWORKS.md @@ -331,9 +331,10 @@ await esbuild.build({ `cereale/min` is the whole library flattened into one minified ES module (33.9 KB, 9.6 KB gzipped) for import maps, `