develop
3
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
6adf26964e |
🌾 ci: only deploy Pages when docs/ actually changed
Gating the deploy on CI success (#12) cost the paths filter, because workflow_run cannot carry one: every green CI run on main redeployed the site, including the README-only merge in #13 that touched no published byte. The question is now asked in a `changes` job whose answer gates build and deploy. It compares docs/ against the commit behind the newest *successful* github-pages deployment — what is actually live — rather than against HEAD^. That distinction is the whole point: - a push carrying several commits may hide the docs change in any of them, and HEAD^ only sees the last one; - if the previous deploy failed, the site is a version further behind than the previous commit suggests, and HEAD^ would skip the deploy that fixes it. Deploys anyway, deliberately, when there is no successful deployment to compare against, when the live commit is missing from history (force push), and on workflow_dispatch — manual dispatch means "publish now", not "check whether I need to". Both checkouts now pin ref to github.event.workflow_run.head_sha. For workflow_run the default checkout is the branch tip, not the commit CI validated, so two pushes in quick succession could publish the newer tree under the older one's green tick. Empty on workflow_dispatch, where the dispatched ref is already what we want. Verified by extracting the step's script from the YAML and running it against this repo's real history with the API stubbed at curl: docs-identical head skips; failed-newest-deploy deploys; missing/absent/dispatch all deploy; a genuine docs change deploys and lists the files. actionlint clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK |
||
|
|
4b910f19bf |
🔍 fix: apply the code review — two visible regressions, and the gates behind them
Nine review angles, fourteen verified findings, all but the byte-table generator applied. The two that mattered most were regressions of mine: - a:hover repainted button-styled anchors, and in dark theme --accent-text equals --accent-solid — hovering the hero CTA drew its label in its own background colour. Verified invisible before (computed color == computed background) and distinct after: 10.39:1 dark, 6.90:1 light. The buttons and the skip link now re-assert their label colours on hover. - Footer links had lost every non-hover affordance: the text-decoration:none carve-out plus body-coloured links left a 2.37:1 shade difference as the only cue. The carve-out is deleted — .nav-links a and .brand already declare none themselves — and the accent rule is back on the footer. Also on the page: #ref-filter, the one text input, moves to --border-ui (it still had the 1.68:1 border the token's own comment calls decorative); focusable code surfaces get the --accent-on-code ring at -2px offset, inside the .code overflow clip; #output .out-err drops #ff8095, the last surviving colour of the deleted indigo palette; the two rgba(255,106,126) washes become color-mix over --err-line so a grep for the token finds them. The theme machinery loses a whole block: the dark media query is guarded with :not([data-theme="light"]), so an explicit light toggle falls through to the bare :root palette and the 21-token hand-copy in [data-theme="light"] is gone. Verified in all four system/toggle combinations. The page stops contradicting the repo: it claimed cereale/min "cannot tree-shake — nothing left to shake" while src/treeshake.test.ts proves the opposite on every run. Corrected here and in FRAMEWORKS.md, with the measured figures (1,837 vs 1,996 bytes for one decorator). The release facts the page was hand-bumping — both tgz names, "0.4.0 lives in the repository", the sixty-eight — now fill from meta.js/the bundle like the version badge always has. The workflows close three holes: - The docs sync gate was blind to NEW untracked build outputs (git diff does not report them; demonstrated). Both workflows now run check:docs-sync, one shared script that fails on anything porcelain reports — which also ends the copy-paste divergence between them. - pages.yml deploys on CI succeeding on main (workflow_run) instead of on the push itself, so a deploy implies green tests, not just in-sync docs. The deploy job refuses refs other than main, closing the workflow_dispatch any-branch deploy, and the build job drops pages/id-token — npm postinstall scripts no longer run alongside an OIDC grant. - The Junie action is pinned to the commit behind v1.7.4 rather than the tag, which is the immutability the previous comment promised but a mutable ref cannot deliver. Verified: every fix confirmed in a rendered browser in both themes; 72 contrast pairs still pass; no overflow at 20 widths; 268 tests, build, check:types, check:docs, actionlint all green. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK |
||
|
|
60cb8303ed |
🚀 ci: deploy Pages through Actions instead of serving the branch
Pages currently serves main /docs directly, which publishes whatever is committed with no check between the push and the live site. This builds the page from src/, asserts the committed bundle matches it, and asserts the page still loads nothing from the network — then uploads. A stale or network-dependent page fails the job instead of going live. Shape is GitHub's own starter pairing: configure-pages@v5, upload-pages-artifact@v3, deploy-pages@v5, verified to exist at those tags. Deploy is a separate job with the pages/id-token permissions scoped to it. `cancel-in-progress: false`, because a half-published site is worse than a stale one — pushes queue rather than interrupt a deploy already going out. Triggered on docs/ rather than src/: docs/ carries the generated bundle, so a src/ change only reaches the site once it has been rebuilt into docs/, which is what the CI sync check already enforces. Needs a one-time setting before it can work: Settings → Pages → Source must be "GitHub Actions" rather than "Deploy from a branch". Until then the deploy job fails on permissions. That switch needs administration:write, which GITHUB_TOKEN does not have, so it cannot be made from CI. It is reversible — setting Source back to a branch restores the current behaviour. actionlint clean across all four workflows; the build job's steps were run locally in order and pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK |