Nine review angles, fourteen verified findings, all but the byte-table generator applied. The two that mattered most were regressions of mine: - a:hover repainted button-styled anchors, and in dark theme --accent-text equals --accent-solid — hovering the hero CTA drew its label in its own background colour. Verified invisible before (computed color == computed background) and distinct after: 10.39:1 dark, 6.90:1 light. The buttons and the skip link now re-assert their label colours on hover. - Footer links had lost every non-hover affordance: the text-decoration:none carve-out plus body-coloured links left a 2.37:1 shade difference as the only cue. The carve-out is deleted — .nav-links a and .brand already declare none themselves — and the accent rule is back on the footer. Also on the page: #ref-filter, the one text input, moves to --border-ui (it still had the 1.68:1 border the token's own comment calls decorative); focusable code surfaces get the --accent-on-code ring at -2px offset, inside the .code overflow clip; #output .out-err drops #ff8095, the last surviving colour of the deleted indigo palette; the two rgba(255,106,126) washes become color-mix over --err-line so a grep for the token finds them. The theme machinery loses a whole block: the dark media query is guarded with :not([data-theme="light"]), so an explicit light toggle falls through to the bare :root palette and the 21-token hand-copy in [data-theme="light"] is gone. Verified in all four system/toggle combinations. The page stops contradicting the repo: it claimed cereale/min "cannot tree-shake — nothing left to shake" while src/treeshake.test.ts proves the opposite on every run. Corrected here and in FRAMEWORKS.md, with the measured figures (1,837 vs 1,996 bytes for one decorator). The release facts the page was hand-bumping — both tgz names, "0.4.0 lives in the repository", the sixty-eight — now fill from meta.js/the bundle like the version badge always has. The workflows close three holes: - The docs sync gate was blind to NEW untracked build outputs (git diff does not report them; demonstrated). Both workflows now run check:docs-sync, one shared script that fails on anything porcelain reports — which also ends the copy-paste divergence between them. - pages.yml deploys on CI succeeding on main (workflow_run) instead of on the push itself, so a deploy implies green tests, not just in-sync docs. The deploy job refuses refs other than main, closing the workflow_dispatch any-branch deploy, and the build job drops pages/id-token — npm postinstall scripts no longer run alongside an OIDC grant. - The Junie action is pinned to the commit behind v1.7.4 rather than the tag, which is the immutability the previous comment promised but a mutable ref cannot deliver. Verified: every fix confirmed in a rendered browser in both themes; 72 contrast pairs still pass; no overflow at 20 widths; 268 tests, build, check:types, check:docs, actionlint all green. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
53 lines
2.4 KiB
YAML
53 lines
2.4 KiB
YAML
name: Junie Review
|
|
|
|
# Automated PR review by Junie, JetBrains' coding agent. Advisory only: it posts a
|
|
# summary and inline comments, and is deliberately not a required check — CI is what
|
|
# gates a merge, and a review that can block one on a judgement call is a review that
|
|
# gets rubber-stamped.
|
|
#
|
|
# Requires a JUNIE_API_KEY repository secret (Settings → Secrets and variables →
|
|
# Actions). Without it the action fails at the first step rather than skipping, so
|
|
# add the secret before merging this file.
|
|
|
|
on:
|
|
pull_request:
|
|
types: [ opened, synchronize, reopened ]
|
|
branches: [ main, develop ]
|
|
|
|
# A PR that gets three pushes in a minute should end up with one review of the final
|
|
# state, not three reviews of intermediate ones. Combined with use_single_comment
|
|
# below, each PR keeps exactly one review comment, rewritten as the diff changes.
|
|
concurrency:
|
|
group: junie-review-${{ github.event.pull_request.number }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
review:
|
|
name: Junie
|
|
runs-on: ubuntu-latest
|
|
|
|
# Secrets are not exposed to `pull_request` runs originating from a fork, so a
|
|
# fork PR would fail on an empty API key rather than review anything. Skip those
|
|
# explicitly — a skipped job reads as "not applicable", a failed one as "broken".
|
|
if: github.event.pull_request.head.repo.full_name == github.repository
|
|
|
|
permissions:
|
|
contents: read # read the diff; Junie does not push from this workflow
|
|
pull-requests: write # post the review summary and inline comments
|
|
issues: write # the PR conversation is an issue timeline to the API
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Review the pull request
|
|
# Pinned to the commit behind release v1.7.4. A tag is a mutable ref the
|
|
# publisher can repoint; only the SHA guarantees the version running is the
|
|
# version that was reviewed — this workflow handles a repo secret. Bump by
|
|
# resolving the new release's commit, not by moving the tag name alone.
|
|
uses: JetBrains/junie-github-action@c2ae82fc9fbe0eb81942ceb3d9bd3f89a6b17b95 # v1.7.4
|
|
with:
|
|
junie_api_key: ${{ secrets.JUNIE_API_KEY }}
|
|
# Built-in structured review prompt, as opposed to a free-form instruction.
|
|
prompt: "code-review"
|
|
# Update one comment across re-runs instead of appending a new one per push.
|
|
use_single_comment: "true"
|