Nine review angles, fourteen verified findings, all but the byte-table generator applied. The two that mattered most were regressions of mine: - a:hover repainted button-styled anchors, and in dark theme --accent-text equals --accent-solid — hovering the hero CTA drew its label in its own background colour. Verified invisible before (computed color == computed background) and distinct after: 10.39:1 dark, 6.90:1 light. The buttons and the skip link now re-assert their label colours on hover. - Footer links had lost every non-hover affordance: the text-decoration:none carve-out plus body-coloured links left a 2.37:1 shade difference as the only cue. The carve-out is deleted — .nav-links a and .brand already declare none themselves — and the accent rule is back on the footer. Also on the page: #ref-filter, the one text input, moves to --border-ui (it still had the 1.68:1 border the token's own comment calls decorative); focusable code surfaces get the --accent-on-code ring at -2px offset, inside the .code overflow clip; #output .out-err drops #ff8095, the last surviving colour of the deleted indigo palette; the two rgba(255,106,126) washes become color-mix over --err-line so a grep for the token finds them. The theme machinery loses a whole block: the dark media query is guarded with :not([data-theme="light"]), so an explicit light toggle falls through to the bare :root palette and the 21-token hand-copy in [data-theme="light"] is gone. Verified in all four system/toggle combinations. The page stops contradicting the repo: it claimed cereale/min "cannot tree-shake — nothing left to shake" while src/treeshake.test.ts proves the opposite on every run. Corrected here and in FRAMEWORKS.md, with the measured figures (1,837 vs 1,996 bytes for one decorator). The release facts the page was hand-bumping — both tgz names, "0.4.0 lives in the repository", the sixty-eight — now fill from meta.js/the bundle like the version badge always has. The workflows close three holes: - The docs sync gate was blind to NEW untracked build outputs (git diff does not report them; demonstrated). Both workflows now run check:docs-sync, one shared script that fails on anything porcelain reports — which also ends the copy-paste divergence between them. - pages.yml deploys on CI succeeding on main (workflow_run) instead of on the push itself, so a deploy implies green tests, not just in-sync docs. The deploy job refuses refs other than main, closing the workflow_dispatch any-branch deploy, and the build job drops pages/id-token — npm postinstall scripts no longer run alongside an OIDC grant. - The Junie action is pinned to the commit behind v1.7.4 rather than the tag, which is the immutability the previous comment promised but a mutable ref cannot deliver. Verified: every fix confirmed in a rendered browser in both themes; 72 contrast pairs still pass; no overflow at 20 widths; 268 tests, build, check:types, check:docs, actionlint all green. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
80 lines
3.1 KiB
YAML
80 lines
3.1 KiB
YAML
name: Deploy Pages
|
|
|
|
# Publishes docs/ to GitHub Pages through Actions rather than by serving the branch
|
|
# directly, so the page is rebuilt from src/ and checked before it goes live instead
|
|
# of after.
|
|
#
|
|
# Triggered by CI completing on main rather than by the push itself, so a deploy
|
|
# implies the full suite passed — type-check, lint, tests, build, entry points, docs.
|
|
# A push that breaks a test turns main red and never reaches Pages; the previous
|
|
# wiring deployed on any docs push, green CI or not. workflow_dispatch stays as the
|
|
# manual escape hatch, and the deploy job refuses any ref that is not main.
|
|
#
|
|
# REQUIRES A ONE-TIME SETTING. Settings → Pages → Build and deployment → Source must
|
|
# be "GitHub Actions", not "Deploy from a branch". Until it is, the first run fails —
|
|
# in the build job at configure-pages if Pages was never enabled, or in the deploy
|
|
# job with "Resource not accessible by integration" if Pages still serves a branch.
|
|
# Either way the workflow is correct; the repository setting is what needs to move.
|
|
# The switch cannot be made from here: it needs administration:write, which
|
|
# GITHUB_TOKEN is not. It is reversible — setting Source back to a branch restores
|
|
# the old behaviour and this workflow simply stops being able to deploy.
|
|
|
|
on:
|
|
workflow_run:
|
|
workflows: [ CI ]
|
|
types: [ completed ]
|
|
branches: [ main ]
|
|
workflow_dispatch:
|
|
|
|
# Never cancel a deploy in flight: a half-published site is worse than a stale one.
|
|
# Queue instead, so the last push wins without interrupting the one already going out.
|
|
concurrency:
|
|
group: pages
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
build:
|
|
name: Build and check
|
|
runs-on: ubuntu-latest
|
|
# workflow_run fires on failure too — deploying is the one thing that must not.
|
|
if: github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success'
|
|
# This job runs third-party code (npm postinstall scripts, the build toolchain),
|
|
# so it gets read-only. The Pages/OIDC grants live on the deploy job alone.
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22.x
|
|
cache: 'npm'
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
- name: The committed page is in sync with src/
|
|
# Rebuilds from src/ and fails on any difference, new untracked files included.
|
|
# Same script CI runs, so the two workflows cannot drift apart.
|
|
run: npm run check:docs-sync
|
|
- name: The page loads nothing from the network
|
|
run: npm run check:docs
|
|
- uses: actions/configure-pages@v5
|
|
- uses: actions/upload-pages-artifact@v3
|
|
with:
|
|
path: ./docs
|
|
|
|
deploy:
|
|
name: Deploy
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
# workflow_dispatch can be pointed at any branch; production only ever serves main.
|
|
if: github.ref == 'refs/heads/main'
|
|
permissions:
|
|
pages: write
|
|
id-token: write
|
|
environment:
|
|
name: github-pages
|
|
url: ${{ steps.deployment.outputs.page_url }}
|
|
steps:
|
|
- name: Deploy to GitHub Pages
|
|
id: deployment
|
|
uses: actions/deploy-pages@v5
|