[quality] dependabot PRs bumping ncc-bundled deps always fail the dist/ gate — add a repack-dist job to test.yml
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 68/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- github-actions, node.js
- Área
- build-system, ci-cd
Línea de trabajo
Start by reading .github/workflows/test.yml, then check .github/dependabot.yml and the existing build-test job to understand dependency groups and dist/ validation. Verify the behavior against #167 or a bundled-dependency Dependabot PR using the documented npm build and pack commands. Done means the repack-dist flow, Dependabot secret configuration, and a green bundled-dependency PR without a manual pack push.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Finding
.github/workflows/test.yml guards dist/index.js against drift ("Verify committed dist/ matches source"). That gate is correct, but it makes every dependabot PR that bumps an ncc-bundled dependency permanently red, because dependabot never runs npm run pack.
Evidence: #167 (js-yaml 5.4.1 → 5.4.2) fails only on that step — job 105929435459 — while main is green on Build and test code for its last 5 runs (latest 35910387179 @ 187c5e3). Reproduced on fresh origin/main 187c5e3 with the same bumps: npm ci && npm run build && npm run pack → dist/index.js | 3 ++-. Rebasing does not help.
Two contributing factors:
js-yamlis declared indevDependenciesbut is a runtime import (src/utils/owners.ts:6,src/utils/config.ts:5) and is bundled intodist/. Because.github/dependabot.ymlgroups bydependency-type, its bumps land in thedev-dependenciesgroup alongside genuinely test-only tooling, so a maintainer has no signal that a repack is needed.- Nothing in CI repacks
dist/for dependabot heads. Theproduction-dependenciesgroup (@actions/core,@actions/github, …) has the same problem: every one of those PRs will also need a manualnpm run packpush.
Recommendation
Add a job to .github/workflows/test.yml that, on pull_request events from dependabot[bot] on a same-repo head, rebuilds dist/ and pushes the result back to the PR branch when it differs. Exact replacement — append to the jobs: map in .github/workflows/test.yml:
repack-dist:
# Dependabot cannot run `npm run pack`; commit the rebuilt bundle to its
# branch so build-test can pass on the next run.
if: >-
github.event_name == 'pull_request' &&
github.actor == 'dependabot[bot]' &&
github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.ref }}
token: ${{ secrets.DEPENDABOT_REPACK_TOKEN }}
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: package.json
cache: npm
- run: npm ci
- run: npm run build
- run: npm run pack
- name: Commit rebuilt dist/ if it changed
run: |
if [ -z "$(git status --porcelain dist/)" ]; then
echo "dist/ is up to date"; exit 0
fi
git config user.name 'github-actions[bot]'
git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
git add dist/
git commit -s -m 'chore: repack dist/ for dependency bump'
git push
Notes for the maintainer applying this:
secrets.DEPENDABOT_REPACK_TOKENmust be a fine-grained PAT (or GitHub App token) withcontents: write, and it must be added under Settings → Secrets → Dependabot as well as Actions: dependabot-triggeredpull_requestruns only see Dependabot secrets, and the defaultGITHUB_TOKENon those runs is read-only. Pushing with a non-default token is also what makes the pushed commit re-triggerbuild-test.- Alternatively drop the
token:input and instead re-run this job viaworkflow_dispatch//retestafter a maintainer approval; the push then usesGITHUB_TOKEN, but only if the default token permission is raised to write. - Independent of the workflow: move
js-yamlfromdevDependenciestodependenciesinpackage.jsonso it groups with the other bundled runtime deps in dependabot'sproduction-dependenciesgroup. That is a one-linepackage.jsonchange; it does not fix the red check by itself, only the mislabelling.
Why no PR: the fix is in .github/workflows/. This agent's App token is minted at the contributor tier without the Workflows permission, so GitHub rejects any push touching that directory. The change needs a human (or an ISSUES_PRS_MERGE-tier agent) to land. No part of the fix lies outside .github/workflows/ other than the optional package.json move noted above, which is a production-manifest change and out of the quality lane.
Completion criteria
-
repack-distjob (or equivalent) added to.github/workflows/test.yml -
DEPENDABOT_REPACK_TOKEN(or chosen alternative) configured as a Dependabot secret - #167 (or the next bundled-dep dependabot PR) turns green without a manual
npm run packpush
Priority
- Impact: medium — every bundled-dep dependabot PR is red until a maintainer hand-repacks; dependency updates silently stall.
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 187c5e3
— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- Lenguaje dominante
- TypeScript
- Estrellas
- 132
- Forks
- 23
- Merge medio
- 1 d 9 h
- PR fusionados (30 d)
- 122
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cncf/prow-github-actions
-
[quality] test.yml never runs on main after a tide merge — github.token merges don't trigger push; add workflow_dispatch + schedulePosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertoagent/quality hive/hosted-available-lke648397-260827-5q9t kind/failing-test quality testing
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
cncf/prow-github-actions#329 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[quality] bundle e2e never drives plain /close or the /milestone refusals through dist/index.jsPosiblemente ocupada @hivecommons-hive la tomó hace 4 días. Abiertoagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
cncf/prow-github-actions#295 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[quality] the cron dispatcher's jobs-input error arms and the push event route are never driven through dist/index.jsPosiblemente ocupada @hivecommons-hive la tomó hace 1 día. Abiertoagent/quality hive/hosted-available-lke648397-260827-5q9t hive/verified-open needs-kind quality testing
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
cncf/prow-github-actions#241 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
[quality] test.yml runs build-test twice per commit on every PR branch — narrow push to main and add a concurrency groupPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertoagent/quality hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
cncf/prow-github-actions#213 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup needs-decision quality testing
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
cncf/prow-github-actions#209 · 6 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de cncf/prow-github-actions
Issues similares
-
bug priority:low ready-for-dev
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Automattic/data-liberation-agent#685 ·
Los mantenedores suelen responder en 1 día
-
Business
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 83/100
txn2/mcp-data-platform#2063 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 77/100
Crosstalk-Solutions/project-nomad#1427 ·
Los mantenedores suelen responder en 2 días