Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[quality] dependabot PRs bumping ncc-bundled deps always fail the dist/ gate — add a repack-dist job to test.yml

Aperta
#171 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
68/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
github-actions, node.js

Direzione di ricerca

Start by reading .github/workflows/test.yml, then check .github/dependabot.yml and the existing build-test job to understand dependency groups and dist/ validation. Verify the behavior against #167 or a bundled-dependency Dependabot PR using the documented npm build and pack commands. Done means the repack-dist flow, Dependabot secret configuration, and a green bundled-dependency PR without a manual pack push.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

kind/failing-test

Finding

.github/workflows/test.yml guards dist/index.js against drift ("Verify committed dist/ matches source"). That gate is correct, but it makes every dependabot PR that bumps an ncc-bundled dependency permanently red, because dependabot never runs npm run pack.

Evidence: #167 (js-yaml 5.4.1 → 5.4.2) fails only on that step — job 105929435459 — while main is green on Build and test code for its last 5 runs (latest 35910387179 @ 187c5e3). Reproduced on fresh origin/main 187c5e3 with the same bumps: npm ci && npm run build && npm run pack → dist/index.js | 3 ++-. Rebasing does not help.

Two contributing factors:

  1. js-yaml is declared in devDependencies but is a runtime import (src/utils/owners.ts:6, src/utils/config.ts:5) and is bundled into dist/. Because .github/dependabot.yml groups by dependency-type, its bumps land in the dev-dependencies group alongside genuinely test-only tooling, so a maintainer has no signal that a repack is needed.
  2. Nothing in CI repacks dist/ for dependabot heads. The production-dependencies group (@actions/core, @actions/github, …) has the same problem: every one of those PRs will also need a manual npm run pack push.

Recommendation

Add a job to .github/workflows/test.yml that, on pull_request events from dependabot[bot] on a same-repo head, rebuilds dist/ and pushes the result back to the PR branch when it differs. Exact replacement — append to the jobs: map in .github/workflows/test.yml:

  repack-dist:
    # Dependabot cannot run `npm run pack`; commit the rebuilt bundle to its
    # branch so build-test can pass on the next run.
    if: >-
      github.event_name == 'pull_request' &&
      github.actor == 'dependabot[bot]' &&
      github.event.pull_request.head.repo.full_name == github.repository
    runs-on: ubuntu-latest
    permissions:
      contents: write
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          ref: ${{ github.event.pull_request.head.ref }}
          token: ${{ secrets.DEPENDABOT_REPACK_TOKEN }}
      - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
        with:
          node-version-file: package.json
          cache: npm
      - run: npm ci
      - run: npm run build
      - run: npm run pack
      - name: Commit rebuilt dist/ if it changed
        run: |
          if [ -z "$(git status --porcelain dist/)" ]; then
            echo "dist/ is up to date"; exit 0
          fi
          git config user.name  'github-actions[bot]'
          git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
          git add dist/
          git commit -s -m 'chore: repack dist/ for dependency bump'
          git push

Notes for the maintainer applying this:

  • secrets.DEPENDABOT_REPACK_TOKEN must be a fine-grained PAT (or GitHub App token) with contents: write, and it must be added under Settings → Secrets → Dependabot as well as Actions: dependabot-triggered pull_request runs only see Dependabot secrets, and the default GITHUB_TOKEN on those runs is read-only. Pushing with a non-default token is also what makes the pushed commit re-trigger build-test.
  • Alternatively drop the token: input and instead re-run this job via workflow_dispatch//retest after a maintainer approval; the push then uses GITHUB_TOKEN, but only if the default token permission is raised to write.
  • Independent of the workflow: move js-yaml from devDependencies to dependencies in package.json so it groups with the other bundled runtime deps in dependabot's production-dependencies group. That is a one-line package.json change; it does not fix the red check by itself, only the mislabelling.

Why no PR: the fix is in .github/workflows/. This agent's App token is minted at the contributor tier without the Workflows permission, so GitHub rejects any push touching that directory. The change needs a human (or an ISSUES_PRS_MERGE-tier agent) to land. No part of the fix lies outside .github/workflows/ other than the optional package.json move noted above, which is a production-manifest change and out of the quality lane.

Completion criteria

  • repack-dist job (or equivalent) added to .github/workflows/test.yml
  • DEPENDABOT_REPACK_TOKEN (or chosen alternative) configured as a Dependabot secret
  • #167 (or the next bundled-dep dependabot PR) turns green without a manual npm run pack push

Priority

  • Impact: medium — every bundled-dep dependabot PR is red until a maintainer hand-repacks; dependency updates silently stall.
  • Effort: low

Filed by quality agent (hold-gated mode)

🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 187c5e3

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Lingua principale
TypeScript
Stelle
132
Fork
23
Merge medio
1g 2h
PR unite (30g)
98

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di cncf/prow-github-actions

Tutte le issue di cncf/prow-github-actions

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.