[quality] dependabot PRs bumping ncc-bundled deps always fail the dist/ gate — add a repack-dist job to test.yml
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- github-actions, node.js
- Ambito
- build-system, ci-cd
Direzione di ricerca
Start by reading .github/workflows/test.yml, then check .github/dependabot.yml and the existing build-test job to understand dependency groups and dist/ validation. Verify the behavior against #167 or a bundled-dependency Dependabot PR using the documented npm build and pack commands. Done means the repack-dist flow, Dependabot secret configuration, and a green bundled-dependency PR without a manual pack push.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Finding
.github/workflows/test.yml guards dist/index.js against drift ("Verify committed dist/ matches source"). That gate is correct, but it makes every dependabot PR that bumps an ncc-bundled dependency permanently red, because dependabot never runs npm run pack.
Evidence: #167 (js-yaml 5.4.1 → 5.4.2) fails only on that step — job 105929435459 — while main is green on Build and test code for its last 5 runs (latest 35910387179 @ 187c5e3). Reproduced on fresh origin/main 187c5e3 with the same bumps: npm ci && npm run build && npm run pack → dist/index.js | 3 ++-. Rebasing does not help.
Two contributing factors:
js-yamlis declared indevDependenciesbut is a runtime import (src/utils/owners.ts:6,src/utils/config.ts:5) and is bundled intodist/. Because.github/dependabot.ymlgroups bydependency-type, its bumps land in thedev-dependenciesgroup alongside genuinely test-only tooling, so a maintainer has no signal that a repack is needed.- Nothing in CI repacks
dist/for dependabot heads. Theproduction-dependenciesgroup (@actions/core,@actions/github, …) has the same problem: every one of those PRs will also need a manualnpm run packpush.
Recommendation
Add a job to .github/workflows/test.yml that, on pull_request events from dependabot[bot] on a same-repo head, rebuilds dist/ and pushes the result back to the PR branch when it differs. Exact replacement — append to the jobs: map in .github/workflows/test.yml:
repack-dist:
# Dependabot cannot run `npm run pack`; commit the rebuilt bundle to its
# branch so build-test can pass on the next run.
if: >-
github.event_name == 'pull_request' &&
github.actor == 'dependabot[bot]' &&
github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.ref }}
token: ${{ secrets.DEPENDABOT_REPACK_TOKEN }}
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: package.json
cache: npm
- run: npm ci
- run: npm run build
- run: npm run pack
- name: Commit rebuilt dist/ if it changed
run: |
if [ -z "$(git status --porcelain dist/)" ]; then
echo "dist/ is up to date"; exit 0
fi
git config user.name 'github-actions[bot]'
git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
git add dist/
git commit -s -m 'chore: repack dist/ for dependency bump'
git push
Notes for the maintainer applying this:
secrets.DEPENDABOT_REPACK_TOKENmust be a fine-grained PAT (or GitHub App token) withcontents: write, and it must be added under Settings → Secrets → Dependabot as well as Actions: dependabot-triggeredpull_requestruns only see Dependabot secrets, and the defaultGITHUB_TOKENon those runs is read-only. Pushing with a non-default token is also what makes the pushed commit re-triggerbuild-test.- Alternatively drop the
token:input and instead re-run this job viaworkflow_dispatch//retestafter a maintainer approval; the push then usesGITHUB_TOKEN, but only if the default token permission is raised to write. - Independent of the workflow: move
js-yamlfromdevDependenciestodependenciesinpackage.jsonso it groups with the other bundled runtime deps in dependabot'sproduction-dependenciesgroup. That is a one-linepackage.jsonchange; it does not fix the red check by itself, only the mislabelling.
Why no PR: the fix is in .github/workflows/. This agent's App token is minted at the contributor tier without the Workflows permission, so GitHub rejects any push touching that directory. The change needs a human (or an ISSUES_PRS_MERGE-tier agent) to land. No part of the fix lies outside .github/workflows/ other than the optional package.json move noted above, which is a production-manifest change and out of the quality lane.
Completion criteria
-
repack-distjob (or equivalent) added to.github/workflows/test.yml -
DEPENDABOT_REPACK_TOKEN(or chosen alternative) configured as a Dependabot secret - #167 (or the next bundled-dep dependabot PR) turns green without a manual
npm run packpush
Priority
- Impact: medium — every bundled-dep dependabot PR is red until a maintainer hand-repacks; dependency updates silently stall.
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 187c5e3
— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- Lingua principale
- TypeScript
- Stelle
- 132
- Fork
- 23
- Merge medio
- 1g 2h
- PR unite (30g)
- 98
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di cncf/prow-github-actions
-
agent/quality hive/hosted-available-lke648397-260827-5q9t kind/failing-test quality testing
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
cncf/prow-github-actions#329 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[quality] bundle e2e never drives plain /close or the /milestone refusals through dist/index.jsForse già presa @hivecommons-hive l’ha presa 3 giorni fa. Apertaagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
cncf/prow-github-actions#295 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[quality] the cron dispatcher's jobs-input error arms and the push event route are never driven through dist/index.jsForse già presa @hivecommons-hive l’ha presa oggi. Apertaagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t needs-kind quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
cncf/prow-github-actions#241 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent/quality hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
cncf/prow-github-actions#213 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup needs-decision quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
cncf/prow-github-actions#209 · 5 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di cncf/prow-github-actions
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
kind/chore priority/must
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
sidereal-io/sidereal#380 ·
I maintainer di solito rispondono entro 1 giorno
-
Mend: dependency security vulnerability
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
opfab/operatorfabric-core#10653 ·
I maintainer di solito rispondono entro 1 giorno
-
backend bug size:sm
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
chrisbenincasa/tunarr#2237 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 2/5 Mezza giornata Idoneità per principianti 69/100
Lam30ne/regulate-app#39 ·