Bumps the actions group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `7.0.1` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `7.0.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0` | `7.0.0` | | [actions/cache/restore](https://github.com/actions/cache) | `5.0.5` | `6.1.0` | | [actions/cache/save](https://github.com/actions/cache) | `5.0.5` | `6.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.1` | `7.0.1` | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.19.1` | `2.20.0` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.1` | `2.4.3` | | [github/codeql-action](https://github.com/github/codeql-action) | `3` | `4` | | [tauri-apps/tauri-action](https://github.com/tauri-apps/tauri-action) | `0.6.2` | `1.0.0` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.95.3` | `3.95.9` | | [actions/stale](https://github.com/actions/stale) | `10.2.0` | `10.4.0` | Updates `actions/checkout` from 4.2.2 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4.2.2...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `actions/setup-python` from 6.2.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/v6.2.0...5fda3b95a4ea91299a34e894583c3862153e4b97) Updates `actions/setup-node` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](48b55a011b...8207627860) Updates `actions/cache/restore` from 5.0.5 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](27d5ce7f10...55cc834586) Updates `actions/cache/save` from 5.0.5 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](27d5ce7f10...55cc834586) Updates `actions/upload-artifact` from 4.6.1 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/v4.6.1...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a) Updates `step-security/harden-runner` from 2.19.1 to 2.20.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](a5ad31d6a1...bf7454d06d) Updates `ossf/scorecard-action` from 2.4.1 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](f49aabe0b5...4eaacf0543) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v3...v4) Updates `tauri-apps/tauri-action` from 0.6.2 to 1.0.0 - [Release notes](https://github.com/tauri-apps/tauri-action/releases) - [Changelog](https://github.com/tauri-apps/tauri-action/blob/dev/CHANGELOG.md) - [Commits](84b9d35b5f...1deb371b0c) Updates `trufflesecurity/trufflehog` from 3.95.3 to 3.95.9 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](37b77001d0...27b0417c16) Updates `actions/stale` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](b5d41d4e1d...1e223db275) --- updated-dependencies: - dependency-name: actions/cache/restore dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/cache/save dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-python dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/stale dependency-version: 10.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: github/codeql-action dependency-version: 4.37.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: step-security/harden-runner dependency-version: 2.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: tauri-apps/tauri-action dependency-version: 1.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.95.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
178 lines
7.6 KiB
YAML
178 lines
7.6 KiB
YAML
# SPDX-License-Identifier: AGPL-3.0-only
|
|
# Copyright 2026-present the Unsloth AI Inc. team. All rights reserved.
|
|
|
|
# Frontend PR gate: lockfile freshness, typecheck, build, and a bundle grep
|
|
# that catches the 2026.5.1 chat-history regression at the JS level.
|
|
#
|
|
# biome runs as non-blocking for now: the codebase currently has accumulated
|
|
# ~470 errors and ~1650 warnings against the existing biome config. Surfacing
|
|
# the count in CI lets us drive it down without forcing a fleet-wide cleanup
|
|
# in the same PR. Drop `continue-on-error` once that number is zero.
|
|
|
|
name: Frontend CI
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- 'studio/frontend/**'
|
|
- 'scripts/check_frontend_dep_removal.py'
|
|
- 'tests/studio/test_frontend_dep_removal.py'
|
|
- 'scripts/sync_allow_scripts_pins.py'
|
|
- 'tests/studio/test_sync_allow_scripts_pins.py'
|
|
- '.github/workflows/studio-frontend-ci.yml'
|
|
push:
|
|
branches: [main, pip]
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build:
|
|
name: Frontend build + bundle sanity
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
defaults:
|
|
run:
|
|
working-directory: studio/frontend
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
# FIXME: drop this step once @assistant-ui/* and assistant-stream
|
|
# leave 0.x -- on 1.x, caret ranges are conventional. Until then,
|
|
# every 0.minor on this surface is a SemVer-major (this is exactly
|
|
# how 2026.5.1 shipped a broken chat runtime: ^0.12.19 quietly
|
|
# resolved to 0.12.28).
|
|
- name: '@assistant-ui must be pinned exactly (no caret/tilde)'
|
|
working-directory: ${{ github.workspace }}
|
|
run: |
|
|
set -e
|
|
if grep -nE '"(@assistant-ui/[a-z-]+|assistant-stream)":[[:space:]]*"[\^~]' studio/frontend/package.json; then
|
|
echo "::error file=studio/frontend/package.json::These packages must be pinned to exact versions until they leave 0.x. Drop the leading ^ or ~."
|
|
exit 1
|
|
fi
|
|
echo "All assistant-ui packages are pinned exactly."
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: '22'
|
|
|
|
# node 22 bundles npm 10.x, which predates allowScripts. Move to the
|
|
# 11.x line and fail loudly if the gate is still missing, so the
|
|
# strict flag below can never silently degrade into a warning.
|
|
- name: Upgrade npm to 11.x (allowScripts enforcement)
|
|
working-directory: ${{ github.workspace }}
|
|
run: |
|
|
npm install -g npm@^11 --no-fund --no-audit
|
|
V=$(npm -v)
|
|
case "$V" in
|
|
11.1[6-9].*|11.[2-9][0-9].*|1[2-9].*) echo "npm $V has allowScripts" ;;
|
|
*) echo "::error::npm $V lacks allowScripts (need >=11.16)"; exit 1 ;;
|
|
esac
|
|
|
|
# Run the structural lockfile scan BEFORE npm ci. A compromised
|
|
# tarball runs its `prepare` / `postinstall` during `npm ci`,
|
|
# so any catch has to fire upstream of that. The scanner is
|
|
# pure-Python read-only; safe to call ahead of every install.
|
|
- name: Lockfile supply-chain audit (pre-install scan)
|
|
working-directory: ${{ github.workspace }}
|
|
run: python3 scripts/lockfile_supply_chain_audit.py
|
|
|
|
# Dependency bumps strand the version-pinned allowScripts entries.
|
|
# The paired pre-commit hook auto-fixes PRs; this is the backstop.
|
|
- name: allowScripts pins must match the lockfile
|
|
working-directory: ${{ github.workspace }}
|
|
run: |
|
|
python3 tests/studio/test_sync_allow_scripts_pins.py
|
|
python3 scripts/sync_allow_scripts_pins.py --check
|
|
|
|
- name: Lockfile must agree with package.json (npm ci is strict)
|
|
# The vite 8 chain (rolldown, lightningcss, tailwind oxide) ships napi
|
|
# binaries with no install scripts. The only script-bearing deps are
|
|
# covered by `allowScripts` in package.json (npm >=11.16, default in
|
|
# npm 12). The pre-install lockfile audit above stays the first line
|
|
# of defence -- it fires before any tarball can run code.
|
|
# --strict-allow-scripts: any unreviewed install script hard-fails
|
|
# the job; the sync hook keeps the pins fresh after bumps.
|
|
run: npm ci --strict-allow-scripts --no-fund --no-audit
|
|
|
|
- name: npm ci must not have modified the working tree
|
|
working-directory: ${{ github.workspace }}
|
|
run: |
|
|
if ! git diff --quiet -- studio/frontend; then
|
|
echo "::error::npm ci modified files; commit the updated lockfile"
|
|
git status -- studio/frontend
|
|
exit 1
|
|
fi
|
|
|
|
# Catch the common foot-gun: a dep dropped from package.json that is
|
|
# still imported somewhere. The script walks the lockfile dep graph
|
|
# from the new top-level deps and only counts top-level node_modules
|
|
# paths as valid resolution targets for bare src/ imports.
|
|
#
|
|
# actions/checkout uses fetch-depth: 1 by default, so the base branch
|
|
# is not available locally. Fetch the single base commit with an
|
|
# explicit refspec so origin/<base> is reliably created (a bare
|
|
# `git fetch origin <ref>` only updates FETCH_HEAD in some configs).
|
|
- name: Dependency removal safety check
|
|
if: github.event_name == 'pull_request'
|
|
working-directory: ${{ github.workspace }}
|
|
run: |
|
|
git fetch --no-tags --depth=1 origin \
|
|
"${{ github.base_ref }}:refs/remotes/origin/${{ github.base_ref }}"
|
|
python3 scripts/check_frontend_dep_removal.py \
|
|
--base "origin/${{ github.base_ref }}" \
|
|
--enumerate-dead
|
|
python3 tests/studio/test_frontend_dep_removal.py
|
|
|
|
- name: Typecheck
|
|
run: npm run typecheck
|
|
|
|
- name: Unit tests
|
|
run: npm test
|
|
|
|
- name: Build
|
|
run: npm run build
|
|
|
|
- name: Built bundle must not contain Unsloth's unstable_Provider call site
|
|
run: |
|
|
set -e
|
|
JS=$(ls dist/assets/index-*.js | head -1)
|
|
HITS=$(grep -c 'unstable_Provider:' "$JS" || echo 0)
|
|
echo "main bundle: $JS"
|
|
echo "unstable_Provider: hits=$HITS (assistant-ui internals contribute up to 3)"
|
|
if [ "$HITS" -gt 3 ]; then
|
|
echo "::error file=studio/frontend/src/features/chat/runtime-provider.tsx::Unsloth bundle still passes unstable_Provider through useRemoteThreadListRuntime; this is the 2026.5.1 chat-history regression. Pass adapters directly into useLocalRuntime instead."
|
|
exit 1
|
|
fi
|
|
|
|
- name: Bundle size budget (75 MB)
|
|
run: |
|
|
SIZE=$(du -sb dist | cut -f1)
|
|
BUDGET=$((75 * 1024 * 1024))
|
|
echo "dist size: $SIZE bytes ($((SIZE/1024/1024)) MB), budget: $BUDGET bytes (75 MB)"
|
|
if [ "$SIZE" -gt "$BUDGET" ]; then
|
|
echo "::error::studio/frontend/dist/ exceeded the 75 MB budget. Drop dead deps (e.g. the unused next dep) or split chunks."
|
|
exit 1
|
|
fi
|
|
|
|
- name: Biome (non-blocking until accumulated drift is cleared)
|
|
continue-on-error: true
|
|
run: npm run biome:check
|
|
|
|
- name: Upload built dist
|
|
# Always upload so a green run is reviewable too -- the dist
|
|
# output catches "tests passed but bundle changed unexpectedly"
|
|
# regressions that would be invisible if we only kept artifacts
|
|
# on failure.
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: studio-frontend-dist
|
|
path: studio/frontend/dist
|
|
retention-days: 3
|