Skip to content

ci: let verify-dist warn instead of fail on dist drift in Dependabot bumps - #82

Open
kurok wants to merge 1 commit into
mainfrom
ci/verify-dist-dependabot
Open

kurok wants to merge 1 commit into
mainfrom
ci/verify-dist-dependabot

Conversation

@kurok

@kurok kurok commented Oct 2, 2026

Copy link
Copy Markdown

Problem

Dependabot runtime-dependency PRs fail Verify dist is up to date, for example #80 (run), where the undici 6.28.0 → 6.29.0 bump changed dist/index.js by 453+/187−. The bump changes the ncc bundle, but Dependabot only edits package.json and package-lock.json and can't rebuild dist/. So every such PR either needed a manual "rebuild dist" commit (#71) or was merged red (#80).

package.yml already rebuilds, attests and commits dist/ on main after merge. That is what fixed main after #80 (77e809f Update dist). The failing check adds no protection for these PRs, it just has to be overridden.

Change

verify-dist in pr.yml:

PR dist/ drift after a clean rebuild
opened by dependabot[bot], changes only package.json / package-lock.json warning, with the dist/ diff stat in the step summary
anything else, including a Dependabot PR someone pushed src/ or dist/ changes to fails, as before
  • Build must still succeed: npm ci and npm run package still have to pass, so a bump that breaks the ncc build still fails the check.
  • Checkout depth: checkout now fetches depth 2 so the step can diff the merge commit against its base.
  • CLAUDE.md: the "Build artifact" note now mentions the exception.

Not done, on purpose: committing dist/ back to the PR. That would need a write token in a job where npm ci runs install scripts from the package that was just bumped.

Verification

  • actionlint passes.
  • The step's shell logic was run locally against seven cases:
Case Result
Dependabot, manifests only exit 0, warning
Dependabot, lock only exit 0, warning
Dependabot, manifests + src/ exit 1
Dependabot, manifests + dist/ exit 1
human, manifests only exit 1
human, src/ exit 1
no drift exit 0
  • main itself rebuilds with 0 drift after a fresh npm ci on Node 24.

This PR is authored by a human, so its own CI run only exercises the unchanged path. The Dependabot path runs on the next runtime bump.

…bumps

Dependabot runtime-dependency PRs fail "Verify dist is up to date" (e.g.
#80, undici 6.28.0 -> 6.29.0: 453+/187- in dist/index.js). The bump
changes the ncc bundle, but Dependabot only edits package.json and
package-lock.json and cannot rebuild dist/, so every such PR needed a
manual "rebuild dist" commit (#71) or merged red (#80). package.yml
already rebuilds, attests and commits dist/ on main after merge, which
is what fixed main after #80.

For a PR opened by dependabot[bot] that changes only package.json and
package-lock.json, drift is now a warning with a dist/ diff stat in the
step summary. The rebuild itself must still succeed, so a bump that
breaks the ncc build still fails. Any other PR, including a Dependabot
PR someone has pushed src/ or dist/ changes to, fails on drift as
before. Checkout fetches depth 2 so the step can diff the merge commit
against its base.

dist/ is deliberately not committed back on the PR's behalf: that needs
a write token while `npm ci` runs the just-bumped package's install
scripts.

Checked the step's shell logic locally against seven cases
(Dependabot manifests-only, lock-only, with src/, with dist/; human
manifests-only and src/; no drift) and actionlint passes.

Signed-off-by: yuriyryabikov <22548029+kurok@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant