diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml index 763578ec..0de77baf 100644 --- a/.github/workflows/pr.yml +++ b/.github/workflows/pr.yml @@ -26,6 +26,10 @@ jobs: steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + with: + # The PR merge commit and its first parent (the base), so the + # drift check can see which files the PR changes. + fetch-depth: 2 - name: Set up Node.js uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: @@ -39,8 +43,34 @@ jobs: # ncc 0.44 produces code-split chunks alongside dist/index.js # (e.g. dist/136.index.js); the whole dist/ tree must stay in # sync with src/. + # + # Dependabot PRs that touch only package.json/package-lock.json are + # the exception. A runtime dependency bump changes the bundle, but + # Dependabot cannot rebuild dist/. package.yml rebuilds, attests and + # commits dist/ on main after merge, so for those PRs the rebuild + # above must still succeed but drift is reported as a warning. A + # Dependabot PR that someone has pushed other changes to is checked + # as usual. dist/ is not committed here on the PR's behalf: that + # would need a write token while `npm ci` runs the just-bumped + # package's install scripts. + env: + DEPENDABOT: ${{ github.event.pull_request.user.login == 'dependabot[bot]' }} run: | if ! git diff --quiet -- dist/ || [ -n "$(git status --porcelain -- dist/)" ]; then + other=$(git diff --name-only HEAD^1 HEAD | grep -v -x -E 'package\.json|package-lock\.json' || true) + if [ "$DEPENDABOT" = "true" ] && [ -z "$other" ]; then + echo "::warning::dist/ changes with this dependency bump; package.yml rebuilds and commits it on main after merge." + { + echo "### dist/ will be rebuilt after merge" + echo + echo "This Dependabot bump changes the bundle. \`package.yml\` rebuilds and commits \`dist/\` on \`main\` once it is merged." + echo + echo '```' + git diff --stat -- dist/ + echo '```' + } >> "$GITHUB_STEP_SUMMARY" + exit 0 + fi echo "::error::dist/ is out of sync with src/." echo "::error::Run 'npm run package' locally and commit the rebuilt dist/." git status --porcelain -- dist/ diff --git a/CLAUDE.md b/CLAUDE.md index d36a06cc..d95781f8 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -24,7 +24,7 @@ When reviewing or editing `userData` in `src/aws.js`: npm run package ``` -CI's `verify-dist` job will fail the PR if `dist/` drifts from a clean build. +CI's `verify-dist` job will fail the PR if `dist/` drifts from a clean build. The one exception is a Dependabot PR that changes only `package.json`/`package-lock.json`: drift there is a warning, because Dependabot cannot rebuild `dist/` and `package.yml` rebuilds and commits it on `main` after merge. ## Tests