Repository navigation
ci: check that the committed bundle is up to date on release PRs - #85
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The failure annotation recommends a branch update that does not trigger bundle regeneration.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds a release-PR bundle freshness check to prevent plugin users receiving a stale committed bundle, addressing #81.
Changes:
- Compares the committed bundle with a fresh build.
- Fails release PRs on differences; skips other PRs and pushes.
| File | Description |
|---|---|
.github/workflows/ci.yml |
Adds the release-only freshness check and failure annotation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
4 of 10 tasks
satsukies
requested review from
enomoto-kazuya
and
a balanced review from Copilot
October 7, 2026 07:51
Member
Author
|
thank you |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Add a CI step that fails a release PR when its committed
plugin/scripts/bundle.jsdoesn't match a fresh build.Plugin users run the committed bundle, which is only regenerated when release-please creates or updates the release PR. release-please doesn't refresh the PR for non-release commits such as Dependabot
Bump ...orci:, so the committed bundle can go stale and differ from what npm publishes..github/workflows/ci.yml,bundle-compatjob: right afternpm run bundle(still on Node 24), a new step runsgit diff --exit-code --stat plugin/scripts/bundle.js.On a mismatch, it fails and prints the manual recovery steps in the log, plus an
::errorannotation pointing to them:--no-verifyis needed because the pre-commit hook blocks bundle commits outside the release workflow.Recovery is manual on purpose. "Update branch" alone does not help, because
release.ymlregenerates the bundle only when release-please updates the PR on a push tomain. An automated regeneration workflow on release-branch pushes was considered and deliberately left out for now, to avoid adding another workflow that pushes with the release App's write access. This only happens when non-release commits land onmainbetween the release PR update and its merge, so it should be rare.It runs only for release PRs (
github.head_refstarts withrelease-please--). On other PRs and onmain, the committed bundle is expected to lag behind between releases.Notes:
main), so the check also catches commits that landed onmainafter the bundle was regenerated, as long as CI re-runs.chore: regenerate bundle.js for release. The regeneration commit re-runs CI, and only that latest run matters.Related Issue
Closes #81
Type of change
Test plan
npm run buildpassesnpm testpasses (235 tests)I ran the step's commands locally on Node 24:
deploygate--v1.5.2,npm ci && npm run bundlefollowed bygit diff --exit-code --stat plugin/scripts/bundle.jsreports no diff.main(c7c6ea5), which has newer dependencies than the committed 1.5.2 bundle, the same commands report a diff and exit non-zero.deploygate--v1.5.2and simulated the PR merge ref with currentmain. The check failed and printed the steps. Following them (everything except the push) produced a regeneration commit. Without--no-verify, the pre-commit hook blocked it as expected. After the commit, the check passed with exit 0.This PR's own CI skips the new step, because the branch isn't a release PR. It will first run on the next release-please PR.
Checklist
plugin/.codex-plugin/plugin.jsonandplugin/.claude-plugin/plugin.jsonif applicable (not applicable: CI only)🤖 Generated with Claude Code