Skip to content

ci: check that the committed bundle is up to date on release PRs - #85

Merged
satsukies merged 3 commits into
mainfrom
ci/release-bundle-freshness
Oct 7, 2026
Merged

satsukies merged 3 commits into
mainfrom
ci/release-bundle-freshness

Conversation

@satsukies

@satsukies satsukies commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

Add a CI step that fails a release PR when its committed plugin/scripts/bundle.js doesn't match a fresh build.

Plugin users run the committed bundle, which is only regenerated when release-please creates or updates the release PR. release-please doesn't refresh the PR for non-release commits such as Dependabot Bump ... or ci:, so the committed bundle can go stale and differ from what npm publishes.

  • .github/workflows/ci.yml, bundle-compat job: right after npm run bundle (still on Node 24), a new step runs git diff --exit-code --stat plugin/scripts/bundle.js.
    • On a mismatch, it fails and prints the manual recovery steps in the log, plus an ::error annotation pointing to them:

      git fetch origin
      git switch -C <release-branch> origin/<release-branch>
      git merge origin/main
      npm ci
      npm run bundle
      git add plugin/scripts/bundle.js
      git commit --no-verify -m "chore: regenerate bundle.js for release"
      git push origin <release-branch>
      

      --no-verify is needed because the pre-commit hook blocks bundle commits outside the release workflow.

    • Recovery is manual on purpose. "Update branch" alone does not help, because release.yml regenerates the bundle only when release-please updates the PR on a push to main. An automated regeneration workflow on release-branch pushes was considered and deliberately left out for now, to avoid adding another workflow that pushes with the release App's write access. This only happens when non-release commits land on main between the release PR update and its merge, so it should be rare.

    • It runs only for release PRs (github.head_ref starts with release-please--). On other PRs and on main, the committed bundle is expected to lag behind between releases.

Notes:

  • PR CI runs on the merge ref (head + current main), so the check also catches commits that landed on main after the bundle was regenerated, as long as CI re-runs.
  • When release-please first opens or updates a release PR, CI can briefly fail on the commit before chore: regenerate bundle.js for release. The regeneration commit re-runs CI, and only that latest run matters.

Related Issue

Closes #81

Type of change

  • Bug fix
  • New feature
  • Documentation
  • Refactor / internal change
  • Build / CI / tooling

Test plan

  • npm run build passes
  • npm test passes (235 tests)
  • Manually verified the change (describe how below)

I ran the step's commands locally on Node 24:

  • Pass: at tag deploygate--v1.5.2, npm ci && npm run bundle followed by git diff --exit-code --stat plugin/scripts/bundle.js reports no diff.
  • Fail: on current main (c7c6ea5), which has newer dependencies than the committed 1.5.2 bundle, the same commands report a diff and exit non-zero.
  • Recovery steps: in a throwaway clone, I made a stale "release branch" from deploygate--v1.5.2 and simulated the PR merge ref with current main. The check failed and printed the steps. Following them (everything except the push) produced a regeneration commit. Without --no-verify, the pre-commit hook blocked it as expected. After the commit, the check passed with exit 0.

This PR's own CI skips the new step, because the branch isn't a release PR. It will first run on the next release-please PR.

Checklist

  • I have updated the plugin version in plugin/.codex-plugin/plugin.json and plugin/.claude-plugin/plugin.json if applicable (not applicable: CI only)
  • I have read and agree to the Code of Conduct

🤖 Generated with Claude Code


Devin Review

Copilot AI balanced review requested due to automatic review settings October 7, 2026 05:42

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread .github/workflows/ci.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The failure annotation recommends a branch update that does not trigger bundle regeneration.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds a release-PR bundle freshness check to prevent plugin users receiving a stale committed bundle, addressing #81.

Changes:

  • Compares the committed bundle with a fresh build.
  • Fails release PRs on differences; skips other PRs and pushes.
File Description
.github/​workflows/​ci.yml Adds the release-only freshness check and failure annotation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci.yml Outdated
Copilot AI balanced review requested due to automatic review settings October 7, 2026 06:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The check is correctly scoped, provides actionable recovery steps, and has no identified blocking issues.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@satsukies satsukies self-assigned this Oct 7, 2026
@satsukies
satsukies requested review from enomoto-kazuya and a balanced review from Copilot October 7, 2026 07:51

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The narrowly scoped check matches the release process and requirements, with no blocking issues identified.

Review effort: Balanced
Findings: None

@enomoto-kazuya enomoto-kazuya left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@satsukies

Copy link
Copy Markdown
Member Author

thank you

@satsukies
satsukies merged commit a5d8ce1 into main Oct 7, 2026
5 checks passed
@satsukies
satsukies deleted the ci/release-bundle-freshness branch October 7, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Check that the committed bundle is up to date on release PRs

3 participants