chore(deps): update nix flake inputs #913
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| pull_request: | |
| branches: | |
| - main | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| pages: write | |
| id-token: write | |
| jobs: | |
| gitleaks: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup Nix | |
| uses: ./.github/actions/setup-nix | |
| with: | |
| tools: gitleaks | |
| skip-pnpm-install: 'true' | |
| - name: Run Gitleaks | |
| run: gitleaks detect --source . --config .gitleaks.toml | |
| lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup Nix | |
| uses: ./.github/actions/setup-nix | |
| with: | |
| tools: nodejs_24 pnpm_10 oxlint oxfmt | |
| - name: Run Lint | |
| run: pnpm run lint | |
| build-and-test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup Nix | |
| uses: ./.github/actions/setup-nix | |
| - name: Run Build | |
| run: pnpm run build | |
| - name: Run Tests | |
| run: pnpm test | |
| # The `ai` peer range spans three majors whose tool types differ, so the | |
| # single build-and-test job above only ever proves whichever version the dev | |
| # catalog pins. This job covers the declared range independently of that pin. | |
| # | |
| # Every entry is an exact version, not a range. A range resolves to whatever | |
| # the lockfile already holds unless the lockfile is deleted, and deleting it | |
| # re-resolves every dependency to its newest in-range version, which trips | |
| # this repo's `trustPolicy: no-downgrade` on unrelated packages. Each pin is | |
| # therefore a boundary worth holding still: | |
| # v5 - the lower bound of the declared peer range | |
| # v6 - the last v6 the dev catalog shipped | |
| # v7 - the major boundary where the AI SDK tool types changed shape | |
| # The newest v7 is not covered here; build-and-test covers whatever the dev | |
| # catalog pins, which is the only v7 that moves. | |
| ai-peer-range: | |
| name: ai-peer-range (${{ matrix.ai }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| ai: | |
| - 5.0.108 # lower bound of the peer range | |
| - 6.0.7 # last v6 the dev catalog shipped | |
| - 7.0.0 # first v7, where Tool became a union | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup Nix | |
| uses: ./.github/actions/setup-nix | |
| with: | |
| skip-pnpm-install: 'true' | |
| # `--filter .` keeps the examples workspace out of resolution; it pulls a | |
| # dependency that `blockExoticSubdeps` rejects on any lockfile update. | |
| # | |
| # Assert the resolved version, not just that the edit looked applied. A | |
| # `sed` that stops matching would otherwise leave the catalog untouched | |
| # and the job would pass while silently testing the version it was meant | |
| # to replace. | |
| - name: Install with ai@${{ matrix.ai }} | |
| run: | | |
| sed -i -E "/^ dev:/,/^ [a-z]+:/ s|^ ai: .*| ai: '${{ matrix.ai }}'|" pnpm-workspace.yaml | |
| pnpm install --no-frozen-lockfile --filter . | |
| resolved=$(node -p "require('./node_modules/ai/package.json').version") | |
| echo "resolved ai@$resolved" | |
| if [ "$resolved" != "${{ matrix.ai }}" ]; then | |
| echo "::error::expected ai@${{ matrix.ai }} but resolved ai@$resolved" | |
| exit 1 | |
| fi | |
| # Type errors are the failure mode here, and vitest type-checks the suite | |
| # via the root project's `typecheck` config. | |
| - name: Run Tests | |
| run: pnpm exec vitest run --project root | |
| coverage: | |
| runs-on: ubuntu-latest | |
| if: github.ref == 'refs/heads/main' | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| - name: Setup Nix | |
| uses: ./.github/actions/setup-nix | |
| - name: Run Tests with Coverage | |
| run: pnpm run coverage | |
| - name: Create Coverage Badge | |
| uses: jaywcjlove/coverage-badges-cli@4e8975aa2628e3329126e7eee36724d07ed86fda # v2.2.0 | |
| with: | |
| source: coverage/coverage-summary.json | |
| output: coverage/badges.svg | |
| - name: Upload coverage artifact | |
| uses: actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b # v4.0.0 | |
| with: | |
| path: coverage | |
| deploy-coverage: | |
| needs: coverage | |
| runs-on: ubuntu-latest | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| steps: | |
| - name: Deploy to GitHub Pages | |
| id: deployment | |
| uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5 |