Skip to content

v0.1.15

Choose a tag to compare

@github-actions github-actions released this 06 Sep 15:13
· 15 commits to main since this release

Run cargo with --locked in CI

Without it, cargo rewrites Cargo.lock in place when it has drifted from the
manifests — so CI resolves dependencies fresh and tests a graph nobody
committed, then the release is built from it. The workspace lock had drifted
by 382 lines before the same flag caught it locally.

Every package here commits a Cargo.lock, so --locked is meaningful: it fails
loudly instead of silently updating. Verified against the current lock before
the flag went in.

The Node side is deliberately left alone: these repositories ship no
pnpm-lock.yaml, so --frozen-lockfile has nothing to freeze against, and
resolving from the registry is what a consumer gets anyway.

Regenerate the vendored loader after the canon gained supportedTargets

The list of built targets belongs with the table: a package that names what
it supports in an error must read it from the same place, or the message and
the resolution can disagree.

Take the NAPI platform table from the vendored copy

Every package with a Rust engine repeated the same map from Node's
platform/arch to the suffix napi-rs builds under. Adding a target means adding
it everywhere, and a package that missed the edit fails only on that platform
— the failure nobody reproduces.

The table, the path and the require are vendored from
scripts/vendor/nativeBinary.ts. The policy is not: some packages degrade when
the binary is absent and answer undefined, others refuse loudly with build
instructions, and both are right for their package. The loader reports what
happened and the caller decides.

Measure coverage once, not once per platform

Lint this package the way its own repository will

biome's configuration lived only at the workspace root. This package is
built from its own repository, where that file does not exist and biome
falls back to its defaults — so lint in CI has been checking a different
set of rules from lint here, and the bans this project actually cares
about were never enforced where it counts.

The config is now the package's own, and says the same thing the root one
did.

Declare what CI has to install

Each package is its own repository: pnpm install there sees only this
file, so a dependency the workspace happened to hoist locally is simply
absent in CI. --coverage needs @vitest/coverage-v8 named here, and an
optional peer a test imports has to be a devDependency as well — optional
is exactly what keeps it from being installed.

Run the gates the package already declared

Three guard-rails were configured and never reached CI, so each one was a
gate nothing ran:

  • tsconfig.json includes tests, but CI typechecked only
    tsconfig.build.json — every type a test relied on went unchecked.
  • vitest.config.ts declares coverage thresholds, but CI ran plain
    vitest run, which does not read them.
  • lint pointed at src/ alone, so no test file was ever linted.

CI now runs pnpm typecheck, pnpm test:coverage and a lint that covers
tests/ as well.


Changes since v0.1.14.