Skip to content

ci: deploy documentation with reusable workflow - #450

Merged
zombieJ merged 1 commit into
masterfrom
agent/deploy-pages
Jul 27, 2026
Merged

ci: deploy documentation with reusable workflow#450
zombieJ merged 1 commit into
masterfrom
agent/deploy-pages

Conversation

@zombieJ

@zombieJ zombieJ commented Jul 27, 2026

Copy link
Copy Markdown
Member

Summary

  • replace the legacy gh-pages deployment action
  • deploy documentation on published releases and manual dispatches
  • reuse the shared react-component Pages workflow

Verification

  • ut --registry https://registry.npmjs.org/
  • GH_PAGES=1 ut run build

Summary by CodeRabbit

  • 新功能

    • 新增文档自动部署至 GitHub Pages 的工作流,支持发布完成后自动部署及手动触发。
  • 变更

    • 移除旧版网站部署流程,统一采用新的文档部署方式。

@zombieJ zombieJ self-assigned this Jul 27, 2026
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@vercel

vercel Bot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
collapse Ready Ready Preview, Comment Jul 27, 2026 8:31am

@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

新增 GitHub Pages 文档部署工作流,支持发布和手动触发,使用最小权限并复用外部部署逻辑;同时移除旧的网站部署工作流。

Changes

GitHub Pages 部署

Layer / File(s) Summary
Pages 部署工作流配置
.github/workflows/deploy-pages.yml, .github/workflows/site-deploy.yml
新增文档 Pages 部署工作流,配置发布与手动触发、最小权限及外部工作流复用;移除原有网站构建与部署流程。

Estimated code review effort: 1 (Trivial) | ~5 minutes

Poem

小兔蹦跳看新章,
Pages 工作流启航。
发布一到即部署,
手动触发也闪亮。
旧流程轻轻退场。

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 标题准确概括了使用可复用工作流部署文档这一主要变更。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/deploy-pages

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

React Doctor could not complete this scan.

react-doctor exited with status 0 before producing a JSON report.

Report this bug

Reviewed by React Doctor for commit 00307aa.

@codecov

codecov Bot commented Jul 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.19%. Comparing base (86cf8af) to head (00307aa).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #450   +/-   ##
=======================================
  Coverage   99.19%   99.19%           
=======================================
  Files           5        5           
  Lines         124      124           
  Branches       45       45           
=======================================
  Hits          123      123           
  Misses          1        1           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

❌ Deploy failed

PR preview ❌ Failed ❌ Failed
🔗 Preview https://react-component-collapse-preview-pr-450.surge.sh (may be unavailable)
📝 Commit00307aa
🪵 LogsView logs
📋 Build log (last lines)
npm error
npm error Could not resolve dependency:
npm error peer eslint@"^3 || ^4 || ^5 || ^6 || ^7 || ^8 || ^9.7" from eslint-plugin-react@7.37.5
npm error node_modules/eslint-plugin-react
npm error   dev eslint-plugin-react@"^7.37.5" from the root project
npm error   eslint-plugin-react@"^7.32.2" from @umijs/fabric@4.0.1
npm error   node_modules/@umijs/fabric
npm error     @umijs/fabric@"^4.0.0" from rc-test@7.1.3
npm error     node_modules/rc-test
npm error       dev rc-test@"^7.1.3" from the root project
npm error
npm error Conflicting peer dependency: eslint@9.39.5
npm error node_modules/eslint
npm error   peer eslint@"^3 || ^4 || ^5 || ^6 || ^7 || ^8 || ^9.7" from eslint-plugin-react@7.37.5
npm error   node_modules/eslint-plugin-react
npm error     dev eslint-plugin-react@"^7.37.5" from the root project
npm error     eslint-plugin-react@"^7.32.2" from @umijs/fabric@4.0.1
npm error     node_modules/@umijs/fabric
npm error       @umijs/fabric@"^4.0.0" from rc-test@7.1.3
npm error       node_modules/rc-test
npm error         dev rc-test@"^7.1.3" from the root project
npm error
npm error Fix the upstream dependency conflict, or retry
npm error this command with --force or --legacy-peer-deps
npm error to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /home/runner/.npm/_logs/2026-07-27T08_32_26_259Z-eresolve-report.txt
npm error A complete log of this run can be found in: /home/runner/.npm/_logs/2026-07-27T08_32_26_259Z-debug-0.log

🤖 Powered by surge-preview

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/deploy-pages.yml:
- Line 15: 将 deploy-pages.yml 中复用工作流的 `@main` 引用替换为已审查的完整 commit SHA,确保 pages:
write 和 id-token: write 权限对应的工作流内容不会随分支更新而变化;同时记录该依赖的来源并建立后续定期审查和更新 SHA 的机制。
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f6bdbfb4-e44c-4a93-bc2c-b7736f477be7

📥 Commits

Reviewing files that changed from the base of the PR and between 86cf8af and 00307aa.

📒 Files selected for processing (2)
  • .github/workflows/deploy-pages.yml
  • .github/workflows/site-deploy.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/site-deploy.yml


jobs:
deploy:
uses: react-component/rc-test/.github/workflows/deploy-pages.yml@main

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== workflow files =="
git ls-files '.github/workflows/*' || true

echo
echo "== deploy-pages.yml =="
if [ -f .github/workflows/deploy-pages.yml ]; then
  cat -n .github/workflows/deploy-pages.yml
fi

echo
echo "== reusable workflow references =="
rg -n "uses:\s*[^\\n]*\\.github/workflows/.+\\.ya?ml|@["'\'']|permissions:" .github/workflows || true

Repository: react-component/collapse

Length of output: 798


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== repo metadata =="
git rev-parse HEAD
git rev-parse --show-toplevel
git status --short
git branch --show-current

echo
echo "== workflow references with permissions =="
python3 - <<'PY'
from pathlib import Path
for p in sorted(Path('.github/workflows').glob('*.yml')):
    if p.name == 'deploy-pages.yml':
        print(f"\n--- {p} ---")
        print(p.read_text())
PY

echo
echo "== remote tag pins in other workflows =="
rg -n "uses: .*@|permissions:|react-component/rc-test" .github/workflows || true

Repository: react-component/collapse

Length of output: 1424


将复用工作流固定到已审查的提交 SHA。

.github/workflows/deploy-pages.yml@main 引用 react-component/rc-test/.github/workflows/deploy-pages.yml,且该工作流拥有 pages: writeid-token: write。分支更新会未经审核就改变部署行为,增加跨仓库供应链风险;改用固定的 commit SHA 并建立后续更新机制。

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/deploy-pages.yml at line 15, 将 deploy-pages.yml 中复用工作流的
`@main` 引用替换为已审查的完整 commit SHA,确保 pages: write 和 id-token: write
权限对应的工作流内容不会随分支更新而变化;同时记录该依赖的来源并建立后续定期审查和更新 SHA 的机制。

Source: Learnings

@zombieJ
zombieJ merged commit f0e5416 into master Jul 27, 2026
10 of 12 checks passed
@zombieJ
zombieJ deleted the agent/deploy-pages branch July 27, 2026 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant