thomas.szbay
44ab167200
fix(ci): bound opengrep installer downloads ( #109089 )
...
* fix(ci): bound opengrep installer downloads
* test(ci): tighten opengrep installer guard
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 23:17:45 -07:00
LZY3538
085c1d4602
fix(ci): bound Opengrep installer fetch with connect timeout ( #109576 )
...
Add --connect-timeout 30 and --max-time 120 to the curl command that
downloads the Opengrep install script and pipes it to bash. Both the
PR-diff (opengrep-precise) and full-scan (opengrep-precise-full)
workflows are covered. A stuck TLS handshake or stalled download
could previously occupy a CI runner until the job-level timeout.
Co-authored-by: Claude <noreply@anthropic.com >
2026-07-16 22:25:14 -07:00
Peter Steinberger
e7c389b97a
perf(ci): cache declarations and remove test import tail ( #109593 )
2026-07-16 21:51:06 -07:00
Peter Steinberger
863297cce5
perf(ci): cut cli-startup-metadata and preflight fixed costs ( #109628 )
...
* perf(build): cut write-cli-startup-metadata wall time via launcher-boot browser help and parallel renders
* perf(ci): fetch preflight parent metadata blob-less instead of a full depth-2 snapshot
* test(ci): expect the blob-less preflight parent fetch in checkout guards
* fix(build): default the bundled root-help render env
RootHelpRenderOptions marks env optional but spawnText requires one;
check-test-types caught the undefined assignment.
2026-07-16 21:35:03 -07:00
Peter Steinberger
8d5e39afcd
feat(android): add Wear OS companion ( #109433 )
...
* feat(android): add Wear OS companion
Co-authored-by: Sebastian Schubotz <git@sibbl.net >
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com >
* style(android): format Wear release gate test
* test(android): cover Wear release CI contracts
* test(android): import Wear JSON fixture type
* fix(android): harden Wear proxy event actor
* test(android): stabilize Wear proxy actor tests
* test(android): isolate Wear proxy actor lifecycles
* test(android): own Wear actor dispatchers
* test(android): use real time for Wear actor tests
* test(android): own Wear actors in test scope
* test(android): stop Wear actors explicitly
* test(android): drain Wear actor cancellation
* test(android): isolate Wear actors from test scheduler
* test(android): inject Wear test clock
---------
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com >
2026-07-16 20:59:29 -07:00
Peter Steinberger
067635cb51
fix(ui): prevent generated locale rebase conflicts ( #109393 )
...
* ci(ui): make locale refresh bot-owned
* test(ui): keep locale gate coverage scoped
* fix(ci): preserve generated PR merge policy
* fix(ci): wait for generated PR head convergence
* fix(ci): retry transient guard API failures
* fix(ci): enforce locale isolation across CI events
* fix(ci): harden generated PR publication
* fix(ci): validate release gate merge tree
* fix(ci): allow trusted main locale output
2026-07-16 18:48:20 -07:00
Peter Steinberger
b78cf56349
improve(ci): persist warm Vitest and Node caches ( #109425 )
...
* perf(ci): harden persistent test caches
* ci: document trusted cache cleanup trigger
* ci: harden composite cache inputs
* perf(ci): isolate Node build bytecode cache
2026-07-16 17:22:28 -07:00
Peter Steinberger
7bf5c772be
improve: reuse Vitest transform cache across CI runs ( #109330 )
...
* ci: persist Vitest transform cache
* fix(ci): declare Vitest cache helpers
* fix(ci): serialize Vitest cache snapshots
2026-07-16 14:15:17 -07:00
Dallin Romney
c4b2183db6
fix(release): repair frozen validation compatibility ( #109272 )
2026-07-16 11:45:31 -07:00
Peter Steinberger
21b08f34b7
perf(ci): run the deadcode Knip scans concurrently ( #109151 )
...
* perf(ci): run the deadcode Knip scans concurrently
check-dependencies spent ~194s running seven Knip child processes
strictly serially (three package scripts, each iterating its scans).
The scans are independent processes over separate configs: both
deadcode scripts now Promise.all their scans, the CI task launches the
three package scripts concurrently with buffered logs, and the lane
moves to the 16 vCPU class for core/memory headroom. The
missing-exports-script contract violation now fails fast before
launching scans. Local: unused-files 218% CPU, 37s wall.
* test(ci): align prerelease plan with the 16 vCPU dependencies lane
2026-07-16 10:46:44 -07:00
Peter Steinberger
037ef6695a
fix(ci): bound actionlint downloads ( #108938 )
2026-07-16 04:24:26 -07:00
Peter Steinberger
d739daef10
fix(ci): handle Android license pipe closure
2026-07-16 12:12:18 +01:00
Peter Steinberger
e0ffbd90d9
fix(ci): isolate bounded metadata retries ( #108804 )
...
* fix(ci): bound Mantis runner IP retries
* fix(e2e): isolate Windows metadata retries
* fix(ci): validate complete runner IPv4
Co-authored-by: Alix-007 <li.long15@xydigit.com >
---------
Co-authored-by: Alix-007 <li.long15@xydigit.com >
2026-07-16 03:39:31 -07:00
Peter Steinberger
b6b8e59b9e
refactor(ci): share Android toolchain setup ( #108855 )
...
* refactor(ci): share Android toolchain setup
* fix(ci): preserve frozen Android targets
2026-07-16 03:38:31 -07:00
Peter Steinberger
76a236da5f
fix(ci): harden release validation gates ( #108798 )
...
* fix(ci): harden release validation gates
* fix(apns): keep tombstones in strict SQLite schema
* fix(ci): isolate PR publication transport
2026-07-16 03:21:08 -07:00
Alix-007
47dd90c5ea
fix(ci): bound Android SDK downloads ( #108723 )
2026-07-16 02:12:07 -07:00
Alix-007
5cd9243465
fix(ci): bound Windows Testbox phone-home requests ( #108755 )
2026-07-16 01:57:53 -07:00
Alix-007
ea3ac194f4
fix(ci): bound Mantis runner IP discovery ( #108699 )
2026-07-16 01:50:22 -07:00
Alix-007
e0394c2ab4
fix(ci): bound native tool downloads ( #108685 )
...
* fix(ci): bound native tool downloads
* fix(ci): bound historical SwiftFormat downloads
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 01:44:30 -07:00
Peter Steinberger
a7d5386896
improve: speed up ring-zero QA smoke ( #108694 )
...
* ci: speed up ring-zero QA smoke
* ci: scope QA sticky cache to Docker lane
* ci: keep QA dependency setup on actions cache
* test: restore modern Docker QA proof
2026-07-16 01:12:40 -07:00
Alix-007
3912cf38b9
fix(ci): bound workflow ShellCheck download ( #108672 )
2026-07-16 00:56:27 -07:00
Sash Zats
0960d07d8e
ci: gate PR edit automation by changed field ( #95010 )
...
* ci: gate PR edit automation by changed field
* ci: include title edits in ClawSweeper dispatch gate
* ci: refine PR edit automation gates
Co-authored-by: Sash Zats <sash@zats.io >
* test(ci): require boolean workflow matcher
Co-authored-by: Sash Zats <sash@zats.io >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 00:42:14 -07:00
Peter Steinberger
a6125b7868
perf(ci): split QA smoke into four profile parts and time tsdown invocations ( #108638 )
2026-07-15 22:41:02 -07:00
Peter Steinberger
6252f9b1f7
improve(ci): speed warm Node shards with sticky bind mount ( #108386 )
...
* perf(ci): bind sticky dependency disk into test shards
* chore(ci): restore workflow guard coverage
* perf(ci): skip pnpm install on exact sticky hits
* fix(ci): require stock layout for sticky dependencies
* perf(ci): bypass pnpm for test shard launches
* fix(ci): declare direct shard runner command
* fix(ci): bypass pnpm in warm shard builds
* fix(ci): invalidate sticky deps on pnpm config
* ci: document sticky failure guard
2026-07-15 15:41:24 -07:00
Peter Steinberger
4c667aac88
fix(release): harden frozen target validation ( #108296 )
...
* fix(release): harden frozen scenario planning
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): omit unsupported scenario-only lanes
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): fail closed on malformed target scenarios
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): report unsupported frozen lanes
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): defer frozen survivor inspection
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): report partial survivor omissions
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(ci): fetch shard fallback from workflow commit
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): gate frozen scenario omissions
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* test(release): auto-clean frozen target temp dirs
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(ci): satisfy frozen validation workflow lint
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
---------
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
2026-07-15 06:31:07 -07:00
Dallin Romney
043e4d1ec4
fix(release): validate frozen targets with current workflows ( #108189 )
...
* fix(release): support frozen validation targets
* fix(release): filter frozen-target upgrade scenarios
2026-07-15 04:28:17 -07:00
Peter Steinberger
57761ebe8c
perf(ci): balance node test shards and gate heavy CI lanes by changed scope ( #108091 )
2026-07-15 01:16:47 -07:00
Peter Steinberger
2e73cff6ca
fix(maint): keep PR maintenance delta-only ( #108018 )
...
* fix(maint): keep fork prep sync delta-only
* fix(ci): use exact merge parent for PR diffs
* fix(ci): pass docs diff base through environment
* test(ci): cover environment-mediated docs base
2026-07-14 22:49:33 -07:00
Peter Steinberger
202b04925c
fix(ci): fetch exact PR base before history ( #107674 )
2026-07-14 10:12:40 -07:00
Peter Steinberger
f81f9d8570
chore: enforce max-lines suppression ratchet ( #107315 )
...
* ci: enforce max-lines suppression ratchet
* chore: prune stale max-lines suppression
* fix: close max-lines ratchet enforcement gaps
* fix: harden max-lines ratchet checks
* fix(ci): satisfy max-lines ratchet checks
* style: format max-lines declarations
* fix(ci): match oxlint suppression grammar
* test: isolate max-lines git fixtures
* chore: prune resolved max-lines debt
* test: skip newline path fixture on Windows
* fix: harden max-lines suppression ratchet
* chore: refresh max-lines baseline
* fix: close max-lines ratchet bypasses
* fix: derive ratchet base from PR merge tree
* fix: support older Git in staged ratchet
* fix: align max-lines declarations and baseline
* chore: refresh max-lines baseline for current main
* fix: exclude generated wizard locales from max-lines
* chore: prune resolved max-lines debt
2026-07-14 09:27:02 -07:00
Peter Steinberger
47d37804a8
improve(ui): catch i18n catalog drift locally ( #107253 )
...
* ci(ui): verify i18n catalogs locally
* fix(ui): preserve scoped i18n sync errors
* refactor(ui): share i18n raw-copy verifier
* test(ui): cover i18n lint gate
* fix(ui): route lint threads to oxlint
2026-07-14 01:12:36 -07:00
Peter Steinberger
f4b7a19624
fix: avoid remote boxes for focused validation ( #107166 )
...
* fix: avoid remote boxes for focused validation
* fix: preserve explicit remote proof routing
* fix: delegate when local diff refs are unavailable
2026-07-14 00:53:17 -07:00
Peter Steinberger
606e2f5dba
fix(ci): stop unrelated main updates from forcing PR rebases ( #107050 )
...
* fix(ci): stop unrelated main updates from forcing PR rebases
* docs(ci): document reusable aggregate proof
* docs(ci): clarify immutable gate success
* chore(ci): refresh stalled PR head
2026-07-14 00:01:01 -07:00
Peter Steinberger
df5097b6e7
fix(native): keep platform validation warning-free ( #107101 )
...
* build(android): keep Gradle warning-free
* ci(native): pin XcodeGen tooling
* test(macos): avoid concurrency warnings
2026-07-13 22:33:12 -07:00
Peter Steinberger
70833dab7f
ci: scope PR Node tests to changed targets ( #106633 )
...
* ci: scope PR Node tests to changed targets
* ci: bound targeted Node test plans
* test: cover changed path manifest input
* fix(ui): preserve model providers lazy boundary
* ci: cover public SDK re-export consumers
* ci: reject unresolved changed test targets
* ci: cover public SDK wrapper imports
* ci: preserve global checks in targeted plans
* docs(ci): clarify targeted boundary coverage
* test(plugins): declare computed runtime dependencies
2026-07-13 15:26:02 -07:00
Peter Steinberger
458746e1c2
chore(ci): enforce changed-file TypeScript LOC ratchet ( #106387 )
...
* ci: enforce changed-file TypeScript LOC ratchet
* ci: derive release-gate LOC base from PR
* test(ci): exclude repository test helpers from LOC ratchet
* ci: validate LOC ratchet on PR merge tree
* style: format release maintainer skill
* ci: run LOC ratchet for fast-only changes
* fix(ci): harden LOC ratchet comparisons
* fix(ci): cover native TypeScript in LOC ratchet
* fix(ci): compare LOC against tested merge tree
* test(ci): cover LOC manifest routing
2026-07-13 07:20:32 -07:00
Peter Steinberger
4b6575636f
fix(ci): finalize control UI locale artifacts
2026-07-13 12:12:51 +01:00
Peter Steinberger
e2ed58efec
fix(ci): publish native generated locales
2026-07-13 11:41:15 +01:00
Peter Steinberger
b1ce84b079
ci: reduce Blacksmith registrations for pull requests ( #106146 )
2026-07-13 01:32:25 -07:00
Peter Steinberger
0ab7e2569b
fix(ci): preserve pinned manual checkout
2026-07-13 03:42:26 -04:00
Vincent Koc
f33ab243cf
fix(sqlite): reject runtimes vulnerable to WAL corruption ( #106065 )
...
* fix(sqlite): require WAL-reset-safe Node runtime
* docs(sqlite): document safe Node runtime floor
* fix(sqlite): defer runtime library validation until use
* fix(ci): align startup memory with Node 24.15
2026-07-13 13:59:00 +08:00
Peter Steinberger
dce8eed0b9
ci(deadcode): restore enforced unused-export ratchet ( #105826 )
...
* ci(deadcode): restore export ratchet
* chore(deadcode): refresh export baseline
* refactor(sessions): remove obsolete patch writer
* refactor(deadcode): classify current export residue
* fix(deadcode): preserve exported signature types
* chore(deadcode): sync export baseline after rebase
* chore(deadcode): classify pairing test exports
* fix(ci): refresh plugin SDK declaration budget
2026-07-12 19:58:38 -07:00
Vincent Koc
2c06dfdd2f
fix(ci): keep unused exports advisory ( #105704 )
...
* fix(ci): preserve frozen deadcode contracts
* fix(ci): keep unused exports advisory
2026-07-13 05:47:05 +08:00
Peter Steinberger
22f183f8cb
ci: isolate legacy QA smoke invocations ( #105340 )
...
* ci: isolate legacy QA smoke invocations
* docs(agents): record PR review recommendation
2026-07-12 12:52:31 +01:00
Peter Steinberger
a20314d6cc
ci: preserve frozen Android build contract ( #105299 )
2026-07-12 11:48:02 +01:00
Peter Steinberger
7bb59c4511
ci: pin release validation Go toolchain ( #105270 )
2026-07-12 11:02:04 +01:00
Peter Steinberger
265ca345a1
ci: pin frozen iOS formatter ( #105242 )
...
* ci: pin frozen iOS formatter
* docs: clarify release CI dispatch
* ci: preserve frozen iOS formatter path
* style: format CI workflow guard
2026-07-12 10:49:26 +01:00
Peter Steinberger
e0f45bfbf0
feat(tooling): enforce indexed access checks in root tests ( #105223 )
...
* feat(tooling): enforce indexed access checks in root tests
* style(tooling): clarify scoped package guard
2026-07-12 10:42:07 +01:00
Peter Steinberger
d79373fa14
ci: bound legacy QA smoke compatibility ( #105213 )
2026-07-12 10:15:33 +01:00
Peter Steinberger
acc57e4145
ci: isolate frozen Control UI tests ( #105208 )
2026-07-12 10:06:23 +01:00