Upgrade codex and claude to latest (#178) #370
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| # Cancel in-progress PR and manually dispatched runs for the same branch; let | |
| # main runs finish so the release workflow's history stays uninterrupted. | |
| concurrency: | |
| group: ci-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name != 'push' }} | |
| permissions: | |
| contents: read | |
| jobs: | |
| validate: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| # deepsec supports Node 22+ (engines.node in package.json); test on both | |
| # the floor and the current Node so a 24-only API change can't sneak in. | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| node: ['22', '24'] | |
| steps: | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| # pnpm version is read from `packageManager` in the root package.json, | |
| # so bumping it there is enough — no version pin needed here. | |
| - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v4.4.0 | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 | |
| with: | |
| node-version: ${{ matrix.node }} | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| # Mirrors the steps in the root `validate` script, split out so the | |
| # GitHub UI shows which one failed without grepping logs. | |
| - run: pnpm -r build | |
| - run: pnpm lint | |
| - run: pnpm knip | |
| - run: pnpm test:unit | |
| - run: pnpm test:bundle | |
| # Typechecks .deepsec/deepsec.config.ts against the freshly bundled | |
| # `dist/config.d.ts` — catches regressions where the published types | |
| # leak references to workspace-internal `@deepsec/*` packages. | |
| - run: pnpm typecheck:deepsec |