Skip to content

Upgrade codex and claude to latest (#178) #370

Upgrade codex and claude to latest (#178)

Upgrade codex and claude to latest (#178) #370

Workflow file for this run

name: CI
on:
pull_request:
push:
branches: [main]
workflow_dispatch:
# Cancel in-progress PR and manually dispatched runs for the same branch; let
# main runs finish so the release workflow's history stays uninterrupted.
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name != 'push' }}
permissions:
contents: read
jobs:
validate:
runs-on: ubuntu-latest
timeout-minutes: 20
# deepsec supports Node 22+ (engines.node in package.json); test on both
# the floor and the current Node so a 24-only API change can't sneak in.
strategy:
fail-fast: false
matrix:
node: ['22', '24']
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
# pnpm version is read from `packageManager` in the root package.json,
# so bumping it there is enough — no version pin needed here.
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v4.4.0
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: ${{ matrix.node }}
cache: pnpm
- run: pnpm install --frozen-lockfile
# Mirrors the steps in the root `validate` script, split out so the
# GitHub UI shows which one failed without grepping logs.
- run: pnpm -r build
- run: pnpm lint
- run: pnpm knip
- run: pnpm test:unit
- run: pnpm test:bundle
# Typechecks .deepsec/deepsec.config.ts against the freshly bundled
# `dist/config.d.ts` — catches regressions where the published types
# leak references to workspace-internal `@deepsec/*` packages.
- run: pnpm typecheck:deepsec