The kit had NO biome config and no lint script, while every plugin repo that
consumes it has both. So its source quietly drifted — unused imports, unsorted
imports, formatting — with nothing to catch any of it. Running biome here for
the first time reported 20 findings across 8 files.
Adds `plugin-kit/biome.json` mirroring the plugin repos' (tab indent, double
quotes, recommended lint preset, organizeImports), a `check` script, and
`@biomejs/biome` pinned to the same `^2.5.2` the plugins pin — without that pin
`bunx biome` resolved 2.4.6, which rejects the 2.5 `rules.preset` key.
Two deliberate differences from the plugin repos' copy:
* no `vcs.useIgnoreFile` — those are standalone repos with a .gitignore beside
the config; plugin-kit is a directory inside this one, and biome errors with
"couldn't find an ignore file". The `files.includes` exclusions cover it.
* `!examples/**/dist` instead of `!ui/dist` — the kit has examples, not a UI.
`css.parser.tailwindDirectives` is carried over and is load-bearing: without it
biome cannot parse `@theme` in src/theme.css and reports three parse errors on
CSS that is perfectly valid Tailwind v4.
Everything here is formatter/import churn except two real findings, both fixed:
* `Layer` (library/define.ts) and `Cause` (sync-engine.ts) were imported and
never used;
* test/spike-httpapi.test.ts read `(reg?.body as …).ui.secret` one line after
`expect(reg).toBeDefined()`. The optional chain undoes the assertion: had
`reg` been undefined the `.ui` access would throw a TypeError instead of
failing the test readably. Now asserted to the type system too.
Wired into plugin-kit-publish.yml as a `Lint & format` step ahead of Typecheck,
so this cannot rot again.
Gates after: biome clean (42 files), tsc clean, 67/67 tests, build clean.
104 lines
4.3 KiB
YAML
104 lines
4.3 KiB
YAML
# Publish the plugin framework (@punktfunk/plugin-kit) to the Gitea npm registry
|
|
# (https://git.unom.io/api/packages/unom/npm/).
|
|
#
|
|
# Trigger: push a tag `plugin-kit-vX.Y.Z` (must equal plugin-kit/package.json "version"),
|
|
# or run manually. Versions independently of the app's `v*` and the SDK's `sdk-v*` tags.
|
|
#
|
|
# The kit's devDependency on @punktfunk/host is `file:../sdk`, so the SDK's dist must be
|
|
# built BEFORE the kit's `bun install` copies it.
|
|
#
|
|
# Auth: REGISTRY_TOKEN — the same repo Actions secret sdk-publish.yml uses.
|
|
name: plugin-kit-publish
|
|
# One pending run per workflow+ref: a newer push supersedes the queued/running one and cancels
|
|
# it (a canary only needs the latest commit; each release tag is its own ref so tag runs never
|
|
# cancel each other). Keeps a busy push cadence from piling ~10 queued runs per commit onto the
|
|
# runner fleet. Gitea honors this for push triggers (PR triggers: see gitea#35933).
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
|
|
on:
|
|
push:
|
|
tags: ['plugin-kit-v*']
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
publish:
|
|
runs-on: ubuntu-24.04
|
|
container:
|
|
image: oven/bun:1
|
|
timeout-minutes: 15
|
|
steps:
|
|
# oven/bun's slim base ships neither git, a CA bundle, nor node — actions/checkout's HTTPS
|
|
# fetch needs git + ca-certificates, and the version-guard step below uses node.
|
|
- name: Install git + node + CA certs
|
|
run: apt-get update && apt-get install -y --no-install-recommends ca-certificates git nodejs
|
|
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Build the SDK (file:../sdk dependency source)
|
|
working-directory: sdk
|
|
run: |
|
|
bun install --frozen-lockfile --ignore-scripts
|
|
bun run build
|
|
|
|
- name: Install dependencies
|
|
working-directory: plugin-kit
|
|
run: bun install --frozen-lockfile --ignore-scripts
|
|
|
|
# bun 1.3 installs a `file:` dependency by copying its DIRECTORIES but symlinking each
|
|
# top-level FILE to itself — `node_modules/@punktfunk/host/package.json -> package.json`, a
|
|
# dangling self-reference. `dist/` therefore arrives intact while the manifest that points at
|
|
# it does not, so module resolution dies at the first step and every `@punktfunk/host` import
|
|
# reads as "cannot find module". Replacing the tree with a real copy is the whole fix; drop
|
|
# this step once bun links `file:` deps correctly again.
|
|
- name: "Repair the file: dependency (bun 1.3 self-symlink)"
|
|
working-directory: plugin-kit
|
|
run: |
|
|
# -f follows the link, so this is true only when the manifest actually resolves.
|
|
if test -f node_modules/@punktfunk/host/package.json; then
|
|
echo "bun linked it correctly — this step can go"
|
|
else
|
|
rm -rf node_modules/@punktfunk/host
|
|
cp -R ../sdk node_modules/@punktfunk/host
|
|
fi
|
|
test -f node_modules/@punktfunk/host/package.json
|
|
test -f node_modules/@punktfunk/host/dist/index.d.ts
|
|
|
|
# The kit had no biome config and no lint step, while every plugin repo that consumes it does
|
|
# — so its source drifted (unused imports, formatting) with nothing to catch it. Now gated
|
|
# here, on the same config and pinned biome version the plugins use.
|
|
- name: Lint & format
|
|
working-directory: plugin-kit
|
|
run: bun run check
|
|
|
|
- name: Typecheck
|
|
working-directory: plugin-kit
|
|
run: bun run typecheck
|
|
|
|
- name: Test
|
|
working-directory: plugin-kit
|
|
run: bun test
|
|
|
|
- name: Build (dist/ JS + .d.ts + theme.css)
|
|
working-directory: plugin-kit
|
|
run: bun run build
|
|
|
|
- name: Tag matches package version
|
|
if: startsWith(github.ref, 'refs/tags/')
|
|
working-directory: plugin-kit
|
|
run: |
|
|
TAG="${GITHUB_REF_NAME#plugin-kit-v}"
|
|
PKG="$(node -p "require('./package.json').version")"
|
|
test "$TAG" = "$PKG" || { echo "tag $GITHUB_REF_NAME does not match package version $PKG"; exit 1; }
|
|
|
|
- name: Publish to Gitea registry
|
|
working-directory: plugin-kit
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
|
run: |
|
|
test -n "$NODE_AUTH_TOKEN" || { echo "REGISTRY_TOKEN secret is empty"; exit 1; }
|
|
printf '//git.unom.io/api/packages/unom/npm/:_authToken=%s\n' "$NODE_AUTH_TOKEN" >> .npmrc
|
|
bun publish
|