Skip to content

Commit 5d2c0a1

Browse files
committed
ci: run the repo's gates on free runners, fork-only
Fork-internal. Upstream's ci.yml targets blacksmith runners this fork does not have, so its jobs queue with no runner and UsefulSoftwareCo#1564 has never carried a check. This runs lint, format, typecheck and the full core/sdk suite - including the 909-line delegation test this PR adds - on ubuntu-latest, which is free and uncapped for public repositories. FORK-ONLY. Must never reach the upstream pull request.
1 parent 014285f commit 5d2c0a1

1 file changed

Lines changed: 61 additions & 0 deletions

File tree

‎.github/workflows/fork-gates.yml‎

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
# FORK-ONLY. This file must never reach an upstream pull request.
2+
#
3+
# Upstream's ci.yml runs on `blacksmith-4vcpu-ubuntu-2404`, runners provisioned for the upstream org.
4+
# On this fork nothing picks those jobs up: they sit `queued` with no runner, forever — no cost, and
5+
# no signal either. That is why the sixteen PRs have never had a check.
6+
#
7+
# This runs the repo's OWN gates on `ubuntu-latest` instead. GitHub-hosted standard runners are free
8+
# for public repositories with no minute cap, and this repository is public, so this costs nothing.
9+
# Kept deliberately small for the same reason: the gates that catch real defects, and none of the
10+
# e2e/deploy/docker jobs, which need secrets this fork does not have and would only fail slowly.
11+
name: Fork gates
12+
13+
on:
14+
pull_request:
15+
workflow_dispatch:
16+
17+
concurrency:
18+
group: fork-gates-${{ github.ref }}
19+
cancel-in-progress: true
20+
21+
permissions:
22+
contents: read
23+
24+
jobs:
25+
gates:
26+
name: Lint, format, typecheck, test
27+
runs-on: ubuntu-latest
28+
timeout-minutes: 25
29+
steps:
30+
- uses: actions/checkout@v4
31+
32+
- uses: oven-sh/setup-bun@v2
33+
with:
34+
bun-version-file: package.json
35+
36+
- name: Install
37+
run: bun install --frozen-lockfile
38+
39+
# Each gate runs even if an earlier one failed, so one run reports everything
40+
# rather than hiding the second failure behind the first.
41+
- name: Lint
42+
id: lint
43+
if: ${{ !cancelled() }}
44+
run: bunx --bun oxlint -c .oxlintrc.jsonc . --deny-warnings
45+
46+
- name: Format
47+
id: fmt
48+
if: ${{ !cancelled() }}
49+
run: bunx --bun oxfmt --check .
50+
51+
- name: Typecheck (core/sdk)
52+
id: tc
53+
if: ${{ !cancelled() }}
54+
working-directory: packages/core/sdk
55+
run: bunx --bun tsgo --noEmit
56+
57+
- name: Test (core/sdk)
58+
id: test
59+
if: ${{ !cancelled() }}
60+
working-directory: packages/core/sdk
61+
run: bun run test

0 commit comments

Comments
 (0)