From d60af2d2c3112c978996b67d7966e16a4d579aad Mon Sep 17 00:00:00 2001 From: Ben Balter Date: Sun, 27 Sep 2026 10:16:39 -0400 Subject: [PATCH] Upgrade @lhci/cli to 0.15.1 and restore insight audits @lhci/cli 0.15.1 bundles Lighthouse 12.6.1 (was 12.1.0 in 0.14.0). Its no-pwa preset now asserts the 12.6 insight audits at error, so the bump alone fails CI on all three pages. Set explicit levels: - image-delivery-insight: restored at warn (removed in d134acb1 only because 12.1.0 lacked it). It flagged the BookCta cover serving 440w for a 176px slot; switch it to explicit widths with a matching sizes attribute so the browser picks 352w, which clears the audit. - network-dependency-tree-insight: restored at warn. The trace engine fails it for any chain of 2+ requests, so every page scores 0. - cls-culprits-insight: warn, matching cumulative-layout-shift, which already warns on the /about headshot shift. - robots-txt: still off. 12.6.1's directive safelist still lacks Content-Signal and scores robots.txt 0. No assertion or preset keys are stale in 12.6.1. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/astro-e2e.yml | 2 +- .lighthouserc.json | 7 +++++-- src/components/BookCta.astro | 3 ++- 3 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/astro-e2e.yml b/.github/workflows/astro-e2e.yml index eedf6154c..91400aa20 100644 --- a/.github/workflows/astro-e2e.yml +++ b/.github/workflows/astro-e2e.yml @@ -160,7 +160,7 @@ jobs: # No npm ci: npx fetches @lhci/cli on its own, and it needs nothing from # the project's dependencies. - name: Run Lighthouse CI - run: npx --yes @lhci/cli@0.14.0 autorun --collect.url="http://localhost/${PAGE}" + run: npx --yes @lhci/cli@0.15.1 autorun --collect.url="http://localhost/${PAGE}" env: PAGE: ${{ matrix.page }} LHCI_GITHUB_APP_TOKEN: ${{ secrets.LHCI_GITHUB_APP_TOKEN }} diff --git a/.lighthouserc.json b/.lighthouserc.json index d75f360fe..163917321 100644 --- a/.lighthouserc.json +++ b/.lighthouserc.json @@ -1,5 +1,5 @@ { - "_comment": "csp-xss flipped to warn: a comprehensive CSP is set in public/_headers (default-src 'self', frame-ancestors 'none', base-uri 'self', form-action 'self'). Note Lighthouse only sees CSP when delivered as an HTTP header, so this assertion may still fail when collecting against the static dist (no server). Other rules remain off because: unused-javascript/unused-css-rules report false positives on Astro/Tailwind output that's already purged; lcp-lazy-loaded/prioritize-lcp-image are noisy because the LCP element varies per page; non-composited-animations flags utility CSS transitions on hover; uses-long-cache-ttl can't be evaluated against a static dist (Cloudflare _headers sets immutable 1y on /assets/* in production). robots-txt is off because Lighthouse 12.1.0 (bundled with @lhci/cli 0.14.x) flags our intentional Content-Signal directive (contentsignals.org, a 2025 spec) as an 'Unknown directive' and scores the file 0 — the robots.txt is valid per the real spec, so this is a false positive from an outdated validator. The image-delivery-insight and network-dependency-tree-insight assertions were removed because those 'insight' audits don't exist in Lighthouse 12.1.0 ('is not a known audit'); re-add them if/when @lhci/cli upgrades to a Lighthouse version that ships them. Re-evaluate these after a successful real-environment lighthouse run.", + "_comment": "csp-xss flipped to warn: a comprehensive CSP is set in public/_headers (default-src 'self', frame-ancestors 'none', base-uri 'self', form-action 'self'). Note Lighthouse only sees CSP when delivered as an HTTP header, so this assertion may still fail when collecting against the static dist (no server). Other rules remain off because: unused-javascript/unused-css-rules report false positives on Astro/Tailwind output that's already purged; lcp-lazy-loaded/prioritize-lcp-image are noisy because the LCP element varies per page; non-composited-animations flags utility CSS transitions on hover; uses-long-cache-ttl can't be evaluated against a static dist (Cloudflare _headers sets immutable 1y on /assets/* in production). robots-txt is still off: Lighthouse 12.6.1 (bundled with @lhci/cli 0.15.1) still only safelists user-agent, allow, disallow, sitemap, crawl-delay, clean-param, host, request-rate, visit-time, and noindex, so it flags our intentional Content-Signal directive (contentsignals.org) as an 'Unknown directive' and scores the file 0. The robots.txt is valid; this is a false positive from the validator. The no-pwa preset in @lhci/cli 0.15.x asserts the Lighthouse 12.6 insight audits at error. network-dependency-tree-insight is set to warn because the trace engine marks it failed for any critical chain of 2+ requests (document then any subresource), so every page scores 0. cls-culprits-insight is set to warn to match cumulative-layout-shift, which is already warn (the /about headshot shifts the intro paragraph). image-delivery-insight is set to warn so a single oversized image surfaces without blocking CI; uses-responsive-images stays at error. Re-evaluate these after a successful real-environment lighthouse run.", "ci": { "collect": { "staticDistDir": "./dist-astro", @@ -27,7 +27,10 @@ "cumulative-layout-shift": "warn", "identical-links-same-purpose": "warn", "total-byte-weight": "warn", - "robots-txt": "off" + "robots-txt": "off", + "network-dependency-tree-insight": "warn", + "image-delivery-insight": "warn", + "cls-culprits-insight": "warn" } }, "upload": { diff --git a/src/components/BookCta.astro b/src/components/BookCta.astro index 8b4493fc9..a0f5183e8 100644 --- a/src/components/BookCta.astro +++ b/src/components/BookCta.astro @@ -57,7 +57,8 @@ const inlineHeadline = alt="Open and Async book cover" width={220} height={244} - densities={[1, 2]} + widths={[176, 224, 352, 448]} + sizes="(min-width: 768px) 224px, 176px" loading="lazy" decoding="async" class="w-44 md:w-56 h-auto"