[pull] main from TryGhost:main - #1420
Merged
Merged
Conversation
no ref - `?v=` was `md5(Date.now())`, generated per process, so every restart and every instance behind a load balancer handed out a different URL for identical bytes — browser and CDN caches never stayed warm - the content-based hash already existed behind a flag but defaulted to off, so nobody was getting it; flipping the default is what actually delivers it - card assets couldn't be hashed at all, because they were minified lazily on first request — at render time the file usually didn't exist yet. Moving that to build time makes the bytes known up front, and drops a non-atomic write to a shared content volume that concurrent boots could tear - hashing content rather than version means a release that doesn't touch card CSS doesn't invalidate every site at once
Ghost is moving from JavaScript to TypeScript, but TypeScript alone doesn't make the codebase type-safe: types disappear at runtime, and data arriving over HTTP, from config, the database, or third-party services can still be missing or malformed. We've adopted type safety as a desired property of Ghost — TypeScript as the language, Zod as the standard for validating data at runtime boundaries. A principle only sticks if it shows up in review, and humans are inconsistent at spotting an unvalidated JSON.parse or a stray `as` assertion buried in a large diff. These CodeRabbit rules make the automated reviewer carry that lens on every PR, so the question "where does this data become trusted?" gets asked even when no human reviewer thinks to ask it. Concretely: - TypeScript files are reviewed for unvalidated boundary data, for handwritten types duplicating what a Zod schema already describes (use z.infer), and for escape hatches like `any`, unchecked `as`, and @ts-nocheck. - New source files must be TypeScript, enforced by an error-mode pre-merge check. Places where plain JS is genuinely required — DB migrations, ember-admin, tooling — are exempt. - Substantially reworked JS files get a single optional nudge that they'd be cheap to convert while the context is fresh. Deliberately out of scope: internal function calls don't need runtime validation, and merely touching a JS file never requires converting it. The rules are meant to reinforce the direction, not to tax unrelated work.
…0004) no ref - cbe73b1 moved card minification to build time and made cards.manifest.json a hard boot requirement, but job_perf-tests only ran build:tsc, so boot died with ENOENT and hyperfine exited 2 - the test jobs never hit this because their nx targets declare build:assets in dependsOn, and the production-image benchmark gets it from Dockerfile.production - this job boots via raw `node index.js`, so there is no target to inherit it from and it has to build the assets itself - the step sits outside the measured command, so the boot-time series stays comparable with its history
CodeRabbit had limited Ghost-specific context, making reviews more likely to miss established conventions or produce broad, generic feedback. Now our documentation is in the codebase, we were able to map canonical documentation to the code it governs and add focused review guidance for backend services, APIs, migrations, packages, Admin UI, public apps, E2E tests, and documentation. Prioritise concrete correctness, security, compatibility, and regression risks while avoiding feedback already covered by lint or CI. Explicitly enable relevant analysis tools, exclude generated output, and skip dependency-bot PRs. Keep general review feedback non-blocking while retaining the existing type-safety pre-merge checks.
Added fast, offline checks for broken repository-relative links, images, heading anchors, and objective Markdown syntax. Uses maintained remark and markdownlint tooling with a deliberately conservative rule set, avoiding subjective formatting noise while making documentation regressions fail through the existing lint:docs command.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )