Skip to content

[pull] main from TryGhost:main - #1420

Merged
pull[bot] merged 5 commits into
code:mainfrom
TryGhost:main
Aug 17, 2026
Merged

pull[bot] merged 5 commits into
code:mainfrom
TryGhost:main

Conversation

@pull

@pull pull Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

jloh and others added 5 commits August 17, 2026 12:22
no ref

- `?v=` was `md5(Date.now())`, generated per process, so every restart and
  every instance behind a load balancer handed out a different URL for
  identical bytes — browser and CDN caches never stayed warm
- the content-based hash already existed behind a flag but defaulted to off,
  so nobody was getting it; flipping the default is what actually delivers it
- card assets couldn't be hashed at all, because they were minified lazily on
  first request — at render time the file usually didn't exist yet. Moving
  that to build time makes the bytes known up front, and drops a non-atomic
  write to a shared content volume that concurrent boots could tear
- hashing content rather than version means a release that doesn't touch card
  CSS doesn't invalidate every site at once
Ghost is moving from JavaScript to TypeScript, but TypeScript alone
doesn't make the codebase type-safe: types disappear at runtime, and
data arriving over HTTP, from config, the database, or third-party
services can still be missing or malformed. We've adopted type safety
as a desired property of Ghost — TypeScript as the language, Zod as
the standard for validating data at runtime boundaries.

A principle only sticks if it shows up in review, and humans are
inconsistent at spotting an unvalidated JSON.parse or a stray `as`
assertion buried in a large diff. These CodeRabbit rules make the
automated reviewer carry that lens on every PR, so the question
"where does this data become trusted?" gets asked even when no human
reviewer thinks to ask it.

Concretely:

- TypeScript files are reviewed for unvalidated boundary data, for
  handwritten types duplicating what a Zod schema already describes
  (use z.infer), and for escape hatches like `any`, unchecked `as`,
  and @ts-nocheck.
- New source files must be TypeScript, enforced by an error-mode
  pre-merge check. Places where plain JS is genuinely required — DB
  migrations, ember-admin, tooling — are exempt.
- Substantially reworked JS files get a single optional nudge that
  they'd be cheap to convert while the context is fresh.

Deliberately out of scope: internal function calls don't need runtime
validation, and merely touching a JS file never requires converting
it. The rules are meant to reinforce the direction, not to tax
unrelated work.
…0004)

no ref

- cbe73b1 moved card minification to build time and made
  cards.manifest.json a hard boot requirement, but job_perf-tests only ran
  build:tsc, so boot died with ENOENT and hyperfine exited 2
- the test jobs never hit this because their nx targets declare build:assets
  in dependsOn, and the production-image benchmark gets it from
  Dockerfile.production - this job boots via raw `node index.js`, so there is
  no target to inherit it from and it has to build the assets itself
- the step sits outside the measured command, so the boot-time series stays
  comparable with its history
CodeRabbit had limited Ghost-specific context, making reviews more likely to
miss established conventions or produce broad, generic feedback.

Now our documentation is in the codebase, we were able to map canonical 
documentation to the code it governs and add focused review
guidance for backend services, APIs, migrations, packages, Admin UI, public
apps, E2E tests, and documentation. Prioritise concrete correctness,
security, compatibility, and regression risks while avoiding feedback already
covered by lint or CI.

Explicitly enable relevant analysis tools, exclude generated output, and skip
dependency-bot PRs. Keep general review feedback non-blocking while retaining
the existing type-safety pre-merge checks.
Added fast, offline checks for broken repository-relative links,
images, heading anchors, and objective Markdown syntax.

Uses maintained remark and markdownlint tooling with a deliberately
conservative rule set, avoiding subjective formatting noise while making
documentation regressions fail through the existing lint:docs command.
@pull pull Bot locked and limited conversation to collaborators Aug 17, 2026
@pull pull Bot added the ⤵️ pull label Aug 17, 2026
@pull
pull Bot merged commit c5f2fd9 into code:main Aug 17, 2026
2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants