Skip to content

feat(mt#3866): Give calibration records an identity, and report disti… #2454

feat(mt#3866): Give calibration records an identity, and report disti…

feat(mt#3866): Give calibration records an identity, and report disti… #2454

name: npm Pack Install Smoke
# mt#3949 — consumer-side gate for the npm publish channel.
#
# Every check the publish path had was a PUBLISHER-side check: does the package
# exist, do we own the name, did OIDC authenticate, is provenance attached. All
# of them pass on a package nobody can install — which is exactly what shipped.
# `@edobry/minsky@0.1.1` declared two dependencies at `workspace:*`, a protocol
# no registry client can resolve, so every install outside this monorepo failed
# at resolution. It was live and uninstallable for a day, across two versions.
#
# This job runs `scripts/verify-npm-pack-install.ts`, which packs the exact
# artifact `npm publish` would upload and installs it — locally and through the
# global path, into a throwaway BUN_INSTALL prefix — then runs the installed
# `minsky --version`. Verifying against the packed tarball is what makes this a
# PRE-publish gate: checking after publishing costs an immutable version number
# per attempt, which is how the original defect was found rather than prevented.
#
# mt#3887: also runs the script's step 4b, which applies migrations against the
# Postgres service below using the INSTALLED package's dist/ layout. This is the
# falsifier for excluding dist/storage/migrations/pg/meta/*_snapshot.json from
# files[] — those are drizzle-kit's generate-time-only metadata, and this job is
# what proves apply-time (`persistence migrate --execute`) never needed them,
# against a real database rather than by reading drizzle's docs.
#
# Sibling gates, and why this is not either of them:
# - bundle-boot-smoke: does the thing we DEPLOY start? (dist/minsky.js on Railway)
# - docker-build-smoke: does the production image BUILD?
# - this: can an end user INSTALL and run what we PUBLISH?
#
# Not registered as a merge-gate required check — that list is owned by
# `.claude/hooks/require-review-before-merge.ts` and adding to it is a separate,
# deliberate decision.
on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
env:
# Secondary hedge for the mt#3623 install flake: disables the streaming
# tarball path implicated upstream (oven-sh/bun#34821). The per-step retry
# loop remains the load-bearing mitigation. Remove both when a bun release
# carries the upstream fix (mt#3835 tracks the retirement).
BUN_FEATURE_FLAG_DISABLE_STREAMING_INSTALL: "1"
jobs:
npm-pack-install-smoke:
name: npm-pack-install-smoke
runs-on: ubuntu-latest
services:
postgres:
# pgvector-enabled image, matching cold-start-migrate.yml — the schema uses the
# `vector` type and the bootstrap snapshot runs CREATE EXTENSION IF NOT EXISTS vector.
image: pgvector/pgvector:pg16
env:
POSTGRES_USER: minsky_test
POSTGRES_PASSWORD: minsky_test
POSTGRES_DB: minsky_pack_smoke
ports:
- 5432:5432
options: >-
--health-cmd pg_isready
--health-interval 5s
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@v4
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: "1.3.14"
# `npm pack` and the publish workflow both run on npm's CLI; pin the same
# Node major `publish-npm.yml` uses so the packed artifact matches.
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "24"
- name: Cache Bun install
uses: actions/cache@v4
with:
path: $HOME/.bun/install/cache
key: bun-install-${{ runner.os }}-${{ hashFiles('bun.lock', 'services/reviewer/bun.lock') }}
restore-keys: |
bun-install-${{ runner.os }}-
- name: Install dependencies
run: for i in 1 2 3; do if bun install --frozen-lockfile --no-progress; then break; fi; if [ "$i" = 3 ]; then exit 1; fi; echo "bun install failed (mt#3623 tarball flake) - retry $i"; sleep 5; done
# The script asserts the bundle is present rather than building it, so a
# stale-bundle failure reads as a stale bundle instead of an install failure.
- name: Build production bundle
run: bun run build
- name: Pack, install, and run the published artifact
env:
# mt#3887: enables step 4b (migration falsifier). Composed from parts, same
# convention as cold-start-migrate.yml, to avoid gitleaks flagging a literal URL.
DATABASE_URL: ${{ format('postgres://{0}:{1}@{2}:5432/{3}', 'minsky_test', 'minsky_test', 'localhost', 'minsky_pack_smoke') }}
run: bun scripts/verify-npm-pack-install.ts