Skip to content

docs: LAUNCH-PRS.md — directory submission drafts (user submits manua… #3

docs: LAUNCH-PRS.md — directory submission drafts (user submits manua…

docs: LAUNCH-PRS.md — directory submission drafts (user submits manua… #3

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
test:
name: ${{ matrix.os }} / Node ${{ matrix.node }}
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
# Mac-Pilot is macOS-only at runtime, but the build/unit tests are
# platform-agnostic. Running across macOS versions catches Node ABI
# drift in better-sqlite3 prebuilds and Buffer API regressions.
os: [macos-13, macos-14, macos-15]
node: ['20', '22']
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node }}
cache: npm
- name: Install
run: npm ci
- name: Build
run: npm run build
- name: Test
run: npm test
security-audit:
name: npm audit (critical)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
# Only `critical` fails the build. Several `high` advisories live in
# transitive deps of @modelcontextprotocol/sdk (hono, path-to-regexp)
# that we cannot patch ourselves — they ship from upstream. We track
# them in `docs/SECURITY-MODEL.md#known-transitive-cves` and re-evaluate
# whenever the SDK publishes. Bumping the SDK is the only fix path.
- run: npm audit --audit-level=critical