Skip to content

chore(deps): bump @clack/prompts from 0.8.2 to 1.7.0 #362

chore(deps): bump @clack/prompts from 0.8.2 to 1.7.0

chore(deps): bump @clack/prompts from 0.8.2 to 1.7.0 #362

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
lint-and-typecheck:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '24'
cache: 'npm'
- run: npm ci
- name: Generate Prisma client
working-directory: apps/api
run: npx prisma generate
- run: npx turbo lint
- run: npx turbo typecheck
test-shared:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '24'
cache: 'npm'
- run: npm ci
- run: npx turbo test --filter=@sidclaw/shared
# The SDK is the published artifact and was previously only BUILT in CI,
# never tested — its suite (incl. the fail-closed governance guards) had no
# automated enforcement, so a revert would have kept CI green.
test-sdk:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '24'
cache: 'npm'
- run: npm ci
# The mcp-proxy CLI suite spawns dist/bin/sidclaw-mcp-proxy.cjs, but
# turbo's `test` task declares dependsOn ["^build"] — that is upstream
# dependencies only, not the package's own build. Without this step the
# CLI tests fail on a fresh checkout while passing on any machine that
# happens to have a stale dist/ lying around.
- run: npx turbo build --filter=@sidclaw/sdk
- run: npx turbo test --filter=@sidclaw/sdk
# The Claude Code hooks are the governance gate for zero-code installs and
# ship via curl | node. There was no Python job in CI at all.
test-hooks:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.11'
- run: pip install pytest
- run: python -m pytest tests/ -q
working-directory: hooks
test-api:
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: agent_identity_test
POSTGRES_USER: agent_identity
POSTGRES_PASSWORD: agent_identity
ports:
- 5433:5432
options: >-
--health-cmd "pg_isready -U agent_identity"
--health-interval 5s
--health-timeout 3s
--health-retries 5
env:
DATABASE_URL: postgresql://agent_identity:agent_identity@localhost:5433/agent_identity_test
NODE_ENV: test
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '24'
cache: 'npm'
- run: npm ci
- name: Generate Prisma client
working-directory: apps/api
run: npx prisma generate
- name: Build dependencies
run: npx turbo build --filter=@sidclaw/shared --filter=@sidclaw/sdk
- name: Run Prisma migrations on test database
working-directory: apps/api
run: npx prisma migrate deploy
- name: Run API tests
run: npx turbo test --filter=@sidclaw/api
build:
runs-on: ubuntu-latest
needs: [lint-and-typecheck, test-shared, test-api]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '24'
cache: 'npm'
- run: npm ci
- name: Generate Prisma client
working-directory: apps/api
run: npx prisma generate
- run: npx turbo build
# Browser E2E suite: nightly in browser-tests.yml (~30 min sequential, too
# heavy per-PR). Re-enabled 2026-07-29 after fixing the dev-login redirect
# that had broken its auth setup.
verify-sdk-package:
runs-on: ubuntu-latest
needs: [lint-and-typecheck, test-shared, test-api]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '24'
cache: 'npm'
- run: npm ci
- name: Build SDK
run: npx turbo build --filter=@sidclaw/sdk
- name: Verify package contents
working-directory: packages/sdk
run: |
npm pack --dry-run
# Verify dist exists and has expected files
test -f dist/index.js
test -f dist/index.cjs
test -f dist/index.d.ts
test -f dist/mcp/index.js
test -f dist/webhooks/index.js
test -f README.md
test -f LICENSE
- name: Verify bundle size
working-directory: packages/sdk
run: |
SIZE=$(du -sb dist/ | cut -f1)
echo "Bundle size: $SIZE bytes"
if [ $SIZE -gt 250000 ]; then
echo "ERROR: Bundle size exceeds 250KB"
exit 1
fi
# ── Production-artifact checks ────────────────────────────────────────────
#
# Everything above validates SOURCE inside a complete workspace. Production
# builds a SUBSET of workspaces into an image whose package manifests are
# rewritten by the Dockerfile. Nothing exercised that second environment, and
# on 2026-07-28 two independent outages came from the gap within 20 minutes:
#
# 1. apps/api/Dockerfile rewrote packages/shared's exports map to a single
# '.' entry, silently dropping the './scopes' subpath. The import
# typechecked, built, and passed all 11 checks, then threw
# ERR_PACKAGE_PATH_NOT_EXPORTED at container start. API 502 for 13 min.
# 2. packages/sdk's dts build needs @modelcontextprotocol/sdk types but
# declared it only as an optional peer; it resolved because a sibling
# workspace hoisted it. The demo Dockerfiles do not copy that manifest,
# so their builds broke while CI stayed green.
#
# Job 1 catches build-time breaks like (2). Job 2 catches runtime breaks like
# (1) — building the image is not enough, the container has to actually boot.
docker-images:
name: docker-images (${{ matrix.image.name }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
image:
- { name: api, file: apps/api/Dockerfile }
- { name: dashboard, file: apps/dashboard/Dockerfile }
- { name: docs, file: apps/docs/Dockerfile }
- { name: landing, file: apps/landing/Dockerfile }
- { name: demo-atlas, file: apps/demo/Dockerfile }
- { name: demo-devops, file: apps/demo-devops/Dockerfile }
- { name: demo-healthcare, file: apps/demo-healthcare/Dockerfile }
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Build ${{ matrix.image.name }} image
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
with:
context: .
file: ${{ matrix.image.file }}
push: false
load: false
cache-from: type=gha,scope=${{ matrix.image.name }}
cache-to: type=gha,mode=max,scope=${{ matrix.image.name }}
api-container-boots:
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: agent_identity_test
POSTGRES_USER: agent_identity
POSTGRES_PASSWORD: agent_identity
ports:
- 5433:5432
options: >-
--health-cmd "pg_isready -U agent_identity"
--health-interval 5s
--health-timeout 3s
--health-retries 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Build the API image locally
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
with:
context: .
file: apps/api/Dockerfile
push: false
load: true
tags: sidclaw-api:ci
cache-from: type=gha,scope=api
- name: Boot the container
run: |
# NODE_ENV=production deliberately: the point is to exercise the
# production boot path, which fails fast on missing config
# (server.ts:17-33). SESSION_SECRET must be >=32 chars, and
# PUBLIC_API_URL is mandatory because /tenant/info embeds it —
# deriving it from headers under trustProxy would be a
# host-header-injection primitive. Throwaway values; this container
# is destroyed with the runner.
docker run -d --name api-ci --network host \
-e DATABASE_URL="postgresql://agent_identity:agent_identity@localhost:5433/agent_identity_test" \
-e NODE_ENV=production \
-e PORT=4000 \
-e SESSION_SECRET="ci-smoke-test-session-secret-not-a-real-secret-0123456789" \
-e PUBLIC_API_URL="http://localhost:4000" \
sidclaw-api:ci
- name: Wait for /health
run: |
# The container runs `prisma migrate deploy` before starting the
# server, which takes ~15s on a fresh database, so it is legitimately
# not listening for a while. Ask docker for the container's actual
# state rather than inferring death from `docker ps` — an earlier
# version of this step used `docker ps -q -f name=...` and reported
# a crash while the container was still applying migrations.
for i in $(seq 1 60); do
code=$(curl -s -o /dev/null -w '%{http_code}' http://localhost:4000/health || echo 000)
if [ "$code" = "200" ]; then
echo "Container healthy after ${i} attempt(s) (~$((i * 3))s):"
curl -s http://localhost:4000/health
echo
exit 0
fi
state=$(docker inspect -f '{{.State.Status}}' api-ci 2>/dev/null || echo missing)
case "$state" in
exited|dead|missing)
echo "::error::API container is '$state' before becoming healthy"
docker inspect -f 'exit code: {{.State.ExitCode}}' api-ci 2>/dev/null || true
docker logs api-ci 2>&1 | tail -60
exit 1
;;
esac
sleep 3
done
echo "::error::API container never became healthy within 180s (last state: $state)"
docker logs api-ci 2>&1 | tail -60
exit 1
- name: Container logs
if: always()
run: docker logs api-ci 2>&1 | tail -40