From 3783824bd4143621e05916d81e852edab2964ecc Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 23 Sep 2026 21:34:14 +0000 Subject: [PATCH 01/14] deps: bump vitest from 5.0.0 to 5.0.1 in the vitest group Bumps the vitest group with 1 update: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest). Updates `vitest` from 5.0.0 to 5.0.1 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 5.0.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vitest ... Signed-off-by: dependabot[bot] --- package-lock.json | 182 +++++++++++++++++++++++----------------------- 1 file changed, 91 insertions(+), 91 deletions(-) diff --git a/package-lock.json b/package-lock.json index bc3fe59..ac4e93d 100644 --- a/package-lock.json +++ b/package-lock.json @@ -586,9 +586,9 @@ "license": "MIT" }, "node_modules/@oxc-project/types": { - "version": "0.149.0", - "resolved": "https://registry.npmjs.org/@oxc-project/types/-/types-0.149.0.tgz", - "integrity": "sha512-Efcc+iF0j3Bf67YjEqIqWXbX5XddXoK/Mw4K1/JuXwRCZ8N16VR7iT23nlCc9XrveFVh/E5Rqs2StT0V8v9LdA==", + "version": "0.150.0", + "resolved": "https://registry.npmjs.org/@oxc-project/types/-/types-0.150.0.tgz", + "integrity": "sha512-rDS5/31E9HfPl/CIzGrn0DOlvBbXFseQ5URJ9sYMfstbKLD/c6Gm9vmRzRGDdAXyOIL4zmO37lc9RIwYqVruZw==", "dev": true, "license": "MIT", "peer": true, @@ -597,9 +597,9 @@ } }, "node_modules/@rolldown/binding-android-arm-eabi": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.8.tgz", - "integrity": "sha512-tN5aztYkKCte4i5SIrrz5yK/HMjEuCqCSCJa418jOV8tZ1cBY3YF2otxB1ktPxzsLA1BeTqwapK0bfjxNvHJVw==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.9.tgz", + "integrity": "sha512-tNISae1QEf/vkb3xkRcjV5SEdzPE97We5IVaa2Z8jSszQPZ8U60B/YCYpw4QI7VidYsBtKavczXf+DyDs9WGxw==", "cpu": [ "arm" ], @@ -615,9 +615,9 @@ } }, "node_modules/@rolldown/binding-android-arm64": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.8.tgz", - "integrity": "sha512-dIYTWl9XprMUiQFoc55KUyk/oS8SKYH3zFl0LTR7RT0Xj4hgSVyuJcroH8JUu8RcpF8fTB6E0aOwCkZoYPcDSQ==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.9.tgz", + "integrity": "sha512-YC8YsI30o606GTZi0VyzYlsDKFP8W61i/QzayHDkLbNEz/IShqAmTa+hsJRj13xTHA0H+6fk4b2UmGn+Q/cMlg==", "cpu": [ "arm64" ], @@ -633,9 +633,9 @@ } }, "node_modules/@rolldown/binding-darwin-arm64": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.8.tgz", - "integrity": "sha512-PCSDQGXD2IyTEFrcgPyBM8jJuGmrbCMuoIOXdbEGVemruKACXoLQJrb+A45Z0L5t1RQkdfJprAYPkikbh7dzdA==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.9.tgz", + "integrity": "sha512-IwhlH3qK5urrY8hZiEgGkHKEFN901p/p2bjxCxJlr4GyNnF7wYpUvK+Y43uaRYuC4hpfjzbR3SJC3arX1jGvmw==", "cpu": [ "arm64" ], @@ -651,9 +651,9 @@ } }, "node_modules/@rolldown/binding-darwin-x64": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.8.tgz", - "integrity": "sha512-Uk7lRsGhPFHVX/sAUC6D5H9Ol30dFHd6iquokll2th3LpdJ3F5CzQB+7DHn0Ri2mG+U7k2zXiPHDrwZenXhwSA==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.9.tgz", + "integrity": "sha512-XxpJfVzFh+jilRxIXUqcfYAYcunIc/XEzIizsOL1fcJee5Sf7H3mH8WlLmfHfluz5amqR88QQo9izKtmMlavAw==", "cpu": [ "x64" ], @@ -669,9 +669,9 @@ } }, "node_modules/@rolldown/binding-freebsd-x64": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.8.tgz", - "integrity": "sha512-DjszaTEVogPqA5bYzsEeqDCQxbcp2fexQwKcRspYji2yzR68fCf+e4fx6kBSRDwX5/brZaHw/hWS9+A/+/w9sQ==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.9.tgz", + "integrity": "sha512-kSfvhmgeWyfkbT3p/1s5vSgboogoah2zkm9fX2zjg2hHxSV7T4KhMWRUUaRk4OXNqoD3QAUeRqLcs1aZOK4U1g==", "cpu": [ "x64" ], @@ -687,9 +687,9 @@ } }, "node_modules/@rolldown/binding-linux-arm-gnueabihf": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.8.tgz", - "integrity": "sha512-zmwa7FTmdzB6aaEEuuls18H6Ap5JmJPSoPTuXixeJZV6tG40SyLkApQtz1g8ptZtiEKqj9OM0oNLPh1AgvE31Q==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.9.tgz", + "integrity": "sha512-1RVzG17pxqbTfYLC352JlLt6kKLG+6Hr30n8DlIJqsnV5luUDd2Qdx9Ayw1Cabfyb1K9k0jXEZ7evxkRoT+uiw==", "cpu": [ "arm" ], @@ -705,9 +705,9 @@ } }, "node_modules/@rolldown/binding-linux-arm64-gnu": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.8.tgz", - "integrity": "sha512-KdYQDPHwJVnbFwdTGMgxsI9SqblBlz6STGM+w1We/d5B8OWWidYH0MwkU/uA1wM5fIpO2MkOVxXrNzzuZhw9ew==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.9.tgz", + "integrity": "sha512-BXqPvZ2drqVD+/Z8UpKwcs4Mp7grM+eGFku4CAEKrEtcbAsUpzREphK1sogCRZGreVPiMkiiBtw0n3TPteuqvw==", "cpu": [ "arm64" ], @@ -726,9 +726,9 @@ } }, "node_modules/@rolldown/binding-linux-arm64-musl": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.8.tgz", - "integrity": "sha512-jFJTifHnNPY+yzOoNZQfSIysrVyXzEQPhPnOUjmD1bcQGHH6s7c8cViKWar8YplQImE5N9JRqMCLrM2CdxOrZA==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.9.tgz", + "integrity": "sha512-11vWvo8YDwLzukt27J3aYDWU+gg2P7J+ZOmiJ0hkF5BXZDW7pVya7r40MXDy6ya0i9KamoENSVKIugvJNgFXIA==", "cpu": [ "arm64" ], @@ -747,9 +747,9 @@ } }, "node_modules/@rolldown/binding-linux-ppc64-gnu": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.8.tgz", - "integrity": "sha512-FhiOziBDWPBjbcmRzfLyIJnaP7AVMFXT7YCXPjXxj7wKU3vx24RjrCNN/zjvVa+N2vVoHJwCoUBvsrN/DG3zIA==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.9.tgz", + "integrity": "sha512-a1tijMkdwsIARtc0F39ApURROkf3NwqinI6TOiSSWCTR7dT96dffNvMUtDHnq64wKNTIZOIlzKrFvvFUznJiyw==", "cpu": [ "ppc64" ], @@ -768,9 +768,9 @@ } }, "node_modules/@rolldown/binding-linux-s390x-gnu": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.8.tgz", - "integrity": "sha512-WnHfADMzOV2Y55wlx1hzzQnar/wDt/VdvWSD99r18Mz9ylNieIGOkRx3UV21h7m/eJvjySYJkO26VvGNFkwsIQ==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.9.tgz", + "integrity": "sha512-x6SQNdAvv4c3hWqTMaWuawzMX9myaCs/yEmlGsxJzkdClnHW7FbrjQuSiRDhuSYzEYoEMhsaJy9qHG/XNemJPQ==", "cpu": [ "s390x" ], @@ -808,9 +808,9 @@ } }, "node_modules/@rolldown/binding-linux-x64-musl": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.8.tgz", - "integrity": "sha512-UefiqfM3D6IVNlZ8tSGs9+Ejjud2T+oxO0IHADU45Y+lyEjD2dVFyZHbkfX0LUb5Zugo/oIv1eCO/KVYhgYJYA==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.9.tgz", + "integrity": "sha512-P7VWAmV+WdJluH7ovnRGoiv2i8To7GAZ+kGzfGup635cyL7SyYl3lSUaA3Gp5THf0n/Co5EyEqb2zbqq+nMOHQ==", "cpu": [ "x64" ], @@ -829,9 +829,9 @@ } }, "node_modules/@rolldown/binding-openharmony-arm64": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.8.tgz", - "integrity": "sha512-637Ke4kWSy6rp9cxQ9gMOXlxPgIw/c1beASV4M//3+9I4uwBVOOl74G+e3zyU3u19U7RkRl/HuewixZ/Z6+Rjg==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.9.tgz", + "integrity": "sha512-1qixtsE4BK8h+yS3BfmZ09UhA7O/N4IACva6YBr7EBvCJraByTuRcgOTaiA62Tm0vey3UcKXLOaoGHtYmNGEVg==", "cpu": [ "arm64" ], @@ -847,9 +847,9 @@ } }, "node_modules/@rolldown/binding-win32-arm64-msvc": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.8.tgz", - "integrity": "sha512-xWBkPOF1Q9k/Gv1nQXnVdLxKu74jXppuOM4Z3mnypVUJJJwLsMl7hNJGRAUJoG8A5MgOI1ACKM+wBFxSJzKy4A==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.9.tgz", + "integrity": "sha512-ok8IQjcEPs1AKZfuEUznVBrJw+gK4soq+bx8b1X2XoMqVClarc1q5JDmVtWXY1xfr6ZuHTAsPXHTgTrqKTZeww==", "cpu": [ "arm64" ], @@ -865,9 +865,9 @@ } }, "node_modules/@rolldown/binding-win32-x64-msvc": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.8.tgz", - "integrity": "sha512-uz2ZvfgXbxqNwijjjbxrnvALwpyODDcgc1T1N8N3rf/DXKQmaFwmB4LX4yyjggpwN2obdQLb2rgirX5ffCWYng==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.9.tgz", + "integrity": "sha512-Ip2mXoU0hM0boq3Rf+ekuT653OROSo6aSYcPT1VHE4q52KvyxgFkQgrgb/IEsxOuvQ2fZZbs8khJAyCEPM24/g==", "cpu": [ "x64" ], @@ -993,9 +993,9 @@ "license": "MIT" }, "node_modules/@vitest/coverage-v8": { - "version": "5.0.0", - "resolved": "https://registry.npmjs.org/@vitest/coverage-v8/-/coverage-v8-5.0.0.tgz", - "integrity": "sha512-toMg6PZGCIa/lQNCDoASrfb1ly4hsUKXFtFYC9kD4t78o5Y6LyNJU7AENt8eHPr3quYdxaxK7hj2mnbFfUk9NA==", + "version": "5.0.1", + "resolved": "https://registry.npmjs.org/@vitest/coverage-v8/-/coverage-v8-5.0.1.tgz", + "integrity": "sha512-FRC8ACiudC3dI6MTplzRSYWHDRnIv2IPfbzs4FdoJNsMal/35sWV8hwIfV8ZcqzSPy+uXHeMVONt9CEqtOU17w==", "dev": true, "license": "MIT", "dependencies": { @@ -1012,8 +1012,8 @@ "url": "https://opencollective.com/vitest" }, "peerDependencies": { - "@vitest/browser": "5.0.0", - "vitest": "5.0.0" + "@vitest/browser": "5.0.1", + "vitest": "5.0.1" }, "peerDependenciesMeta": { "@vitest/browser": { @@ -1045,14 +1045,14 @@ } }, "node_modules/@vitest/mocker": { - "version": "5.0.0", - "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-5.0.0.tgz", - "integrity": "sha512-66PGTMIiVJP3t4a5yxU9qPtf7MdTBs8jmToMvy+HVflB3Yy13WJZTtPePdvU+wjRV02SKK5doLbSA6o9pwOmiA==", + "version": "5.0.1", + "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-5.0.1.tgz", + "integrity": "sha512-6K1DoBNAPGvuOcSsGA4D6x+5zEEff/KmOOP3uetT2TrGpVfI+HRHRnJJfKi5ib/g1vx8IYHQD8s0pbJz8WQI7Q==", "dev": true, "license": "MIT", "dependencies": { "@jridgewell/trace-mapping": "0.3.31", - "@vitest/spy": "5.0.0", + "@vitest/spy": "5.0.1", "estree-walker": "^3.0.3", "magic-string": "^1.2.3" }, @@ -1073,9 +1073,9 @@ } }, "node_modules/@vitest/spy": { - "version": "5.0.0", - "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-5.0.0.tgz", - "integrity": "sha512-uy+luWBAPw9XfthoHi5AkfHUnuPYEESjl0p/r+meoBnU8bxg5GDQ3Ey8MjcJ6sqahkL4PFyrvfMJJBw7LbU06g==", + "version": "5.0.1", + "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-5.0.1.tgz", + "integrity": "sha512-rbto/mF/SGERxEgYOek7Xm6B9b+y+mVoo+f4b2LymYO8zM1b7uB5nHuhVMTP2hxdzgxvGiZYGxGIaMvL5y180Q==", "dev": true, "license": "MIT", "funding": { @@ -2337,9 +2337,9 @@ } }, "node_modules/magic-string": { - "version": "1.3.1", - "resolved": "https://registry.npmjs.org/magic-string/-/magic-string-1.3.1.tgz", - "integrity": "sha512-rm91zr2Ou+XueDTohjQQjdQEcYM6zVi8KVUCG8Ec3vHwUEKrhSdCNyfuIywkA6hcCAteIn0ZOtAHA6eGpiX+Pg==", + "version": "1.4.1", + "resolved": "https://registry.npmjs.org/magic-string/-/magic-string-1.4.1.tgz", + "integrity": "sha512-8lyCu36ErXR0J9uaGKlKQoiLZKmtI63YGLE8G2o9jyRPdr4X47LusSOwgOJOzcVtp81fTAAjxR7BwKz682Jhow==", "dev": true, "license": "MIT", "dependencies": { @@ -3621,14 +3621,14 @@ } }, "node_modules/rolldown": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/rolldown/-/rolldown-1.2.8.tgz", - "integrity": "sha512-Z67nTmhZe7anqnM/EjI392w5i/ANUinjip7QYsOyN37oayduxt3ksdX0hf5OOamkAd53BiIHfbfSzfUmzKFQqQ==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/rolldown/-/rolldown-1.2.9.tgz", + "integrity": "sha512-hx/Pv0N1haXRb11qkfnK5MXB/iqr7i0yjWQqmO9uHqZpBgQSqzc8UsSnEpalsh+j1I8qQ2CkXAkJC8Br3dKSlg==", "dev": true, "license": "MIT", "peer": true, "dependencies": { - "@oxc-project/types": "=0.149.0", + "@oxc-project/types": "=0.150.0", "@rolldown/pluginutils": "^1.0.0" }, "bin": { @@ -3638,27 +3638,27 @@ "node": "^20.19.0 || >=22.12.0" }, "optionalDependencies": { - "@rolldown/binding-android-arm-eabi": "1.2.8", - "@rolldown/binding-android-arm64": "1.2.8", - "@rolldown/binding-darwin-arm64": "1.2.8", - "@rolldown/binding-darwin-x64": "1.2.8", - "@rolldown/binding-freebsd-x64": "1.2.8", - "@rolldown/binding-linux-arm-gnueabihf": "1.2.8", - "@rolldown/binding-linux-arm64-gnu": "1.2.8", - "@rolldown/binding-linux-arm64-musl": "1.2.8", - "@rolldown/binding-linux-ppc64-gnu": "1.2.8", - "@rolldown/binding-linux-s390x-gnu": "1.2.8", - "@rolldown/binding-linux-x64-gnu": "1.2.8", - "@rolldown/binding-linux-x64-musl": "1.2.8", - "@rolldown/binding-openharmony-arm64": "1.2.8", - "@rolldown/binding-win32-arm64-msvc": "1.2.8", - "@rolldown/binding-win32-x64-msvc": "1.2.8" + "@rolldown/binding-android-arm-eabi": "1.2.9", + "@rolldown/binding-android-arm64": "1.2.9", + "@rolldown/binding-darwin-arm64": "1.2.9", + "@rolldown/binding-darwin-x64": "1.2.9", + "@rolldown/binding-freebsd-x64": "1.2.9", + "@rolldown/binding-linux-arm-gnueabihf": "1.2.9", + "@rolldown/binding-linux-arm64-gnu": "1.2.9", + "@rolldown/binding-linux-arm64-musl": "1.2.9", + "@rolldown/binding-linux-ppc64-gnu": "1.2.9", + "@rolldown/binding-linux-s390x-gnu": "1.2.9", + "@rolldown/binding-linux-x64-gnu": "1.2.9", + "@rolldown/binding-linux-x64-musl": "1.2.9", + "@rolldown/binding-openharmony-arm64": "1.2.9", + "@rolldown/binding-win32-arm64-msvc": "1.2.9", + "@rolldown/binding-win32-x64-msvc": "1.2.9" } }, "node_modules/rolldown/node_modules/@rolldown/binding-linux-x64-gnu": { - "version": "1.2.8", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.8.tgz", - "integrity": "sha512-H9tRr5ibfXFVLxbPOseVewewFpl28zcEdjRDt2FTUZU7odxP0gEv1ki4/kGmcGOh78oRwZuuQllGLZ9zTJp84g==", + "version": "1.2.9", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.9.tgz", + "integrity": "sha512-9s0AZ8BFK5/n7B/TBoa2yJE3gI3KURrbXcPBlsAsvjU4VeJKgE90y1YtNxyEUIcHPQkg6/yfF3qihUrcM/Kf0Q==", "cpu": [ "x64" ], @@ -4059,14 +4059,14 @@ } }, "node_modules/vitest": { - "version": "5.0.0", - "resolved": "https://registry.npmjs.org/vitest/-/vitest-5.0.0.tgz", - "integrity": "sha512-gpsMNoRhMjMktVxPtstOH4/PJuPyovVaMDr4oDilXaGH1EcqM2OE96SoHT2VIQ6fTGtTjqmHDrEu2X9RQiXf8Q==", + "version": "5.0.1", + "resolved": "https://registry.npmjs.org/vitest/-/vitest-5.0.1.tgz", + "integrity": "sha512-iA95lQbKEkvrtTkdAgnWbXfbipWiiWe/hDl2P5tMi6WFwD76G0NxXAGp/M9EOcYupeGJRr6wppMc7CoA41TQjg==", "dev": true, "license": "MIT", "dependencies": { "@types/chai": "^5.2.2", - "@vitest/mocker": "5.0.0", + "@vitest/mocker": "5.0.1", "chai": "^6.2.2", "es-module-lexer": "^2.3.2", "expect-type": "^1.4.0", @@ -4092,12 +4092,12 @@ "@edge-runtime/vm": "*", "@opentelemetry/api": "^1.9.0", "@types/node": "^22.0.0 || >=24.0.0", - "@vitest/browser-playwright": "5.0.0", - "@vitest/browser-preview": "5.0.0", + "@vitest/browser-playwright": "5.0.1", + "@vitest/browser-preview": "5.0.1", "@vitest/browser-webdriverio": "^5.0.0-beta.5 || >=5.0.0", - "@vitest/coverage-istanbul": "5.0.0", - "@vitest/coverage-v8": "5.0.0", - "@vitest/ui": "5.0.0", + "@vitest/coverage-istanbul": "5.0.1", + "@vitest/coverage-v8": "5.0.1", + "@vitest/ui": "5.0.1", "happy-dom": "*", "jsdom": "*", "vite": "^6.4.0 || ^7.0.0 || ^8.0.0" From f0e872dd73095897f8701016b5d7428f09df7cdd Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 23 Sep 2026 21:34:20 +0000 Subject: [PATCH 02/14] deps: bump eslint from 10.10.0 to 10.11.0 in the eslint group Bumps the eslint group with 1 update: [eslint](https://github.com/eslint/eslint). Updates `eslint` from 10.10.0 to 10.11.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.10.0...v10.11.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.11.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: eslint ... Signed-off-by: dependabot[bot] --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index bc3fe59..3b8e5c6 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1515,9 +1515,9 @@ } }, "node_modules/eslint": { - "version": "10.10.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.10.0.tgz", - "integrity": "sha512-NPXn6r5zl4uET1DAVPaOwzX3rut4c0wcmw3dWJAfOsTM5+TogXo0DDjz8pwm/hL8cyVNpHqeK4JpN0NjnyFFNw==", + "version": "10.11.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.11.0.tgz", + "integrity": "sha512-P7a6UEEqb9G95MYAtqkmsTbVXIYyzIfl6NGOIJk162PaahFxFyeGcrlXYFSiagECg4sEm8IseJdZBKR3rx6MsQ==", "dev": true, "license": "MIT", "workspaces": [ From ebed26fc9211ac107bc84925a20147c7b0b24187 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 23 Sep 2026 21:34:26 +0000 Subject: [PATCH 03/14] deps: bump prettier from 3.9.6 to 3.9.8 in the prettier group Bumps the prettier group with 1 update: [prettier](https://github.com/prettier/prettier). Updates `prettier` from 3.9.6 to 3.9.8 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](https://github.com/prettier/prettier/compare/3.9.6...3.9.8) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: prettier ... Signed-off-by: dependabot[bot] --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index bc3fe59..df62c84 100644 --- a/package-lock.json +++ b/package-lock.json @@ -3566,9 +3566,9 @@ } }, "node_modules/prettier": { - "version": "3.9.6", - "resolved": "https://registry.npmjs.org/prettier/-/prettier-3.9.6.tgz", - "integrity": "sha512-OpN0zzVdiaiAhxpuuj5efpIS4sY9j7bY6uR5mnj5yPzGkdkjNKSJeUThPb60Jw29QuAZgA4o+/iB49kFiaBX6g==", + "version": "3.9.8", + "resolved": "https://registry.npmjs.org/prettier/-/prettier-3.9.8.tgz", + "integrity": "sha512-WRFq3Wn3WId7LLROfMLdH7xaFr2jR62wU8nLO6rQUOLOxNZUviyJQs1M0iIhLexSFy+L+w0ch66wtoO2jRjG0A==", "dev": true, "license": "MIT", "bin": { From bcdb2beccf355ccdf8ee371d62535dfcc58a9926 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 23 Sep 2026 21:35:03 +0000 Subject: [PATCH 04/14] deps: bump @cldmv/slothlet from 3.15.3 to 3.17.0 in the minor group Bumps the minor group with 1 update: [@cldmv/slothlet](https://github.com/CLDMV/slothlet). Updates `@cldmv/slothlet` from 3.15.3 to 3.17.0 - [Release notes](https://github.com/CLDMV/slothlet/releases) - [Commits](https://github.com/CLDMV/slothlet/compare/@cldmv/slothlet-i18n@3.15.3...@cldmv/slothlet-i18n@3.17.0) --- updated-dependencies: - dependency-name: "@cldmv/slothlet" dependency-version: 3.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor ... Signed-off-by: dependabot[bot] --- package-lock.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index bc3fe59..8b9a046 100644 --- a/package-lock.json +++ b/package-lock.json @@ -173,15 +173,15 @@ } }, "node_modules/@cldmv/slothlet": { - "version": "3.15.3", - "resolved": "https://registry.npmjs.org/@cldmv/slothlet/-/slothlet-3.15.3.tgz", - "integrity": "sha512-no/G0qEObp9MOlwbpUpR0CKCv3KwkWp2ZujHjvG5Y2XNOQL/hgNnk7PyXrpm5JVDKox1DB3IetbCHWx388zG/w==", + "version": "3.17.0", + "resolved": "https://registry.npmjs.org/@cldmv/slothlet/-/slothlet-3.17.0.tgz", + "integrity": "sha512-rOpJZBPbhDBr3CRG2bjRvlIrw6VTMmnXi8z7CyGHaVK1+AJc0PEh1CKEumsZSxK8WON0za/gh5g5QGCwdbV59A==", "license": "Apache-2.0", "bin": { "slothlet": "bin/slothlet.mjs" }, "engines": { - "node": ">=22.0.0" + "node": ">=22.12.0" }, "funding": { "type": "github", @@ -194,7 +194,7 @@ "@cldmv/slothlet-i18n": "^3.11.0", "@cldmv/slothlet-types": "^3.11.0", "esbuild": "^0.28.0", - "typescript": "^6.0.3" + "typescript": "^6.0.3 || ^7.0.0" }, "peerDependenciesMeta": { "@cldmv/slothlet-i18n": { From 08583a9a6ec4182d463aa02acb3930e71d55923a Mon Sep 17 00:00:00 2001 From: "cldmv-bot[bot]" <230771808+cldmv-bot[bot]@users.noreply.github.com> Date: Wed, 23 Sep 2026 21:37:52 +0000 Subject: [PATCH 05/14] chore: bump version to 1.1.10 --- package-lock.json | 4 ++-- package.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index fb533a9..e779116 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@cldmv/git-embedded", - "version": "1.1.9", + "version": "1.1.10", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@cldmv/git-embedded", - "version": "1.1.9", + "version": "1.1.10", "license": "Apache-2.0", "dependencies": { "@cldmv/slothlet": "^3.7.0", diff --git a/package.json b/package.json index 8c07588..dd97f98 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@cldmv/git-embedded", - "version": "1.1.9", + "version": "1.1.10", "description": "Manage embedded git repositories (anonymous gitlinks) without .gitmodules. Provides hooks that restore standard git-command ergonomics for embedded children while keeping the child's origin URL out of the public parent repo.", "type": "module", "license": "Apache-2.0", From ad1379ccd7ad951ea915664da3978745a33fbe90 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 27 Sep 2026 12:39:59 -0700 Subject: [PATCH 06/14] chore: restore the verbatim Apache-2.0 license text The LICENSE file's section 6 (Trademarks) was missing the words "reasonable and customary use in", so it was not the Apache License 2.0 the package declares. Replace it with the verbatim text from https://www.apache.org/licenses/LICENSE-2.0.txt, unchanged since the license was published in January 2004. --- LICENSE | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/LICENSE b/LICENSE index e7273c3..d645695 100644 --- a/LICENSE +++ b/LICENSE @@ -1,3 +1,4 @@ + Apache License Version 2.0, January 2004 http://www.apache.org/licenses/ @@ -137,8 +138,8 @@ 6. Trademarks. This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, - except as required for describing the origin of the Work and - reproducing the content of the NOTICE file. + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. 7. Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each @@ -186,7 +187,7 @@ same "printed page" as the copyright notice for easier identification within third-party archives. - Copyright 2026 CLDMV + Copyright [yyyy] [name of copyright owner] Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. From 54ba05974f9bcbbd599f5488edd8e9a031f52db3 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 27 Sep 2026 12:52:17 -0700 Subject: [PATCH 07/14] ci: sync v4 workflows with CLDMV/.github v4.29.0 templates MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Rebuild every .github/workflows/*.yml and .github/dependabot.yml against the current CLDMV/.github v4.29.0 templates (repo header + template body), and add the standard workflows this repo was missing: dependabot-recreate.yml, member-auto-merge.yml, pr-notify.yml, provenance.yml, release-merge.yml. Notable template-side changes picked up: - Per-job `permissions:` blocks replacing workflow-level grants across branch-retention, ci, cla, codeql, dependabot-auto-merge, feature-pr, hotfixes-release, hotfix-redirector, next-release, next-reset, pr-title-normalizer, publish, scorecard, tag-health, update-major-version-tags. - ci.yml / publish.yml: `max_node_major` now defaults to blank (inherit the reusable's default) instead of a hardcoded "26" pin; LTS-only matrix comment updated to include Node 20. - ci.yml: new lint/format autofix inputs (format_command, lint_fix_command, lint_command, format_check_command). - ci.yml / hotfixes-release.yml / next-release.yml: build_command switched from a hardcoded `echo` to `npm run build:ci` (the repo's build:ci script is itself that same no-op echo, so behavior is unchanged). - master-commit-audit.yml: now a thin caller into reusable-master-commit-audit.yml@v4 instead of inlining the create-app-token + audit-commit-subject steps. - codeql.yml / dependency-review.yml: added the private-repo CLDMV_SKIP_CODE_SCANNING / CLDMV_SKIP_DEPENDENCY_REVIEW documentation. - v4-bootstrap.yml: added the `variables` bootstrap phase + `code_scanning_config` input. - feature-pr.yml: added `deps/**` to the auto-PR branch-prefix set. Repo-specific customizations re-applied on top of the synced templates: - ci.yml: skip_type_check: true (git-embedded's dynamic slothlet-composed API has no meaningful static type surface), with its explanatory comment. - dependabot-auto-merge.yml: merge_method: "squash" (repo's deliberate choice, kept even though next/hotfixes rulesets currently narrow it to merge anyway). - dependabot.yml: the marked >=16 ignore rule for the npm ecosystem (marked-terminal@7.3.0 caps marked at <16; no newer marked-terminal release lifts it). release-merge.yml's workflows: list already matches this repo's ci.yml name (๐Ÿงช CI Tests & Build). provenance.yml's package_name is set to @cldmv/git-embedded; extra_packages left empty (no satellite packages). --- .github/dependabot.yml | 11 +- .github/workflows/branch-retention.yml | 24 +- .github/workflows/ci.yml | 598 +++++++++--------- .github/workflows/cla.yml | 40 +- .github/workflows/codeql.yml | 77 ++- .github/workflows/dependabot-auto-merge.yml | 34 +- .github/workflows/dependabot-recreate.yml | 63 ++ .github/workflows/dependency-review.yml | 42 +- .github/workflows/feature-pr.yml | 11 +- .github/workflows/hotfix-redirector.yml | 8 + .github/workflows/hotfixes-release.yml | 11 +- .github/workflows/labeler.yml | 22 +- .github/workflows/master-commit-audit.yml | 70 +- .github/workflows/member-auto-merge.yml | 71 +++ .github/workflows/next-release.yml | 11 +- .github/workflows/next-reset.yml | 27 +- .github/workflows/pr-notify.yml | 40 ++ .github/workflows/pr-title-normalizer.yml | 29 +- .github/workflows/provenance.yml | 47 ++ .github/workflows/publish.yml | 227 ++++--- .github/workflows/release-merge.yml | 74 +++ .github/workflows/release-notify.yml | 16 +- .github/workflows/scorecard.yml | 47 +- .github/workflows/stale.yml | 44 +- .github/workflows/tag-health.yml | 80 +-- .../workflows/update-major-version-tags.yml | 147 ++--- .github/workflows/v4-bootstrap.yml | 115 ++-- .github/workflows/welcome.yml | 26 +- 28 files changed, 1213 insertions(+), 799 deletions(-) create mode 100644 .github/workflows/dependabot-recreate.yml create mode 100644 .github/workflows/member-auto-merge.yml create mode 100644 .github/workflows/pr-notify.yml create mode 100644 .github/workflows/provenance.yml create mode 100644 .github/workflows/release-merge.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index fb38120..936330a 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -80,10 +80,13 @@ updates: versions: [">=16"] groups: # vitest and @vitest/coverage-v8 (and other @vitest/* packages) peer - # each other exactly, so bumping one without the other breaks - # `npm ci` with an ERESOLVE. Bump the whole family together in one - # PR. Must come before security/patch/minor below โ€” Dependabot - # assigns each update to the FIRST matching group. + # each other EXACTLY, so a partial bump (e.g. vitest to 5.0.0 while + # @vitest/coverage-v8 stays 4.1.11) breaks `npm ci` with an ERESOLVE. + # Bump the whole family together in one PR so the exact-peer + # versions never diverge. Must come before security/patch/minor + # below โ€” Dependabot assigns each update to the FIRST matching + # group, and this one has no applies-to restriction so it always + # wins for vitest-family packages regardless of update type. vitest: patterns: - "vitest" diff --git a/.github/workflows/branch-retention.yml b/.github/workflows/branch-retention.yml index 3353ff9..fd6c51f 100644 --- a/.github/workflows/branch-retention.yml +++ b/.github/workflows/branch-retention.yml @@ -21,18 +21,20 @@ name: ๐ŸŒฟ Branch Retention on: - pull_request: - types: [closed] - branches: [master, main, next, hotfixes] + pull_request: + types: [closed] + branches: [master, main, next, hotfixes] permissions: - contents: write - pull-requests: read + contents: read jobs: - retain: - if: github.event.pull_request.merged == true - uses: CLDMV/.github/.github/workflows/reusable-branch-retention.yml@v4 - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + retain: + permissions: + contents: write + pull-requests: read + if: github.event.pull_request.merged == true + uses: CLDMV/.github/.github/workflows/reusable-branch-retention.yml@v4 + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4216d35..1ebf523 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,125 +11,146 @@ name: ๐Ÿงช CI Tests & Build on: - # Note: do NOT add `paths:` / `paths-ignore:` at the trigger level. Doing - # that makes GitHub skip the workflow entirely for docs-only changes, which - # means `Required PR Check` never posts and the ruleset blocks the merge. - # The reusable workflow's `paths-gate` job does the same job from inside, - # and exposes a `docs_only` output so this workflow can still green-light - # the required check for docs-only PRs (see `required-check` below). The - # ignore globs themselves are passed via the `paths_ignore:` input below - # โ€” override there if your repo needs different rules. - # - # `push` fires for branches in this repo only (forks push to their own remote, - # not ours). Branch protection on the PR reads the status check from the - # commit SHA, so this single trigger covers both pre-PR pushes and PR head - # updates without duplicating runs. - push: - # Bot-managed branches (badges, gh-pages) carry no source to test. - branches-ignore: [badges, gh-pages] - # `pull_request` covers two cases: - # - Fork PRs (push doesn't fire upstream for fork commits). - # - Release PRs from `next` / `hotfixes` โ†’ `master`. Their head SHA is - # a bot `chore: bump version` commit that workflow-ci.yml's - # `commit-gate` job filters out on the push path, so without the - # pull_request fallback the release PR's `Required PR Check` - # status never gets posted and the ruleset blocks the merge. - # `branches:` includes the v4 integration branches so PRs targeting - # `next` / `hotfixes` get CI too โ€” feature PRs from forks would - # otherwise get nothing. Non-fork feature PRs still skip the - # pull_request `ci` job (push covers them); see the `if:` on the job. - pull_request: - types: [opened, synchronize, reopened, ready_for_review] - branches: [master, main, next, hotfixes] - workflow_dispatch: - inputs: - debug: - description: "Enable debug logging for troubleshooting" - type: boolean - required: false - default: false - node_version: - description: "Node.js version to use (default: lts/*)" - type: string - required: false - default: "lts/*" - min_node_version: - description: "Minimum Node.js version for matrix testing (default: 22.12.0 โ€” the floor vitest 5 actually runs on)" - type: string - required: false - default: "22.12.0" - max_node_major: - description: "Override max Node.js major version (default: 26)" - type: string - required: false - default: "26" - lts_only_matrix: - description: "Only include even-numbered (LTS) Node.js major versions in the test matrix" - type: boolean - required: false - default: true - package_manager: - description: "Package manager (npm or yarn)" - type: string - required: false - default: "npm" - test_environment: - description: "Environment for tests (affects NODE_ENV and NODE_OPTIONS --conditions flag)" - type: string - required: false - default: "development" - # โ”€โ”€ Coverage badge โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ - enable_coverage_badge: - description: "Run the coverage + badge-push job after CI passes" - type: boolean - required: false - default: true - coverage_command: - description: "Command to run tests and generate coverage data" - type: string - required: false - default: "npm run ci:coverage" - coverage_summary_path: - description: "Path to the coverage-summary.json produced by Jest / c8" - type: string - required: false - default: "coverage/coverage-summary.json" - badges_branch: - description: "Branch where the badge JSON is published" - type: string - required: false - default: "badges" - badge_filename: - description: "Filename for the badge JSON committed to the badges branch" - type: string - required: false - default: "coverage.json" - upload_coverage_artifact: - description: "Upload the full coverage/ directory as a workflow artifact" - type: boolean - required: false - default: true - # โ”€โ”€ Type check โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ - type_check_command: - description: "Command to run type checking" - type: string - required: false - default: "npm run test:types" - skip_type_check: - description: "Skip the type-check step in the coverage-badge job" - type: boolean - required: false - default: false - default_branch: - description: "Default branch name โ€” badge is only pushed on pushes to this branch" - type: string - required: false - default: "master" - enable_coverage_pr_comment: - description: "Inject a coverage badge into the PR description on pull request events" - type: boolean - required: false - default: true + # Note: do NOT add `paths:` / `paths-ignore:` at the trigger level. Doing + # that makes GitHub skip the workflow entirely for docs-only changes, which + # means `Required PR Check` never posts and the ruleset blocks the merge. + # The reusable workflow's `paths-gate` job does the same job from inside, + # and exposes a `docs_only` output so this workflow can still green-light + # the required check for docs-only PRs (see `required-check` below). The + # ignore globs themselves are passed via the `paths_ignore:` input below + # โ€” override there if your repo needs different rules. + # + # `push` fires for branches in this repo only (forks push to their own remote, + # not ours). Branch protection on the PR reads the status check from the + # commit SHA, so this single trigger covers both pre-PR pushes and PR head + # updates without duplicating runs. + push: + # Bot-managed branches (badges, gh-pages) carry no source to test. + branches-ignore: [badges, gh-pages] + # `pull_request` covers two cases: + # - Fork PRs (push doesn't fire upstream for fork commits). + # - Release PRs from `next` / `hotfixes` โ†’ `master`. Their head SHA is + # a bot `chore: bump version` commit that workflow-ci.yml's + # `commit-gate` job filters out on the push path, so without the + # pull_request fallback the release PR's `Required PR Check` + # status never gets posted and the ruleset blocks the merge. + # `branches:` includes the v4 integration branches so PRs targeting + # `next` / `hotfixes` get CI too โ€” feature PRs from forks would + # otherwise get nothing. Non-fork feature PRs still skip the + # pull_request `ci` job (push covers them); see the `if:` on the job. + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + branches: [master, main, next, hotfixes] + workflow_dispatch: + inputs: + debug: + description: "Enable debug logging for troubleshooting" + type: boolean + required: false + default: false + node_version: + description: "Node.js version to use (default: lts/*)" + type: string + required: false + default: "lts/*" + min_node_version: + description: "Minimum Node.js version for matrix testing (default: 22.12.0 โ€” the floor vitest 5 actually runs on)" + type: string + required: false + default: "22.12.0" + max_node_major: + description: "Max Node.js major version for the test matrix. Leave blank (the default) to inherit the CLDMV/.github reusable workflow's default; set a value only to pin/override for a specific run." + type: string + required: false + default: "" + lts_only_matrix: + description: "Only include even-numbered (LTS) Node.js major versions in the test matrix" + type: boolean + required: false + default: true + package_manager: + description: "Package manager (npm or yarn)" + type: string + required: false + default: "npm" + test_environment: + description: "Environment for tests (affects NODE_ENV and NODE_OPTIONS --conditions flag)" + type: string + required: false + default: "development" + # โ”€โ”€ Lint & format (autofix) โ€” all default to `--if-present` (no-op when absent) + format_command: + description: "Formatter that writes fixes (prettier --write)" + type: string + required: false + default: "npm run format --if-present" + lint_fix_command: + description: "Linter that writes safe fixes (eslint --fix)" + type: string + required: false + default: "npm run lint:fix --if-present" + lint_command: + description: "Lint check (no writes) โ€” the authoritative lint gate" + type: string + required: false + default: "npm run lint --if-present" + format_check_command: + description: "Format check (no writes) โ€” used on fork / integration branches" + type: string + required: false + default: "npm run format:check --if-present" + # โ”€โ”€ Coverage badge โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ + enable_coverage_badge: + description: "Run the coverage + badge-push job after CI passes" + type: boolean + required: false + default: true + coverage_command: + description: "Command to run tests and generate coverage data" + type: string + required: false + default: "npm run ci:coverage" + coverage_summary_path: + description: "Path to the coverage-summary.json produced by Jest / c8" + type: string + required: false + default: "coverage/coverage-summary.json" + badges_branch: + description: "Branch where the badge JSON is published" + type: string + required: false + default: "badges" + badge_filename: + description: "Filename for the badge JSON committed to the badges branch" + type: string + required: false + default: "coverage.json" + upload_coverage_artifact: + description: "Upload the full coverage/ directory as a workflow artifact" + type: boolean + required: false + default: true + # โ”€โ”€ Type check โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ + type_check_command: + description: "Command to run type checking" + type: string + required: false + default: "npm run test:types" + skip_type_check: + description: "Skip the type-check step in the coverage-badge job" + type: boolean + required: false + default: false + default_branch: + description: "Default branch name โ€” badge is only pushed on pushes to this branch" + type: string + required: false + default: "master" + enable_coverage_pr_comment: + description: "Inject a coverage badge into the PR description on pull request events" + type: boolean + required: false + default: true # Concurrency policy, by context: # - FEATURE branches / feature PRs โ†’ cancel superseded runs (per-ref group + @@ -150,8 +171,8 @@ on: # is set only on pull_request (the release PR's head โ†’ next/hotfixes); # github.ref carries the branch on push. concurrency: - group: ci-${{ github.workflow }}-${{ github.ref }}${{ (github.ref == format('refs/heads/{0}', vars.CLDMV_RELEASE_BASE != '' && vars.CLDMV_RELEASE_BASE || github.event.repository.default_branch) || github.ref == 'refs/heads/next' || github.ref == 'refs/heads/hotfixes' || github.head_ref == 'next' || github.head_ref == 'hotfixes') && format('-{0}', github.run_id) || '' }} - cancel-in-progress: true + group: ci-${{ github.workflow }}-${{ github.ref }}${{ (github.ref == format('refs/heads/{0}', vars.CLDMV_RELEASE_BASE != '' && vars.CLDMV_RELEASE_BASE || github.event.repository.default_branch) || github.ref == 'refs/heads/next' || github.ref == 'refs/heads/hotfixes' || github.head_ref == 'next' || github.head_ref == 'hotfixes') && format('-{0}', github.run_id) || '' }} + cancel-in-progress: true # Workflow-level: matches the broadest write surface the called # `workflow-ci.yml` reaches across its branches: @@ -161,171 +182,184 @@ concurrency: # inherit but never exercise the surface. The mirror job overrides to # `permissions: {}` since it's pure shell. permissions: - contents: write - pull-requests: write + contents: read jobs: - ci: - name: ๐Ÿ—๏ธ Continuous Integration - # Run on pull_request when: - # - The PR is from a fork (push doesn't fire upstream for fork commits). - # - The PR is a v4 release PR โ€” head ref is `next` or `hotfixes` - # targeting `master`/`main`. Push-event CI on the head SHA is - # unreliable for these because workflow-ci.yml's `commit-gate` - # filters out the bot's `chore: bump version` commit, so without - # this fallback the release PR's `Required PR Check` never posts. - # Other (in-repo, non-release) PRs skip โ€” the push event on the head - # branch already ran CI and posted status to the SHA. - if: | - github.event_name != 'pull_request' || - github.event.pull_request.head.repo.fork == true || - github.event.pull_request.head.ref == 'next' || - github.event.pull_request.head.ref == 'hotfixes' - uses: CLDMV/.github/.github/workflows/workflow-ci.yml@v4 - with: - package_name: "@cldmv/git-embedded" # Required: replace with your NPM package name - # Globs that should NOT trigger the heavy CI matrix. When every changed - # file matches one of these, `docs_only=true` flows out of the reusable - # and `required-check` below posts a green Required PR Check without - # running CI. The default in the reusable matches these โ€” override only - # if your repo needs different rules. - paths_ignore: | - **.md - docs/** - *.md - LICENSE - .gitignore - debug: ${{ github.event.inputs.debug == 'true' }} - node_version: ${{ github.event.inputs.node_version || 'lts/*' }} - min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} - max_node_major: ${{ github.event.inputs.max_node_major || '26' }} - # LTS-only matrix (even majors: 22, 24, โ€ฆ) on every event. Odd majors - # (23, 25, โ€ฆ) are non-LTS interim releases, and the native-binding test - # toolchain (vitest 4 / rolldown / vite 8) excludes them via `engines` - # (`>=22.12.0`), so a "full matrix" on them only re-discovers a - # known toolchain gap ("Cannot find native binding") rather than a real - # per-version regression. workflow_dispatch can still opt out (set false). - lts_only_matrix: ${{ github.event.inputs.lts_only_matrix != 'false' }} - package_manager: ${{ github.event.inputs.package_manager || 'npm' }} - test_command: "npm test" # Use defaults: NODE_ENV=development, NODE_OPTIONS=--conditions=development - # test_command: "NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override NODE_OPTIONS only - # test_command: "NODE_ENV=test npm test" # Override NODE_ENV only - # test_command: "NODE_ENV=test NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override both - test_environment: ${{ github.event.inputs.test_environment || 'development' }} # Alternative to setting in test_command - build_command: "echo 'โœ“ no build step'" - skip_performance_tests: false - skip_matrix_tests: false + ci: + permissions: + contents: write + pull-requests: write + name: ๐Ÿ—๏ธ Continuous Integration + # Run on pull_request when: + # - The PR is from a fork (push doesn't fire upstream for fork commits). + # - The PR is a v4 release PR โ€” head ref is `next` or `hotfixes` + # targeting `master`/`main`. Push-event CI on the head SHA is + # unreliable for these because workflow-ci.yml's `commit-gate` + # filters out the bot's `chore: bump version` commit, so without + # this fallback the release PR's `Required PR Check` never posts. + # Other (in-repo, non-release) PRs skip โ€” the push event on the head + # branch already ran CI and posted status to the SHA. + if: | + github.event_name != 'pull_request' || + github.event.pull_request.head.repo.fork == true || + github.event.pull_request.head.ref == 'next' || + github.event.pull_request.head.ref == 'hotfixes' + uses: CLDMV/.github/.github/workflows/workflow-ci.yml@v4 + with: + package_name: "@cldmv/git-embedded" # Required: replace with your NPM package name + # Globs that should NOT trigger the heavy CI matrix. When every changed + # file matches one of these, `docs_only=true` flows out of the reusable + # and `required-check` below posts a green Required PR Check without + # running CI. The default in the reusable matches these โ€” override only + # if your repo needs different rules. + paths_ignore: | + **.md + docs/** + *.md + LICENSE + .gitignore + debug: ${{ github.event.inputs.debug == 'true' }} + node_version: ${{ github.event.inputs.node_version || 'lts/*' }} + min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} + max_node_major: ${{ github.event.inputs.max_node_major || '' }} # blank โ‡’ inherit the CLDMV/.github reusable default + # LTS-only matrix (even majors: 20, 22, 24, โ€ฆ) on every event. Odd majors + # (21, 23, โ€ฆ) are non-LTS interim releases, and the native-binding test + # toolchain (vitest 4 / rolldown / vite 8) excludes them via `engines` + # (`^20.19.0 || >=22.12.0`), so a "full matrix" on them only re-discovers a + # known toolchain gap ("Cannot find native binding") rather than a real + # per-version regression. workflow_dispatch can still opt out (set false). + lts_only_matrix: ${{ github.event.inputs.lts_only_matrix != 'false' }} + package_manager: ${{ github.event.inputs.package_manager || 'npm' }} + test_command: "npm test" # Use defaults: NODE_ENV=development, NODE_OPTIONS=--conditions=development + # test_command: "NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override NODE_OPTIONS only + # test_command: "NODE_ENV=test npm test" # Override NODE_ENV only + # test_command: "NODE_ENV=test NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override both + test_environment: ${{ github.event.inputs.test_environment || 'development' }} # Alternative to setting in test_command + # โ”€โ”€ Lint & format (autofix gate) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ + # The lint-format job applies safe fixes (prettier --write, eslint --fix) + # and commits them back on internal branches; on fork PRs / integration + # branches it runs the check variants and fails with a fix hint. Every + # command uses `--if-present`, so a repo with no such script is a graceful + # no-op. Add the scripts to package.json to opt in; override a command for + # a monorepo-aware invocation; or set empty ("") to disable that phase. + format_command: ${{ github.event.inputs.format_command || 'npm run format --if-present' }} + lint_fix_command: ${{ github.event.inputs.lint_fix_command || 'npm run lint:fix --if-present' }} + lint_command: ${{ github.event.inputs.lint_command || 'npm run lint --if-present' }} + format_check_command: ${{ github.event.inputs.format_check_command || 'npm run format:check --if-present' }} + build_command: "npm run build:ci" + skip_performance_tests: false + skip_matrix_tests: false - # โ”€โ”€ Coverage badge โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ - # Runs after a successful CI build; pushes a Shields.io-compatible badge - # JSON to the `badges` branch (signed commit via bot GPG). - # Only runs on direct pushes to default_branch โ€” PRs and feature branches - # are automatically skipped so coverage always reflects merged master code. - # Requires: the coverage_command produces coverage/coverage-summary.json - enable_coverage_badge: ${{ github.event.inputs.enable_coverage_badge != 'false' }} - default_branch: ${{ github.event.inputs.default_branch || 'master' }} # Badge only pushed when a push lands on this branch - coverage_command: ${{ github.event.inputs.coverage_command || 'npm run ci:coverage' }} - coverage_summary_path: ${{ github.event.inputs.coverage_summary_path || 'coverage/coverage-summary.json' }} - badges_branch: ${{ github.event.inputs.badges_branch || 'badges' }} - badge_filename: ${{ github.event.inputs.badge_filename || 'coverage.json' }} - upload_coverage_artifact: ${{ github.event.inputs.upload_coverage_artifact != 'false' }} + # โ”€โ”€ Coverage badge โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ + # Runs after a successful CI build; pushes a Shields.io-compatible badge + # JSON to the `badges` branch (signed commit via bot GPG). + # Only runs on direct pushes to default_branch โ€” PRs and feature branches + # are automatically skipped so coverage always reflects merged master code. + # Requires: the coverage_command produces coverage/coverage-summary.json + enable_coverage_badge: ${{ github.event.inputs.enable_coverage_badge != 'false' }} + default_branch: ${{ github.event.inputs.default_branch || 'master' }} # Badge only pushed when a push lands on this branch + coverage_command: ${{ github.event.inputs.coverage_command || 'npm run ci:coverage' }} + coverage_summary_path: ${{ github.event.inputs.coverage_summary_path || 'coverage/coverage-summary.json' }} + badges_branch: ${{ github.event.inputs.badges_branch || 'badges' }} + badge_filename: ${{ github.event.inputs.badge_filename || 'coverage.json' }} + upload_coverage_artifact: ${{ github.event.inputs.upload_coverage_artifact != 'false' }} - # โ”€โ”€ Type check (runs inside the coverage-badge job) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ - # Skipped deliberately: git-embedded is a dynamic slothlet-composed API - # (self.* / context.* resolved at runtime). tsc can't statically type that - # surface, slothlet's typegen only emits an all-`any` structural interface - # (no real types), and a checkJs pass is ~260 untypeable dynamic-API errors โ€” - # there is no meaningful JS type-check to run. ESLint is the static-analysis - # net. (Investigated 2026-07-19; revisit if the API gains real generated types.) - type_check_command: ${{ github.event.inputs.type_check_command || 'npm run test:types' }} - skip_type_check: true + # โ”€โ”€ Type check (runs inside the coverage-badge job) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ + # Skipped deliberately: git-embedded is a dynamic slothlet-composed API + # (self.* / context.* resolved at runtime). tsc can't statically type that + # surface, slothlet's typegen only emits an all-`any` structural interface + # (no real types), and a checkJs pass is ~260 untypeable dynamic-API errors โ€” + # there is no meaningful JS type-check to run. ESLint is the static-analysis + # net. (Investigated 2026-07-19; revisit if the API gains real generated types.) + type_check_command: ${{ github.event.inputs.type_check_command || 'npm run test:types' }} + skip_type_check: true - # โ”€โ”€ PR coverage badge โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ - # Injects a Shields.io badge + breakdown table directly into the PR body - # on every push to the PR branch. Only fires on pull_request events; - # skipped automatically on push and workflow_dispatch. No files committed. - enable_coverage_pr_comment: ${{ github.event.inputs.enable_coverage_pr_comment != 'false' }} + # โ”€โ”€ PR coverage badge โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ + # Injects a Shields.io badge + breakdown table directly into the PR body + # on every push to the PR branch. Only fires on pull_request events; + # skipped automatically on push and workflow_dispatch. No files committed. + enable_coverage_pr_comment: ${{ github.event.inputs.enable_coverage_pr_comment != 'false' }} - # Authentication & Bot Configuration - # The workflow supports automatic App token detection for enhanced permissions and proper attribution: - # - WITH App secrets: Operations attributed to CLDMV bot, enhanced permissions for workflow repositories - # - WITHOUT App secrets: Falls back to GitHub Actions bot with standard permissions - # Note: CI workflow currently only runs build/test jobs, but App secrets are included for consistency - # To set up App authentication, add these secrets to your repository settings: - secrets: - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} - # Optional: CLDMV Bot credentials for enhanced permissions and proper attribution - # If not provided, will use default GITHUB_TOKEN with GitHub Actions bot attribution - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - # Required when enable_coverage_badge: true - BOT_NAME: ${{ secrets.CLDMV_BOT_NAME }} - BOT_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} - BOT_GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} - BOT_GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} + # Authentication & Bot Configuration + # The workflow supports automatic App token detection for enhanced permissions and proper attribution: + # - WITH App secrets: Operations attributed to CLDMV bot, enhanced permissions for workflow repositories + # - WITHOUT App secrets: Falls back to GitHub Actions bot with standard permissions + # Note: CI workflow currently only runs build/test jobs, but App secrets are included for consistency + # To set up App authentication, add these secrets to your repository settings: + secrets: + NPM_TOKEN: ${{ secrets.NPM_TOKEN }} + # Optional: CLDMV Bot credentials for enhanced permissions and proper attribution + # If not provided, will use default GITHUB_TOKEN with GitHub Actions bot attribution + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + # Required when enable_coverage_badge: true + BOT_NAME: ${{ secrets.CLDMV_BOT_NAME }} + BOT_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} + BOT_GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} + BOT_GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} - # โœ… Stable check that mirrors the `ci` result so branch protection has a - # single, predictable status name to require. The push event runs on the - # same SHA that becomes the PR head, so the status attaches to the PR - # automatically โ€” no `pull_request` round-trip needed for non-fork - # non-release PRs. - required-check: - name: โœ… Required PR Check - needs: ci - # Mirror the `ci` job's gating exactly. The four cases that run: - # 1. push events (job needs CI run) - # 2. fork PRs (push doesn't cover forks) - # 3. release PRs from `next` โ†’ master/main (push covers SHA but commit-gate skips chore-bump) - # 4. release PRs from `hotfixes` โ†’ master/main (same reason) - # In-repo feature PRs targeting `next` / `hotfixes` skip on - # pull_request โ€” push on the head branch already posted the status - # on the SHA, and mirroring here would overwrite it. - if: | - always() && ( - github.event_name != 'pull_request' || - github.event.pull_request.head.repo.fork == true || - github.event.pull_request.head.ref == 'next' || - github.event.pull_request.head.ref == 'hotfixes' - ) - # Match the reusable's runner routing (workflow-ci.yml): private CLDMV - # repos run on self-hosted cldmv-runners (GitHub-hosted Actions budget is - # private-metered and exhausted), public repos use free GitHub-hosted, and - # RUNS_ON_DEFAULT overrides. Hardcoding ubuntu-latest here made this - # required check fail to provision a runner on private repos once the - # reusable moved its own jobs to cldmv-runners in v4.19.1 (see CLDMV/.github#208). - runs-on: ${{ vars.RUNS_ON_DEFAULT != '' && vars.RUNS_ON_DEFAULT || ((github.repository_owner == 'CLDMV' && github.event.repository.private) && 'cldmv-runners' || 'ubuntu-latest') }} - # Pure shell mirror โ€” no GitHub API access. Strip the workflow's - # write defaults to zero for this job. - permissions: {} - steps: - - name: Mirror reusable result - env: - IS_MASTER_SYNC: ${{ needs.ci.outputs.is_master_sync }} - DOCS_ONLY: ${{ needs.ci.outputs.docs_only }} - CI_RESULT: ${{ needs.ci.result }} - run: | - echo "ci.result=$CI_RESULT docs_only=$DOCS_ONLY is_master_sync=$IS_MASTER_SYNC" - # next/hotfixes was force-synced to master โ€” head SHA matches the - # default branch, nothing new to test, green-light without running CI. - if [ "$IS_MASTER_SYNC" = "true" ]; then - echo "Branch tip matches master โ€” Required PR Check passes without running CI." - exit 0 - fi - # Docs-only PR โ€” the reusable skipped the heavy chain and exported - # docs_only=true. Green-light Required PR Check so the ruleset - # doesn't block a docs change. - if [ "$DOCS_ONLY" = "true" ]; then - echo "Docs-only change โ€” Required PR Check passes without running CI." - exit 0 - fi - if [ "$CI_RESULT" = "success" ]; then - echo "Reusable CI passed." - exit 0 - elif [ "$CI_RESULT" = "failure" ] || [ "$CI_RESULT" = "cancelled" ]; then - echo "Reusable CI did not pass." - exit 1 - else - # covers 'skipped' or undefined; force red to avoid silent green - echo "Reusable CI produced no pass/fail; treating as failure." - exit 1 - fi + # โœ… Stable check that mirrors the `ci` result so branch protection has a + # single, predictable status name to require. The push event runs on the + # same SHA that becomes the PR head, so the status attaches to the PR + # automatically โ€” no `pull_request` round-trip needed for non-fork + # non-release PRs. + required-check: + name: โœ… Required PR Check + needs: ci + # Mirror the `ci` job's gating exactly. The four cases that run: + # 1. push events (job needs CI run) + # 2. fork PRs (push doesn't cover forks) + # 3. release PRs from `next` โ†’ master/main (push covers SHA but commit-gate skips chore-bump) + # 4. release PRs from `hotfixes` โ†’ master/main (same reason) + # In-repo feature PRs targeting `next` / `hotfixes` skip on + # pull_request โ€” push on the head branch already posted the status + # on the SHA, and mirroring here would overwrite it. + if: | + always() && ( + github.event_name != 'pull_request' || + github.event.pull_request.head.repo.fork == true || + github.event.pull_request.head.ref == 'next' || + github.event.pull_request.head.ref == 'hotfixes' + ) + # Match the reusable's runner routing (workflow-ci.yml): private CLDMV + # repos run on self-hosted cldmv-runners (GitHub-hosted Actions budget is + # private-metered and exhausted), public repos use free GitHub-hosted, and + # RUNS_ON_DEFAULT overrides. Hardcoding ubuntu-latest here made this + # required check fail to provision a runner on private repos once the + # reusable moved its own jobs to cldmv-runners in v4.19.1 (see #208). + runs-on: ${{ vars.RUNS_ON_DEFAULT != '' && vars.RUNS_ON_DEFAULT || ((github.repository_owner == 'CLDMV' && github.event.repository.private) && 'cldmv-runners' || 'ubuntu-latest') }} + # Pure shell mirror โ€” no GitHub API access. Strip the workflow's + # write defaults to zero for this job. + permissions: {} + steps: + - name: Mirror reusable result + env: + IS_MASTER_SYNC: ${{ needs.ci.outputs.is_master_sync }} + DOCS_ONLY: ${{ needs.ci.outputs.docs_only }} + CI_RESULT: ${{ needs.ci.result }} + run: | + echo "ci.result=$CI_RESULT docs_only=$DOCS_ONLY is_master_sync=$IS_MASTER_SYNC" + # next/hotfixes was force-synced to master โ€” head SHA matches the + # default branch, nothing new to test, green-light without running CI. + if [ "$IS_MASTER_SYNC" = "true" ]; then + echo "Branch tip matches master โ€” Required PR Check passes without running CI." + exit 0 + fi + # Docs-only PR โ€” the reusable skipped the heavy chain and exported + # docs_only=true. Green-light Required PR Check so the ruleset + # doesn't block a docs change. + if [ "$DOCS_ONLY" = "true" ]; then + echo "Docs-only change โ€” Required PR Check passes without running CI." + exit 0 + fi + if [ "$CI_RESULT" = "success" ]; then + echo "Reusable CI passed." + exit 0 + elif [ "$CI_RESULT" = "failure" ] || [ "$CI_RESULT" = "cancelled" ]; then + echo "Reusable CI did not pass." + exit 1 + else + # covers 'skipped' or undefined; force red to avoid silent green + echo "Reusable CI produced no pass/fail; treating as failure." + exit 1 + fi diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index 2a2a3d7..1b84f47 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -35,26 +35,28 @@ name: ๐Ÿ“œ CLA on: - pull_request_target: - types: [opened, synchronize, reopened, ready_for_review] - issue_comment: - types: [created] + pull_request_target: + types: [opened, synchronize, reopened, ready_for_review] + issue_comment: + types: [created] permissions: - contents: read - pull-requests: write - statuses: write - issues: write + contents: read jobs: - cla: - uses: CLDMV/.github/.github/workflows/reusable-cla.yml@v4 - with: - cla_version: "1.0" - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - CLA_BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_CLA_BOT_APP_CLIENT_ID }} - CLA_BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_CLA_BOT_APP_PRIVATE_KEY }} - TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} - TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} + cla: + permissions: + contents: read + pull-requests: write + statuses: write + issues: write + uses: CLDMV/.github/.github/workflows/reusable-cla.yml@v4 + with: + cla_version: "1.0" + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + CLA_BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_CLA_BOT_APP_CLIENT_ID }} + CLA_BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_CLA_BOT_APP_PRIVATE_KEY }} + TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} + TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index bca0380..1c705ed 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -9,6 +9,17 @@ # Individual repo: .github/workflows/codeql.yml # +# PRIVATE REPOS are skipped by DEFAULT: the bootstrap's `variables` phase +# sets CLDMV_SKIP_CODE_SCANNING (this workflow then uploads an empty 0-alert +# SARIF instead of analyzing) on every private repo not opted in, since Code +# Security bills per active committer there. To actually scan a private +# repo: pay for GitHub Code Security and add the repo to the `scan` list in +# data/code-scanning-skips.json in CLDMV/.github. Public repos scan by +# default (free); a public repo with nothing to analyze goes in that file's +# `skip` section. Consumers outside CLDMV can pass `skip_code_scanning: +# true` below instead. Do NOT just delete this file on a repo whose ruleset +# requires code_scanning โ€” the gate then waits forever. +# # REQUIRED REPO SETTING โ€” CodeQL must be in "Advanced" mode for this workflow # to upload SARIF. If the repo has CodeQL "Default setup" enabled (the # GitHub-managed alternative), upload runs fail with: @@ -30,41 +41,43 @@ name: ๐Ÿ” CodeQL on: - push: - branches: [master, main] - # Same fork-PR consideration as ci.yml: pull_request fires for forks; SARIF - # upload to base-repo Security tab fails with read-only token. Acceptable โ€” - # push-to-master analysis after merge catches anything missed. DO NOT use - # pull_request_target (runs base-repo workflow with secrets against fork - # code; dangerous). - pull_request: - types: [opened, synchronize, reopened, ready_for_review] - # Include the v4 integration branches (`next`, `hotfixes`) so feature - # and hotfix PRs trigger CodeQL. Without these, branch protection - # rulesets that require the CodeQL check on `next`/`hotfixes` will - # sit on "waiting for results" indefinitely. Branches that don't - # exist in a given repo simply never trigger the workflow โ€” harmless - # for repos that haven't adopted the v4 staging-branch flow. - branches: [master, main, next, hotfixes] - schedule: - - cron: "37 14 * * 1" # weekly Monday 14:37 UTC; GitHub updates queries over time + push: + branches: [master, main] + # Same fork-PR consideration as ci.yml: pull_request fires for forks; SARIF + # upload to base-repo Security tab fails with read-only token. Acceptable โ€” + # push-to-master analysis after merge catches anything missed. DO NOT use + # pull_request_target (runs base-repo workflow with secrets against fork + # code; dangerous). + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + # Include the v4 integration branches (`next`, `hotfixes`) so feature + # and hotfix PRs trigger CodeQL. Without these, branch protection + # rulesets that require the CodeQL check on `next`/`hotfixes` will + # sit on "waiting for results" indefinitely. Branches that don't + # exist in a given repo simply never trigger the workflow โ€” harmless + # for repos that haven't adopted the v4 staging-branch flow. + branches: [master, main, next, hotfixes] + schedule: + - cron: "37 14 * * 1" # weekly Monday 14:37 UTC; GitHub updates queries over time permissions: - security-events: write - contents: read - actions: read + contents: read concurrency: - group: codeql-${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: ${{ github.ref != 'refs/heads/master' && github.ref != 'refs/heads/main' }} + group: codeql-${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.ref != 'refs/heads/master' && github.ref != 'refs/heads/main' }} jobs: - analyze: - uses: CLDMV/.github/.github/workflows/reusable-codeql.yml@v4 - with: - languages: "javascript-typescript" - # Override defaults if needed: - # queries: "security-extended,security-and-quality" - # paths_ignore: "node_modules/,dist/,coverage/,**/test/**" - # config_file: ".github/codeql-config.yml" - # build_mode: "autobuild" + analyze: + permissions: + security-events: write + contents: read + actions: read + uses: CLDMV/.github/.github/workflows/reusable-codeql.yml@v4 + with: + languages: "javascript-typescript" + # Override defaults if needed: + # queries: "security-extended,security-and-quality" + # paths_ignore: "node_modules/,dist/,coverage/,**/test/**" + # config_file: ".github/codeql-config.yml" + # build_mode: "autobuild" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 0ec8bef..b5a35e6 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -33,22 +33,26 @@ name: ๐Ÿค– Dependabot Auto-Merge on: - pull_request: - types: [opened, reopened, synchronize, ready_for_review] + pull_request: + types: [opened, reopened, synchronize, ready_for_review] permissions: - contents: write - pull-requests: write + contents: read jobs: - automerge: - # Pre-filter at workflow level so this doesn't spin up for every PR. - if: github.event.pull_request.user.login == 'dependabot[bot]' - uses: CLDMV/.github/.github/workflows/reusable-dependabot-auto-merge.yml@v4 - with: - bump_types: "patch,minor" - merge_method: "squash" - # also_for_actors: "renovate[bot]" # extend if you adopt Renovate - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + automerge: + permissions: + contents: write + pull-requests: write + # Pre-filter at workflow level so this doesn't spin up for every PR. + if: github.event.pull_request.user.login == 'dependabot[bot]' + uses: CLDMV/.github/.github/workflows/reusable-dependabot-auto-merge.yml@v4 + with: + bump_types: "patch,minor" + # merge_method defaults to "merge" โ€” Dependabot PRs target next / hotfixes, + # whose rulesets are merge-only. Override only if your branches differ. + merge_method: "squash" + # also_for_actors: "renovate[bot]" # extend if you adopt Renovate + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/dependabot-recreate.yml b/.github/workflows/dependabot-recreate.yml new file mode 100644 index 0000000..12ca937 --- /dev/null +++ b/.github/workflows/dependabot-recreate.yml @@ -0,0 +1,63 @@ +# +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/dependabot-recreate.yml +# @Date: 2026-07-31 00:00:00 -07:00 (1785481200) +# @Author: Nate Corcoran +# @Email: +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# + +# Individual repo: .github/workflows/dependabot-recreate.yml +# +# Auto-fires `@dependabot recreate` when a Dependabot PR gets stuck in the +# "edited by someone other than Dependabot" state. That state breaks +# `@dependabot rebase` and โ€” under a required-signed-commits ruleset โ€” blocks +# the PR with an unsigned commit. `recreate` rebuilds it as a fresh, signed +# Dependabot commit that dependabot-auto-merge.yml then merges. See +# reusable-dependabot-recreate.yml for the mechanics + the command-actor caveat. +# +# Default in v4: ON. Delete this file to opt out entirely; add a `no-recreate` +# label to a specific PR to exempt just that one (e.g. one you've hand-edited +# on purpose and don't want overwritten). +# +# Triggers: +# - issue_comment: catches Dependabot's own "can't rebase, use recreate" reply +# (Dependabot only comments back when a rebase FAILS โ€” success is a silent +# ๐Ÿ‘ + force-push). +# - pull_request_target: proactive net for a Dependabot PR whose head commit +# is unverified. pull_request_target (not pull_request) is required so the +# job can read the bot-App secrets โ€” Dependabot-triggered `pull_request` +# runs get a read-only token and no secrets. It is SAFE here: Dependabot PRs +# are same-repo branches (not forks), and this workflow never checks out or +# runs PR code โ€” it only reads the PR and posts a comment via the API. +name: ๐Ÿ” Dependabot Auto-Recreate + +on: + issue_comment: + types: [created] + pull_request_target: + types: [opened, synchronize, reopened] + +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + recreate: + # A) Dependabot replied that it can't rebase (the PR was edited), or + # B) a Dependabot PR opened/updated โ€” the reusable then checks whether + # its head commit is actually unverified before doing anything. + if: >- + (github.event_name == 'issue_comment' + && github.event.issue.pull_request + && github.event.comment.user.login == 'dependabot[bot]' + && contains(github.event.comment.body, 'edited by someone other than Dependabot')) + || (github.event_name == 'pull_request_target' + && github.event.pull_request.user.login == 'dependabot[bot]') + uses: CLDMV/.github/.github/workflows/reusable-dependabot-recreate.yml@v4 + with: + skip_label: "no-recreate" + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index efd3d5a..72227a5 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -8,27 +8,35 @@ # # Individual repo: .github/workflows/dependency-review.yml +# +# PRIVATE REPOS are skipped by DEFAULT (the dependency-review API needs +# GitHub Advanced Security there): the bootstrap's `variables` phase sets +# CLDMV_SKIP_DEPENDENCY_REVIEW on every private repo not opted into the +# `scan` list in data/code-scanning-skips.json in CLDMV/.github. To run the +# review on a private repo, pay for Code Security and add it to that list. +# Consumers outside CLDMV can pass `skip_dependency_review: true` below +# instead. name: ๐Ÿ”’ Dependency Review on: - pull_request: - types: [opened, synchronize, reopened, ready_for_review] - branches: [master, main] + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + branches: [master, main] permissions: - contents: read - pull-requests: write + contents: read + pull-requests: write jobs: - review: - uses: CLDMV/.github/.github/workflows/reusable-dependency-review.yml@v4 - with: - fail_on_severity: "moderate" - # Per-repo license policy override: - # deny_licenses: "AGPL-3.0,LGPL-3.0" # block copyleft for an Apache-2.0 repo - # Bot App credentials. When set, the dependency-review PR comment is - # posted by the consumer's bot App instead of github-actions[bot]. - # Both lines are optional; remove them to fall back to GITHUB_TOKEN. - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + review: + uses: CLDMV/.github/.github/workflows/reusable-dependency-review.yml@v4 + with: + fail_on_severity: "moderate" + # Per-repo license policy override: + # deny_licenses: "AGPL-3.0,LGPL-3.0" # block copyleft for an Apache-2.0 repo + # Bot App credentials. When set, the dependency-review PR comment is + # posted by the consumer's bot App instead of github-actions[bot]. + # Both lines are optional; remove them to fall back to GITHUB_TOKEN. + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/feature-pr.yml b/.github/workflows/feature-pr.yml index 150a294..903ab09 100644 --- a/.github/workflows/feature-pr.yml +++ b/.github/workflows/feature-pr.yml @@ -12,7 +12,7 @@ # right integration branch on every push. # # Mapping (matches CLDMV/.github docs/conventions/branch-naming.md): -# feat/*, feature/*, fix/*, release/*, chore/*, refactor/*, +# feat/*, feature/*, fix/*, release/*, chore/*, deps/*, refactor/*, # docs/*, ci/*, perf/*, test/*, style/* โ†’ next # hotfix/* โ†’ hotfixes # @@ -35,6 +35,7 @@ on: - 'fix/**' - 'release/**' - 'chore/**' + - 'deps/**' - 'refactor/**' - 'docs/**' - 'ci/**' @@ -47,6 +48,9 @@ concurrency: group: feature-pr-${{ github.repository }}-${{ github.ref }} cancel-in-progress: false +permissions: + contents: read + jobs: open-pr: permissions: @@ -57,5 +61,10 @@ jobs: # Map your repo/org secrets to the expected names. BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + # Optional: only needed if you also use reusable-lint-format.yml / + # reusable-coverage-badge.yml (or otherwise sign a commit locally as + # this identity). Passed through so this PR's changelog body + # recognizes that identity as a bot instead of listing it as a + # contributor. BOT_NAME: ${{ secrets.CLDMV_BOT_NAME }} BOT_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} diff --git a/.github/workflows/hotfix-redirector.yml b/.github/workflows/hotfix-redirector.yml index 9ff0443..b257393 100644 --- a/.github/workflows/hotfix-redirector.yml +++ b/.github/workflows/hotfix-redirector.yml @@ -39,6 +39,9 @@ concurrency: group: hotfix-redirector-${{ github.event.pull_request.number }} cancel-in-progress: true +permissions: + contents: read + jobs: redirect: permissions: @@ -49,6 +52,11 @@ jobs: # Map your repo/org secrets to the expected names. BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + # GPG signing identity โ€” REQUIRED if this repo redirects Dependabot + # SECURITY PRs: that path cherry-picks a commit onto `hotfixes`, and + # an unsigned commit is silently blocked by required-signatures (no + # failing check names the cause). The commit is signed and authored as + # this real-user bot account (the GPG key's owner), not the App bot. BOT_NAME: ${{ secrets.CLDMV_BOT_NAME }} BOT_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} BOT_GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} diff --git a/.github/workflows/hotfixes-release.yml b/.github/workflows/hotfixes-release.yml index 7f7afa2..97c069a 100644 --- a/.github/workflows/hotfixes-release.yml +++ b/.github/workflows/hotfixes-release.yml @@ -31,6 +31,9 @@ concurrency: group: hotfixes-release-${{ github.repository }} cancel-in-progress: false +permissions: + contents: read + jobs: release: permissions: @@ -39,11 +42,17 @@ jobs: uses: CLDMV/.github/.github/workflows/workflow-hotfixes-release.yml@v4 with: package_name: "@cldmv/git-embedded" - build_command: "echo 'โœ“ no build step'" + build_command: "npm run build:ci" secrets: # Map your repo/org secrets to the expected names. BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + # Optional: only needed if you also use reusable-lint-format.yml / + # reusable-coverage-badge.yml (or otherwise sign a commit locally as + # this identity). Passed through so the release-PR changelog + # recognizes that identity as a bot instead of listing it as a + # contributor โ€” see CLDMV_BOT_NAME/CLDMV_BOT_EMAIL in your other + # workflows for the same values. BOT_NAME: ${{ secrets.CLDMV_BOT_NAME }} BOT_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} # Optional release-PR notifier webhooks โ€” each is independently diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml index 340e9af..72cbbbc 100644 --- a/.github/workflows/labeler.yml +++ b/.github/workflows/labeler.yml @@ -27,18 +27,18 @@ name: ๐Ÿท๏ธ PR Labeler # DO NOT add a checkout step or any step that executes PR-supplied content # (build commands, scripts, test runs, etc.) to this workflow. on: - pull_request_target: - types: [opened, synchronize, reopened, ready_for_review] + pull_request_target: + types: [opened, synchronize, reopened, ready_for_review] permissions: - contents: read - pull-requests: write + contents: read + pull-requests: write jobs: - label: - uses: CLDMV/.github/.github/workflows/reusable-pr-labeler.yml@v4 - # Optional. Without these, labels are attributed to github-actions[bot]. - # With these, they're attributed to your CLDMV bot App. - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + label: + uses: CLDMV/.github/.github/workflows/reusable-pr-labeler.yml@v4 + # Optional. Without these, labels are attributed to github-actions[bot]. + # With these, they're attributed to your CLDMV bot App. + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/master-commit-audit.yml b/.github/workflows/master-commit-audit.yml index c6f50f7..e6447a7 100644 --- a/.github/workflows/master-commit-audit.yml +++ b/.github/workflows/master-commit-audit.yml @@ -10,57 +10,43 @@ # Individual repo: .github/workflows/master-commit-audit.yml # # Post-merge safety net: when any commit lands on the default branch, verify -# its subject matches the expected release-flow patterns. On miss, auto-file -# a GitHub Issue (deduped by SHA) so the alert is persistent and assignable -# โ€” not just a red โŒ that dies in inbox. +# its subject matches the expected release-flow patterns. On miss, auto-file a +# GitHub Issue (deduped by SHA) so the alert is persistent and assignable โ€” +# not just a red โŒ that dies in inbox. # # Catches: release-workflow title-generation regressions, branch-protection # bypasses, unexpected bot commits, direct emergency pushes. # -# Batch 5.1 from tmp/plan-future-workflows.md. +# Thin caller: steps, the action ref, and the canonical commit-subject pattern +# set all live in reusable-master-commit-audit.yml@v4 (the patterns come from +# the audit-commit-subject action's default). Nothing here can drift. name: ๐Ÿงพ Master Commit Audit on: - push: - branches: [master, main] + push: + branches: [master, main] permissions: - contents: read - issues: write + contents: read + issues: write jobs: - audit: - runs-on: ubuntu-latest - steps: - # Optional. Without these, the audit issue is filed by - # github-actions[bot]. With them, the issue is filed by your bot App. - - name: Create App token (falls back to GITHUB_TOKEN) - id: app-token - uses: CLDMV/.github/.github/actions/github/steps/create-app-token@v4 + audit: + uses: CLDMV/.github/.github/workflows/reusable-master-commit-audit.yml@v4 with: - client_id: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - private_key: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - env: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - - - name: Audit commit subject - uses: CLDMV/.github/.github/actions/git/jobs/audit-commit-subject@v4 - with: - commit_sha: ${{ github.sha }} - # allowed_patterns omitted -> inherit the canonical default from - # audit-commit-subject (release/chore/merge patterns, including - # the "release: vX.Y.Z - " form). Customize only if - # this repo's conventions genuinely differ โ€” a hardcoded copy - # here goes stale the next time the canonical default changes. - # allowed_patterns: | - # ^release: v\d+\.\d+\.\d+( - .+?)?( \(#\d+\))?$ - # ^chore(\([^)]+\))?: .+ - # ^Merge pull request #\d+ from .+ - # ^feat(\([^)]+\))?: .+ - # Canonical label names from CLDMV/.github's data/github-labels.json - # (note the space after each colon). Replace with names that exist - # in your repo's label catalog. - issue_labels: "type: ci,priority: high" - # issue_assignee: "shinrai" # uncomment to auto-assign - github_token: ${{ steps.app-token.outputs.token }} + # allowed_patterns omitted โ†’ inherit the canonical default + # (release + chore + merge). Uncomment ONLY if this repo lands other + # commit shapes directly on the default branch: + # allowed_patterns: | + # ^release: v\d+\.\d+\.\d+( - .+?)?( \(#\d+\))?$ + # ^chore(\([^)]+\))?: .+ + # ^Merge pull request #\d+ from .+ + # ^feat(\([^)]+\))?: .+ + issue_labels: "type: ci,priority: high" + # issue_assignee: "shinrai" # uncomment to auto-assign + # Optional bot App credentials โ€” when set, the audit issue is filed by + # the consumer's bot App instead of github-actions[bot]. Remove both + # lines to fall back to GITHUB_TOKEN. + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/member-auto-merge.yml b/.github/workflows/member-auto-merge.yml new file mode 100644 index 0000000..edd5334 --- /dev/null +++ b/.github/workflows/member-auto-merge.yml @@ -0,0 +1,71 @@ +# +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/member-auto-merge.yml +# @Date: 2026-05-28 00:00:00 -07:00 (1780210800) +# @Author: Nate Corcoran +# @Email: +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# + +# Individual repo: .github/workflows/member-auto-merge.yml +# +# Auto-enables GitHub's "auto-merge" flag on PRs opened by org members +# against `next` or `hotfixes`, scoped to the standard branch-prefix +# conventions (feat/, fix/, hotfix/, chore/, โ€ฆ). Removes the per-PR +# friction of clicking "Enable auto-merge" โ€” the merge still waits for +# the ruleset's prerequisites (required approvals + CI green). +# +# This does NOT approve the PR. The human-review gate stays intact โ€” +# unlike `dependabot-auto-merge.yml` which bot-approves Dependabot bumps. +# +# Default in v4: ON. To opt out, delete this file โ€” member PRs still +# require a manual "Enable auto-merge" click but otherwise work normally. +# +# Required setup (one-time per repo, both done by `v4-bootstrap.yml`): +# 1. Settings โ†’ Pull Requests โ†’ "Allow auto-merge" โ†’ ON +# 2. A ruleset on next/hotfixes with required status checks AND a +# required-approving-review count โ‰ฅ 1 (the default v4 rulesets do +# both). The action refuses to enable auto-merge on a branch +# without required checks; the ruleset's approval requirement is +# what keeps a human in the loop after auto-merge is enabled. +name: ๐Ÿš€ Member Auto-Enable Auto-Merge + +on: + pull_request_target: + types: [opened, reopened, synchronize, ready_for_review] + +permissions: + contents: read + pull-requests: write + +# Collapse a burst of pushes to one run per PR; the latest state always wins. +concurrency: + group: member-auto-merge-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + enable: + # Pre-filter at workflow level so this doesn't spin up for every PR. + # The action repeats these checks for defense in depth (and clearer + # skip-reason logging), so trimming this `if` is fine; widening it + # is fine too โ€” the action will skip anything that doesn't match. + if: | + github.event.pull_request.draft == false && + ( + github.event.pull_request.author_association == 'MEMBER' || + github.event.pull_request.author_association == 'OWNER' || + github.event.pull_request.author_association == 'COLLABORATOR' + ) && + ( + github.event.pull_request.base.ref == 'next' || + github.event.pull_request.base.ref == 'hotfixes' + ) + uses: CLDMV/.github/.github/workflows/reusable-member-auto-merge.yml@v4 + with: + merge_method: "MERGE" + # CUSTOMIZE: tighten or widen as your repo requires. + # allowed_associations: "MEMBER,OWNER,COLLABORATOR" + # branch_prefixes: "feat,feature,fix,hotfix,chore,refactor,docs,ci,perf,test,style" + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/next-release.yml b/.github/workflows/next-release.yml index 691b15f..a9f7b6f 100644 --- a/.github/workflows/next-release.yml +++ b/.github/workflows/next-release.yml @@ -37,6 +37,9 @@ concurrency: group: next-release-${{ github.repository }} cancel-in-progress: false +permissions: + contents: read + jobs: release: permissions: @@ -45,11 +48,17 @@ jobs: uses: CLDMV/.github/.github/workflows/workflow-next-release.yml@v4 with: package_name: "@cldmv/git-embedded" - build_command: "echo 'โœ“ no build step'" + build_command: "npm run build:ci" secrets: # Map your repo/org secrets to the expected names. BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + # Optional: only needed if you also use reusable-lint-format.yml / + # reusable-coverage-badge.yml (or otherwise sign a commit locally as + # this identity). Passed through so the release-PR changelog + # recognizes that identity as a bot instead of listing it as a + # contributor โ€” see CLDMV_BOT_NAME/CLDMV_BOT_EMAIL in your other + # workflows for the same values. BOT_NAME: ${{ secrets.CLDMV_BOT_NAME }} BOT_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} # Optional release-PR notifier webhooks โ€” each is independently diff --git a/.github/workflows/next-reset.yml b/.github/workflows/next-reset.yml index 6576845..c7eb04a 100644 --- a/.github/workflows/next-reset.yml +++ b/.github/workflows/next-reset.yml @@ -25,19 +25,22 @@ name: โ™ป๏ธ Next/Hotfixes Reset (v4) on: - push: - branches: [master, main] + push: + branches: [master, main] concurrency: - group: next-reset-${{ github.repository }} - cancel-in-progress: false + group: next-reset-${{ github.repository }} + cancel-in-progress: false + +permissions: + contents: read jobs: - sync: - permissions: - contents: write - uses: CLDMV/.github/.github/workflows/workflow-next-reset.yml@v4 - secrets: - # Map your repo/org secrets to the expected names. - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + sync: + permissions: + contents: write + uses: CLDMV/.github/.github/workflows/workflow-next-reset.yml@v4 + secrets: + # Map your repo/org secrets to the expected names. + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/pr-notify.yml b/.github/workflows/pr-notify.yml new file mode 100644 index 0000000..549d55d --- /dev/null +++ b/.github/workflows/pr-notify.yml @@ -0,0 +1,40 @@ +# +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/pr-notify.yml +# @Date: 2026-05-26 00:00:00 -07:00 (1780124400) +# @Author: Nate Corcoran +# @Email: +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# + +# Individual repo: .github/workflows/pr-notify.yml +# +# Fires once per PR open. Targets ALL PRs in the repo (including the release +# PRs opened by the release-flow workflows) โ€” exactly one notification per +# PR-open event. +# +# Channels are addressed by secret name; no config file. Set the secret to +# enable the channel, leave it unset to skip: +# +# DISCORD_PR_PUBLIC_WEBHOOK / DISCORD_PR_PRIVATE_WEBHOOK +# SLACK_PR_PUBLIC_WEBHOOK / SLACK_PR_PRIVATE_WEBHOOK +# GENERIC_PR_PUBLIC_WEBHOOK / GENERIC_PR_PRIVATE_WEBHOOK +# +# Visibility is determined automatically from the repo: GitHub `public` โ†’ +# PUBLIC, `private` or `internal` โ†’ PRIVATE. Set the org-level secret in +# CLDMV for the default URL; set a repo-level secret with the same name to +# override (or to an empty string to mute that channel for this repo). +name: ๐Ÿ“ฅ PR Notify + +on: + pull_request: + types: [opened] + +permissions: + contents: read + pull-requests: read + +jobs: + notify: + uses: CLDMV/.github/.github/workflows/reusable-pr-notifier.yml@v4 + secrets: inherit diff --git a/.github/workflows/pr-title-normalizer.yml b/.github/workflows/pr-title-normalizer.yml index 0aa8554..996a67b 100644 --- a/.github/workflows/pr-title-normalizer.yml +++ b/.github/workflows/pr-title-normalizer.yml @@ -26,20 +26,23 @@ name: ๐Ÿท๏ธ PR Title Normalizer # only (NOT edited): a maintainer hand-editing the title must not kick off a # re-normalize loop. on: - pull_request_target: - types: [opened, synchronize] + pull_request_target: + types: [opened, synchronize] concurrency: - group: pr-title-normalizer-${{ github.event.pull_request.number }} - cancel-in-progress: true + group: pr-title-normalizer-${{ github.event.pull_request.number }} + cancel-in-progress: true + +permissions: + contents: read jobs: - normalize: - permissions: - contents: read - pull-requests: write - uses: CLDMV/.github/.github/workflows/workflow-pr-title-normalizer.yml@v4 - secrets: - # Map your repo/org secrets to the expected names. - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + normalize: + permissions: + contents: read + pull-requests: write + uses: CLDMV/.github/.github/workflows/workflow-pr-title-normalizer.yml@v4 + secrets: + # Map your repo/org secrets to the expected names. + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/provenance.yml b/.github/workflows/provenance.yml new file mode 100644 index 0000000..12d9255 --- /dev/null +++ b/.github/workflows/provenance.yml @@ -0,0 +1,47 @@ +# +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/provenance.yml +# @Date: 2026-09-05 00:00:00 -07:00 (1788591600) +# @Author: Nate Corcoran +# @Email: +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# + +# SLSA build provenance (.intoto.jsonl) for this repo's published releases. +# Decoupled from the publish workflow on purpose (see reusable-provenance.yml): +# the SLSA generator is a reusable-workflow call and cannot carry +# `continue-on-error`, so running it here โ€” on its own `release: published` +# trigger โ€” keeps a provenance failure from ever turning a release run red +# (issue #268). It re-packs the SAME build artifact the publish run uploaded, so +# the signed subjects are byte-identical to what was published. +# +# Prereq: the org's allowed actions/reusable-workflows policy must permit +# slsa-framework/*. +name: ๐Ÿ” SLSA Provenance + +on: + release: + types: [published] + +jobs: + provenance: + # Public, real releases only โ€” SLSA provenance is recorded in the public + # Rekor transparency log. Skip drafts, prereleases, and private repos. + if: | + !github.event.repository.private && + !github.event.release.draft && + !github.event.release.prerelease + permissions: + actions: read # look up the publish run's build artifact + id-token: write # provenance signing (OIDC) + contents: write # upload the .intoto.jsonl release asset + uses: CLDMV/.github/.github/workflows/reusable-provenance.yml@v4 + with: + tag: ${{ github.event.release.tag_name }} + # CUSTOMIZE: these MUST match your publish.yml so the re-packed + # tarballs are byte-identical to what was published. + package_name: "@cldmv/git-embedded" + node_version: "lts/*" + # Satellite packages (same value as publish.yml's extra_packages); + # empty disables. See docs/conventions/satellite-packages.md. + extra_packages: "" diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index b5742ea..3cc34a4 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -11,115 +11,132 @@ name: ๐Ÿ“ฆ Release and Publish on: - push: - branches: [master, main] - paths-ignore: - - "**.md" - - ".github/ISSUE_TEMPLATE/**" - - ".github/PULL_REQUEST_TEMPLATE/**" - workflow_dispatch: - inputs: - debug: - description: "Enable debug logging for troubleshooting" - type: boolean - required: false - default: false - dry_run: - description: "Dry run mode - validate everything but don't publish or create releases" - type: boolean - required: false - default: false - node_version: - description: "Node.js version to use (default: lts/*)" - type: string - required: false - default: "lts/*" - package_manager: - description: "Package manager (npm or yarn)" - type: string - required: false - default: "npm" - test_environment: - description: "Environment for tests (affects NODE_ENV and NODE_OPTIONS --conditions flag)" - type: string - required: false - default: "development" - version: - description: "Version to publish (auto-detected from package.json if not provided)" - type: string - required: false - default: "" - publish_to_npm: - description: "Publish to NPM registry" - type: boolean - required: false - default: true - publish_to_github_packages: - description: "Publish to GitHub Packages registry" - type: boolean - required: false - default: true - min_node_version: - description: "Minimum Node.js version for matrix testing (default: 22.12.0 โ€” the floor vitest 5 actually runs on)" - type: string - required: false - default: "22.12.0" - max_node_major: - description: "Override max Node.js major version (default: 26)" - type: string - required: false - default: "26" - use_gpg: - description: "Enable GPG signing (if GPG secrets provided)" - type: boolean - required: false - default: false + push: + branches: [master, main] + paths-ignore: + - "**.md" + - ".github/ISSUE_TEMPLATE/**" + - ".github/PULL_REQUEST_TEMPLATE/**" + workflow_dispatch: + inputs: + debug: + description: "Enable debug logging for troubleshooting" + type: boolean + required: false + default: false + dry_run: + description: "Dry run mode - validate everything but don't publish or create releases" + type: boolean + required: false + default: false + node_version: + description: "Node.js version to use (default: lts/*)" + type: string + required: false + default: "lts/*" + package_manager: + description: "Package manager (npm or yarn)" + type: string + required: false + default: "npm" + test_environment: + description: "Environment for tests (affects NODE_ENV and NODE_OPTIONS --conditions flag)" + type: string + required: false + default: "development" + version: + description: "Version to publish (auto-detected from package.json if not provided)" + type: string + required: false + default: "" + publish_to_npm: + description: "Publish to NPM registry" + type: boolean + required: false + default: true + publish_to_github_packages: + description: "Publish to GitHub Packages registry" + type: boolean + required: false + default: true + min_node_version: + description: "Minimum Node.js version for matrix testing (enables matrix when set; default: 22.12.0 โ€” the floor vitest 5 actually runs on)" + type: string + required: false + default: "22.12.0" + max_node_major: + description: "Max Node.js major version for the test matrix. Leave blank (the default) to inherit the CLDMV/.github reusable workflow's default; set a value only to pin/override for a specific run." + type: string + required: false + default: "" + use_gpg: + description: "Enable GPG signing (if GPG secrets provided)" + type: boolean + required: false + default: false # NEVER cancel an in-flight publish โ€” half-published versions are nasty to # clean up. Concurrent publishes for the same ref queue instead so they # serialize naturally. concurrency: - group: publish-${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: false + group: publish-${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +permissions: + contents: read jobs: - publish-package: - if: github.event_name == 'push' || github.event_name == 'workflow_dispatch' - permissions: - contents: write - packages: write - id-token: write - uses: CLDMV/.github/.github/workflows/workflow-publish.yml@v4 - with: - package_name: "@cldmv/git-embedded" # Required: replace with your NPM package name - debug: ${{ github.event.inputs.debug == 'true' }} - dry_run: ${{ github.event.inputs.dry_run == 'true' }} - node_version: ${{ github.event.inputs.node_version || 'lts/*' }} - package_manager: ${{ github.event.inputs.package_manager || 'npm' }} - version: ${{ github.event.inputs.version || '' }} - publish_to_npm: ${{ github.event.inputs.publish_to_npm != 'false' }} - publish_to_github_packages: ${{ github.event.inputs.publish_to_github_packages != 'false' }} - publish_command: "" - github_packages_publish_command: "" - min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} - max_node_major: ${{ github.event.inputs.max_node_major || '26' }} - test_command: "npm test" # Use defaults: NODE_ENV=development, NODE_OPTIONS=--conditions=development - # test_command: "NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override NODE_OPTIONS only - # test_command: "NODE_ENV=test npm test" # Override NODE_ENV only - # test_command: "NODE_ENV=test NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override both - test_environment: ${{ github.event.inputs.test_environment || 'development' }} # Alternative to setting in test_command - build_command: "npm run build:ci" - is_prerelease: false - release_source_only: false - create_documentation: true - skip_performance_tests: false - skip_matrix_tests: false - use_gpg: ${{ github.event.inputs.use_gpg == 'true' }} - secrets: - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} - TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} - GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} - GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} + publish-package: + if: github.event_name == 'push' || github.event_name == 'workflow_dispatch' + permissions: + contents: write + packages: write + id-token: write + uses: CLDMV/.github/.github/workflows/workflow-publish.yml@v4 + with: + package_name: "@cldmv/git-embedded" # Required: replace with your NPM package name + debug: ${{ github.event.inputs.debug == 'true' }} + dry_run: ${{ github.event.inputs.dry_run == 'true' }} + node_version: ${{ github.event.inputs.node_version || 'lts/*' }} + package_manager: ${{ github.event.inputs.package_manager || 'npm' }} + version: ${{ github.event.inputs.version || '' }} + publish_to_npm: ${{ github.event.inputs.publish_to_npm != 'false' }} + publish_to_github_packages: ${{ github.event.inputs.publish_to_github_packages != 'false' }} + publish_command: "" + github_packages_publish_command: "" + min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} + max_node_major: ${{ github.event.inputs.max_node_major || '' }} # blank โ‡’ inherit the CLDMV/.github reusable default + test_command: "npm test" # Use defaults: NODE_ENV=development, NODE_OPTIONS=--conditions=development + # test_command: "NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override NODE_OPTIONS only + # test_command: "NODE_ENV=test npm test" # Override NODE_ENV only + # test_command: "NODE_ENV=test NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override both + test_environment: ${{ github.event.inputs.test_environment || 'development' }} # Alternative to setting in test_command + build_command: "npm run build:ci" + # --- Satellite packages (optional) ---------------------------------------- + # Publish extra packages carved from this build's output (e.g. locale JSON, + # generated types) at the SAME version/commit as the core, each with its own + # @scope/name@version tag + GitHub Release. Uncomment to opt in. + # extra_packages: a JSON [{ name, dir }] array, OR a glob (single '*' in the + # final path segment, e.g. "dist-packages/*"). Empty = disabled. + # build_subpackages_command: runs after build_command to produce + # dist-packages// โ€” omit if build_command already does the carve. + # First publish of each new @scope/name needs a one-time token publish + + # trusted-publisher setup. Full details + the contract: + # docs/conventions/satellite-packages.md + # extra_packages: "dist-packages/*" + # build_subpackages_command: "npm run build:subpackages" + # -------------------------------------------------------------------------- + is_prerelease: false + release_source_only: false + create_documentation: true + skip_performance_tests: false + skip_matrix_tests: false + use_gpg: ${{ github.event.inputs.use_gpg == 'true' }} + secrets: + NPM_TOKEN: ${{ secrets.NPM_TOKEN }} + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} + TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} + GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} + GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} diff --git a/.github/workflows/release-merge.yml b/.github/workflows/release-merge.yml new file mode 100644 index 0000000..c9c6452 --- /dev/null +++ b/.github/workflows/release-merge.yml @@ -0,0 +1,74 @@ +# +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/release-merge.yml +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# + +# Individual repo: .github/workflows/release-merge.yml +# +# v4 core (optional): squash-merge the persistent `next โ†’ master` release PR on +# YOUR APPROVAL, via the REST merge API with the PR body as the commit message. +# +# Why not just click "Squash and merge"? The mobile Default path can land a +# title-only commit (dropping the curated changelog + coverage), and the web/ +# mobile squash UI auto-appends its own `Co-authored-by:` list (not deduped, not +# bot-stripped). An explicit-message API merge avoids both โ€” the release commit +# is exactly the curated PR body. It also merges only once EVERY check (required +# AND non-required, e.g. the coverage badge and the release-PR body refresh) has +# finished and passed, so the body it captures is never stale. +# +# How you use it: approve the release PR as you normally do. The merge fires when +# CI is green โ€” if you approve before CI finishes, it re-evaluates once CI +# actually finishes and merges once the last check passes. Nothing auto-merges +# without your approval. +# +# Re-evaluation uses `workflow_run`, not `check_suite` โ€” GitHub does not send +# `check_suite: completed` for a suite created by GitHub Actions itself, which +# is every check your own ci.yml produces; it only fires for a suite created +# by a third-party App. See CLDMV/.github#318: an approval given before CI +# finished left a release PR stuck fully green with nothing re-firing the +# merge check, because check_suite silently never fired for that case at all. +# `workflow_run` is GitHub's documented replacement for exactly this pattern. +# +# IMPORTANT: `workflows:` below must list the exact `name:` of THIS repo's own +# ci.yml (matched by literal workflow name, not filename) โ€” update it if you +# renamed that workflow. If more than one top-level workflow in your repo can +# plausibly be the last to finish (e.g. a separately-scheduled CodeQL run that +# sometimes outlasts ci.yml), list all of them; a workflow that finishes and +# isn't listed here won't re-arm the merge check, though the manual +# workflow_dispatch fallback below always will. +# +# Thin caller: all logic lives in the reusable, pinned at @v4. +# NOTE: pull_request_review / workflow_run events run the copy of this file on +# the DEFAULT branch, so it takes effect once it ships to master with a release. +name: ๐Ÿšฆ Release Merge (v4) + +on: + pull_request_review: + types: [submitted] # your approval arms it + workflow_run: + workflows: ["๐Ÿงช CI Tests & Build"] # โ† match your ci.yml's `name:` โ€” see #318 + types: [completed] + workflow_dispatch: # manual re-evaluation + +# Serialize per repo: each run re-resolves the release PR + re-gates the head, +# so queue (don't cancel) to avoid racing a merge that's already in flight. +concurrency: + group: release-merge-${{ github.repository }} + cancel-in-progress: false + +permissions: + contents: read + +jobs: + merge: + permissions: + contents: write + pull-requests: write + checks: read + statuses: read + uses: CLDMV/.github/.github/workflows/workflow-release-merge.yml@v4 + secrets: + # Map your repo/org secrets to the expected names. + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/release-notify.yml b/.github/workflows/release-notify.yml index 5ecdb1f..8956a1e 100644 --- a/.github/workflows/release-notify.yml +++ b/.github/workflows/release-notify.yml @@ -23,15 +23,15 @@ name: ๐Ÿ“ฃ Release Notify on: - release: - types: [published] + release: + types: [published] permissions: - contents: read + contents: read jobs: - notify: - # Defensive: skip untagged releases (mirrors Batch 1.2's filter) - if: github.event.release.tag_name != '' - uses: CLDMV/.github/.github/workflows/reusable-release-notifier.yml@v4 - secrets: inherit + notify: + # Defensive: skip untagged releases (mirrors Batch 1.2's filter) + if: github.event.release.tag_name != '' + uses: CLDMV/.github/.github/workflows/reusable-release-notifier.yml@v4 + secrets: inherit diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 6f832e9..d2221ef 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -14,26 +14,21 @@ # scorecard-action version live in reusable-scorecard.yml@v4, so the action # version can't drift in this copy (it just calls the org reusable). Triggers # stay here, per OpenSSF's recommended setup. -# -# NOTE: this MUST stay a thin caller. OSSF Scorecard's publish step verifies -# the analysis job and allows only a fixed set of steps; the inline form used -# our checkout-code composite, which trips "job has unallowed step" -> publish -# HTTP 400. The reusable uses actions/checkout directly, which passes. name: ๐Ÿ”ฌ OpenSSF Scorecard on: - branch_protection_rule: - schedule: - - cron: "32 7 * * 1" # weekly Monday 07:32 UTC - push: - branches: [master, main] - workflow_dispatch: + branch_protection_rule: + schedule: + - cron: "32 7 * * 1" # weekly Monday 07:32 UTC + push: + branches: [master, main] + workflow_dispatch: # Caller must grant what the reusable needs โ€” notably id-token: write for the # OpenSSF transparency-log publish. # -# No workflow-level `permissions:` here โ€” grant on the `analyze` job below -# instead. scorecard-action's publish step verifies that write permissions +# Keep the workflow-level grant READ-ONLY (contents: read) and grant every +# WRITE on the `analyze` job instead. scorecard-action's publish step verifies that write permissions # were granted JOB-scoped, not workflow-wide (matching OSSF's own example: # https://github.com/ossf/scorecard-action#example-workflow). A workflow-level # grant satisfies GitHub's own reusable-workflow permission rules fine, but @@ -47,15 +42,19 @@ on: # tampered with results before they hit the public transparency log). That # trade-off means the reusable's own SARIF-to-Security-tab upload step has no # permission to run in this configuration; the public OpenSSF badge is the -# thing actually enabled here, so this repo takes that trade-off. Only add -# security-events: write back (job-scoped) if publish_results is set to false -# instead. +# thing this default enables, so consumers take that trade-off by default. +# Only add security-events: write back (job-scoped) if publish_results is set +# to false instead (SARIF-to-Security-tab upload, no public badge). + +permissions: + contents: read + jobs: - analyze: - permissions: - id-token: write - contents: read - actions: read - uses: CLDMV/.github/.github/workflows/reusable-scorecard.yml@v4 - with: - publish_results: true # set false for private repos / to skip the public badge + analyze: + permissions: + id-token: write + contents: read + actions: read + uses: CLDMV/.github/.github/workflows/reusable-scorecard.yml@v4 + with: + publish_results: true # set false to skip the public badge in favor of SARIF-to-Security-tab. Private repos need not bother: every scorecard job auto-skips there (OpenSSF cannot publish private repos, so the run would only burn paid minutes). diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index da9e454..989998e 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -18,29 +18,29 @@ name: ๐Ÿ‚ Stale Issues & PRs on: - schedule: - - cron: "13 5 * * *" # daily 05:13 UTC (off-the-hour to avoid GH cron stampede) - workflow_dispatch: - inputs: - dry_run: - description: "Preview only โ€” no changes will be made" - type: boolean - default: false + schedule: + - cron: "13 5 * * *" # daily 05:13 UTC (off-the-hour to avoid GH cron stampede) + workflow_dispatch: + inputs: + dry_run: + description: "Preview only โ€” no changes will be made" + type: boolean + default: false permissions: - issues: write - pull-requests: write + issues: write + pull-requests: write jobs: - sweep: - uses: CLDMV/.github/.github/workflows/reusable-stale.yml@v4 - with: - dry_run: ${{ github.event.inputs.dry_run == 'true' }} - # Override timers if needed: - # days_before_issue_stale: 60 - # days_before_issue_close: 14 - # days_before_pr_stale: 30 - # days_before_pr_close: 7 - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + sweep: + uses: CLDMV/.github/.github/workflows/reusable-stale.yml@v4 + with: + dry_run: ${{ github.event.inputs.dry_run == 'true' }} + # Override timers if needed: + # days_before_issue_stale: 60 + # days_before_issue_close: 14 + # days_before_pr_stale: 30 + # days_before_pr_close: 7 + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/tag-health.yml b/.github/workflows/tag-health.yml index a5135f8..cd1b2b3 100644 --- a/.github/workflows/tag-health.yml +++ b/.github/workflows/tag-health.yml @@ -19,46 +19,48 @@ name: ๐Ÿฅ Tag Health on: - schedule: - # Weekly Sunday 04:04 UTC. Off-the-hour to dodge the GitHub :00-cron - # stampede; weekly cadence because tag drift accumulates slowly. - - cron: "4 4 * * 0" - workflow_dispatch: - inputs: - debug: - description: "Enable debug logging for troubleshooting" - type: boolean - required: false - default: false - create_documentation: - description: "Update VERSION_TAGS.md if rolling tags moved" - type: boolean - required: false - default: false - use_gpg: - description: "Enable GPG signing for any tags the sweep creates/recreates" - type: boolean - required: false - default: true + schedule: + # Weekly Sunday 04:04 UTC. Off-the-hour to dodge the GitHub :00-cron + # stampede; weekly cadence because tag drift accumulates slowly. + - cron: "4 4 * * 0" + workflow_dispatch: + inputs: + debug: + description: "Enable debug logging for troubleshooting" + type: boolean + required: false + default: false + create_documentation: + description: "Update VERSION_TAGS.md if rolling tags moved" + type: boolean + required: false + default: false + use_gpg: + description: "Enable GPG signing for any tags the sweep creates/recreates" + type: boolean + required: false + default: true permissions: - contents: write + contents: read jobs: - health: - uses: CLDMV/.github/.github/workflows/reusable-tag-health.yml@v4 - with: - debug: ${{ github.event.inputs.debug == 'true' }} - # Full unified sweep: validates, fixes bot signatures, fixes - # unsigned tags, recovers orphaned releases, relocates orphaned - # tags, and updates rolling major/minor refs. - run_unified_tag_health: true - create_documentation: ${{ github.event.inputs.create_documentation == 'true' }} - use_gpg: ${{ github.event.inputs.use_gpg != 'false' }} - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} - TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} - GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} - GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} + health: + permissions: + contents: write + uses: CLDMV/.github/.github/workflows/reusable-tag-health.yml@v4 + with: + debug: ${{ github.event.inputs.debug == 'true' }} + # Full unified sweep: validates, fixes bot signatures, fixes + # unsigned tags, recovers orphaned releases, relocates orphaned + # tags, and updates rolling major/minor refs. + run_unified_tag_health: true + create_documentation: ${{ github.event.inputs.create_documentation == 'true' }} + use_gpg: ${{ github.event.inputs.use_gpg != 'false' }} + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} + TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} + GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} + GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} diff --git a/.github/workflows/update-major-version-tags.yml b/.github/workflows/update-major-version-tags.yml index aa0b7bc..96e54bc 100644 --- a/.github/workflows/update-major-version-tags.yml +++ b/.github/workflows/update-major-version-tags.yml @@ -11,77 +11,80 @@ name: ๐Ÿท๏ธ Update Major Version Tags on: - release: - types: [published] - workflow_dispatch: - inputs: - debug: - description: "Enable debug logging for troubleshooting" - type: boolean - required: false - default: false - create_documentation: - description: "Whether to create/update VERSION_TAGS.md documentation" - type: boolean - required: false - default: false - use_gpg: - description: "Enable GPG signing (if GPG secrets provided)" - type: boolean - required: false - default: true - # Tag health configuration - max_tags: - description: "Maximum number of tags to process (safety limit)" - required: false - default: "100" - max_major_versions: - description: "Maximum number of major versions to process" - required: false - default: "10" - max_minor_versions: - description: "Maximum number of minor versions per major to process" - required: false - default: "10" - bot_patterns: - description: "JSON array of bot name patterns to identify bot signatures" - required: false - default: '["CLDMV Bot", "cldmv-bot", "github-actions[bot]"]' - include_patterns: - description: "JSON array of tag patterns to include (e.g. ['v*', 'release-*'])" - required: false - default: '["v*"]' - exclude_patterns: - description: "JSON array of tag patterns to exclude" - required: false - default: "[]" + release: + types: [published] + workflow_dispatch: + inputs: + debug: + description: "Enable debug logging for troubleshooting" + type: boolean + required: false + default: false + create_documentation: + description: "Whether to create/update VERSION_TAGS.md documentation" + type: boolean + required: false + default: false + use_gpg: + description: "Enable GPG signing (if GPG secrets provided)" + type: boolean + required: false + default: true + # Tag health configuration + max_tags: + description: "Maximum number of tags to process (safety limit)" + required: false + default: "100" + max_major_versions: + description: "Maximum number of major versions to process" + required: false + default: "10" + max_minor_versions: + description: "Maximum number of minor versions per major to process" + required: false + default: "10" + bot_patterns: + description: "JSON array of bot name patterns to identify bot signatures" + required: false + default: '["CLDMV Bot", "cldmv-bot", "github-actions[bot]"]' + include_patterns: + description: "JSON array of tag patterns to include (e.g. ['v*', 'release-*'])" + required: false + default: '["v*"]' + exclude_patterns: + description: "JSON array of tag patterns to exclude" + required: false + default: "[]" + +permissions: + contents: read jobs: - update-tags: - # Skip release events fired without a tag_name (e.g. "untagged-" runs - # the bot or a prior code path can produce). The reusable workflow has its - # own tag-readiness polling for forward-facing prevention; this guard - # protects against legacy / external sources of untagged release events. - # Batch 1.2 from tmp/plan-future-workflows.md. - if: github.event_name != 'release' || github.event.release.tag_name != '' - uses: CLDMV/.github/.github/workflows/workflow-update-major-version-tags.yml@v4 - permissions: - contents: write - with: - debug: ${{ github.event.inputs.debug == 'true' }} - create_documentation: ${{ github.event.inputs.create_documentation == 'true' }} - use_gpg: ${{ github.event.inputs.use_gpg != 'false' }} - max_tags: ${{ github.event.inputs.max_tags || '100' }} - max_major_versions: ${{ github.event.inputs.max_major_versions || '10' }} - max_minor_versions: ${{ github.event.inputs.max_minor_versions || '10' }} - bot_patterns: ${{ github.event.inputs.bot_patterns || '["CLDMV Bot", "cldmv-bot", "github-actions[bot]"]' }} - include_patterns: ${{ github.event.inputs.include_patterns || '["v*"]' }} - exclude_patterns: ${{ github.event.inputs.exclude_patterns || '[]' }} - secrets: - # Map your repo/org secrets to the expected names - TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} - TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} - GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} - GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + update-tags: + # Skip release events fired without a tag_name (e.g. "untagged-" runs + # the bot or a prior code path can produce). The reusable workflow has its + # own tag-readiness polling for forward-facing prevention; this guard + # protects against legacy / external sources of untagged release events. + # Batch 1.2 from tmp/plan-future-workflows.md. + if: github.event_name != 'release' || github.event.release.tag_name != '' + uses: CLDMV/.github/.github/workflows/workflow-update-major-version-tags.yml@v4 + permissions: + contents: write + with: + debug: ${{ github.event.inputs.debug == 'true' }} + create_documentation: ${{ github.event.inputs.create_documentation == 'true' }} + use_gpg: ${{ github.event.inputs.use_gpg != 'false' }} + max_tags: ${{ github.event.inputs.max_tags || '100' }} + max_major_versions: ${{ github.event.inputs.max_major_versions || '10' }} + max_minor_versions: ${{ github.event.inputs.max_minor_versions || '10' }} + bot_patterns: ${{ github.event.inputs.bot_patterns || '["CLDMV Bot", "cldmv-bot", "github-actions[bot]"]' }} + include_patterns: ${{ github.event.inputs.include_patterns || '["v*"]' }} + exclude_patterns: ${{ github.event.inputs.exclude_patterns || '[]' }} + secrets: + # Map your repo/org secrets to the expected names + TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} + TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} + GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} + GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/v4-bootstrap.yml b/.github/workflows/v4-bootstrap.yml index 9ed58f7..808b248 100644 --- a/.github/workflows/v4-bootstrap.yml +++ b/.github/workflows/v4-bootstrap.yml @@ -44,63 +44,68 @@ name: ๐Ÿš€ v4 Bootstrap on: - workflow_dispatch: - inputs: - dry_run: - description: "Dry-run: preview every mutation without firing it. Default `true` โ€” set to `false` to actually apply changes." - type: boolean - required: false - default: true - code_security: - description: "Code Security policy. off = disable. public-only = enable only if this repo is public (free). all = enable (paid on private)." - type: choice - required: false - default: "off" - options: - - "off" - - "public-only" - - "all" - secret_protection: - description: "Secret Protection (scanning + push protection) policy. Same shape as code_security." - type: choice - required: false - default: "off" - options: - - "off" - - "public-only" - - "all" - steps: - description: "Subset of phases to run, comma-separated." - required: false - default: "branches,settings,security,rulesets" + workflow_dispatch: + inputs: + dry_run: + description: "Dry-run: preview every mutation without firing it. Default `true` โ€” set to `false` to actually apply changes." + type: boolean + required: false + default: true + code_security: + description: "Code Security policy. off = disable. public-only = enable only if this repo is public (free). all = enable (paid on private)." + type: choice + required: false + default: "off" + options: + - "off" + - "public-only" + - "all" + secret_protection: + description: "Secret Protection (scanning + push protection) policy. Same shape as code_security." + type: choice + required: false + default: "off" + options: + - "off" + - "public-only" + - "all" + steps: + description: "Subset of phases to run, comma-separated." + required: false + default: "branches,settings,security,rulesets,variables" + code_scanning_config: + description: "Override for the variables-phase GHAS config (scan/skip lists): inline JSON or a workspace path. Empty = the data/code-scanning-skips.json bundled in CLDMV/.github โ€” third-party orgs supply their own here." + required: false + default: "" permissions: - contents: read + contents: read jobs: - bootstrap: - name: "๐Ÿš€ Bootstrap v4 (this repo)" - runs-on: ubuntu-latest - steps: - - name: Create App token - id: app-token - # Full-permission App token โ€” bootstrap needs administration:write - # for security toggles + ruleset import, plus contents:write for - # branch creation. - uses: CLDMV/.github/.github/actions/github/steps/create-app-token@v4 - with: - client_id: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - private_key: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - env: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + bootstrap: + name: "๐Ÿš€ Bootstrap v4 (this repo)" + runs-on: ubuntu-latest + steps: + - name: Create App token + id: app-token + # Full-permission App token โ€” bootstrap needs administration:write + # for security toggles + ruleset import, plus contents:write for + # branch creation. + uses: CLDMV/.github/.github/actions/github/steps/create-app-token@v4 + with: + client_id: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + private_key: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + env: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} - - name: Bootstrap - uses: CLDMV/.github/.github/actions/github/jobs/org-bootstrap-repo@v4 - with: - # target_repo defaults to GITHUB_REPOSITORY (this repo). - github_token: ${{ steps.app-token.outputs.token }} - dry_run: ${{ github.event.inputs.dry_run }} - steps: ${{ github.event.inputs.steps }} - code_security: ${{ github.event.inputs.code_security }} - secret_protection: ${{ github.event.inputs.secret_protection }} + - name: Bootstrap + uses: CLDMV/.github/.github/actions/github/jobs/org-bootstrap-repo@v4 + with: + # target_repo defaults to GITHUB_REPOSITORY (this repo). + github_token: ${{ steps.app-token.outputs.token }} + dry_run: ${{ github.event.inputs.dry_run }} + steps: ${{ github.event.inputs.steps }} + code_security: ${{ github.event.inputs.code_security }} + secret_protection: ${{ github.event.inputs.secret_protection }} + code_scanning_config: ${{ github.event.inputs.code_scanning_config }} diff --git a/.github/workflows/welcome.yml b/.github/workflows/welcome.yml index d5ab5cd..e45d095 100644 --- a/.github/workflows/welcome.yml +++ b/.github/workflows/welcome.yml @@ -19,20 +19,20 @@ name: ๐Ÿ‘‹ Welcome Contributor # - We only call REST APIs to read prior interactions and post a comment # DO NOT add a checkout step or any step that executes PR-supplied content. on: - issues: - types: [opened] - pull_request_target: - types: [opened] + issues: + types: [opened] + pull_request_target: + types: [opened] permissions: - issues: write - pull-requests: write + issues: write + pull-requests: write jobs: - welcome: - uses: CLDMV/.github/.github/workflows/reusable-welcome.yml@v4 - # Optional. Without these, the welcome comment is posted by - # github-actions[bot]. With these, it's posted by your CLDMV bot App. - secrets: - BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} - BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + welcome: + uses: CLDMV/.github/.github/workflows/reusable-welcome.yml@v4 + # Optional. Without these, the welcome comment is posted by + # github-actions[bot]. With these, it's posted by your CLDMV bot App. + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} From 6ac136f4110f7af9ca4f0069f18d543bf202b487 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 27 Sep 2026 13:17:51 -0700 Subject: [PATCH 08/14] ci: correct workflow header metadata and finish the v4 sync - fix @Project / @Filename in workflow headers that still named the CLDMV/.github template (@cldmv/.github, /examples/...) instead of this repository - dependabot-auto-merge: drop the explicit merge_method "squash". The next and hotfixes rulesets allow merge commits only (CLDMV/.github data/rulesets), so squash was stale; the template's default merge method applies. --- .github/dependabot.yml | 4 ++-- .github/workflows/dependabot-auto-merge.yml | 1 - .github/workflows/feature-pr.yml | 4 ++-- .github/workflows/hotfix-redirector.yml | 4 ++-- .github/workflows/hotfixes-release.yml | 4 ++-- .github/workflows/next-release.yml | 4 ++-- .github/workflows/next-reset.yml | 4 ++-- .github/workflows/pr-title-normalizer.yml | 4 ++-- 8 files changed, 14 insertions(+), 15 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 936330a..77dbc1b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,6 +1,6 @@ # -# @Project: @cldmv/.github -# @Filename: /examples/individual-repo-workflows/automation/dependabot.yml +# @Project: @cldmv/git-embedded +# @Filename: /.github/dependabot.yml # @Date: 2026-05-26 00:00:00 -07:00 (1782460800) # @Author: Nate Corcoran # @Email: diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index b5a35e6..fdc3d76 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -51,7 +51,6 @@ jobs: bump_types: "patch,minor" # merge_method defaults to "merge" โ€” Dependabot PRs target next / hotfixes, # whose rulesets are merge-only. Override only if your branches differ. - merge_method: "squash" # also_for_actors: "renovate[bot]" # extend if you adopt Renovate secrets: BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} diff --git a/.github/workflows/feature-pr.yml b/.github/workflows/feature-pr.yml index 903ab09..1b7f7c1 100644 --- a/.github/workflows/feature-pr.yml +++ b/.github/workflows/feature-pr.yml @@ -1,6 +1,6 @@ # -# @Project: @cldmv/.github -# @Filename: /examples/individual-repo-workflows/release-flow-v4/feature-pr.yml +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/feature-pr.yml # @Author: Nate Corcoran # @Email: # @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. diff --git a/.github/workflows/hotfix-redirector.yml b/.github/workflows/hotfix-redirector.yml index b257393..c9980ae 100644 --- a/.github/workflows/hotfix-redirector.yml +++ b/.github/workflows/hotfix-redirector.yml @@ -1,6 +1,6 @@ # -# @Project: @cldmv/.github -# @Filename: /examples/individual-repo-workflows/release-flow-v4/hotfix-redirector.yml +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/hotfix-redirector.yml # @Date: 2026-05-22 00:00:00 -07:00 (1779778800) # @Author: Nate Corcoran # @Email: diff --git a/.github/workflows/hotfixes-release.yml b/.github/workflows/hotfixes-release.yml index 97c069a..42d71e4 100644 --- a/.github/workflows/hotfixes-release.yml +++ b/.github/workflows/hotfixes-release.yml @@ -1,6 +1,6 @@ # -# @Project: @cldmv/.github -# @Filename: /examples/individual-repo-workflows/release-flow-v4/hotfixes-release.yml +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/hotfixes-release.yml # @Date: 2026-05-22 00:00:00 -07:00 (1779778800) # @Author: Nate Corcoran # @Email: diff --git a/.github/workflows/next-release.yml b/.github/workflows/next-release.yml index a9f7b6f..0ffbb3b 100644 --- a/.github/workflows/next-release.yml +++ b/.github/workflows/next-release.yml @@ -1,6 +1,6 @@ # -# @Project: @cldmv/.github -# @Filename: /examples/individual-repo-workflows/release-flow-v4/next-release.yml +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/next-release.yml # @Date: 2026-05-22 00:00:00 -07:00 (1779778800) # @Author: Nate Corcoran # @Email: diff --git a/.github/workflows/next-reset.yml b/.github/workflows/next-reset.yml index c7eb04a..5f0c498 100644 --- a/.github/workflows/next-reset.yml +++ b/.github/workflows/next-reset.yml @@ -1,6 +1,6 @@ # -# @Project: @cldmv/.github -# @Filename: /examples/individual-repo-workflows/release-flow-v4/next-reset.yml +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/next-reset.yml # @Date: 2026-05-22 00:00:00 -07:00 (1779778800) # @Author: Nate Corcoran # @Email: diff --git a/.github/workflows/pr-title-normalizer.yml b/.github/workflows/pr-title-normalizer.yml index 996a67b..9f91d8c 100644 --- a/.github/workflows/pr-title-normalizer.yml +++ b/.github/workflows/pr-title-normalizer.yml @@ -1,6 +1,6 @@ # -# @Project: @cldmv/.github -# @Filename: /examples/individual-repo-workflows/release-flow-v4/pr-title-normalizer.yml +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/pr-title-normalizer.yml # @Date: 2026-05-22 00:00:00 -07:00 (1779778800) # @Author: Nate Corcoran # @Email: From 1f88fa44d62dfc67a6af1f7f8bcf2d4bd8edbbd0 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 27 Sep 2026 23:58:16 -0700 Subject: [PATCH 09/14] ci: bring the v4 workflow sync up to CLDMV/.github v4.29.2 --- .github/workflows/dependabot-auto-merge.yml | 1 + .github/workflows/release-merge.yml | 42 ++++++++++++++++----- 2 files changed, 34 insertions(+), 9 deletions(-) diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index fdc3d76..ada21db 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -51,6 +51,7 @@ jobs: bump_types: "patch,minor" # merge_method defaults to "merge" โ€” Dependabot PRs target next / hotfixes, # whose rulesets are merge-only. Override only if your branches differ. + # merge_method: "merge" # also_for_actors: "renovate[bot]" # extend if you adopt Renovate secrets: BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} diff --git a/.github/workflows/release-merge.yml b/.github/workflows/release-merge.yml index c9c6452..78546be 100644 --- a/.github/workflows/release-merge.yml +++ b/.github/workflows/release-merge.yml @@ -1,6 +1,8 @@ # # @Project: @cldmv/git-embedded # @Filename: /.github/workflows/release-merge.yml +# @Author: Nate Corcoran +# @Email: # @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # @@ -30,13 +32,17 @@ # merge check, because check_suite silently never fired for that case at all. # `workflow_run` is GitHub's documented replacement for exactly this pattern. # -# IMPORTANT: `workflows:` below must list the exact `name:` of THIS repo's own -# ci.yml (matched by literal workflow name, not filename) โ€” update it if you -# renamed that workflow. If more than one top-level workflow in your repo can -# plausibly be the last to finish (e.g. a separately-scheduled CodeQL run that -# sometimes outlasts ci.yml), list all of them; a workflow that finishes and -# isn't listed here won't re-arm the merge check, though the manual -# workflow_dispatch fallback below always will. +# IMPORTANT: the merge gate waits on EVERY check-run on the release PR's head +# commit, from any workflow โ€” so `workflows:` below must name every workflow in +# your repo that puts a check on that commit, not just ci.yml. Only the one that +# finishes LAST can see a fully green head; if it isn't listed, nothing re-fires +# and the PR sits approved + green until you dispatch this workflow by hand. +# CodeQL in particular routinely outlasts ci.yml (CLDMV/.github PR #322 stuck +# exactly this way). The list below covers the standard v4 template set by their +# template `name:`s โ€” names are matched literally (not by filename), so fix any +# you renamed, and add any extra PR-triggered workflow your repo has. Listing a +# workflow your repo doesn't have is harmless. `branches:` limits re-fires to +# runs on the integration branches, so feature-branch CI doesn't wake this up. # # Thin caller: all logic lives in the reusable, pinned at @v4. # NOTE: pull_request_review / workflow_run events run the copy of this file on @@ -46,13 +52,31 @@ name: ๐Ÿšฆ Release Merge (v4) on: pull_request_review: types: [submitted] # your approval arms it - workflow_run: - workflows: ["๐Ÿงช CI Tests & Build"] # โ† match your ci.yml's `name:` โ€” see #318 + workflow_run: # re-evaluate as each check-producing workflow finishes โ€” see #318 + workflows: # โ† must match your workflows' `name:`s โ€” see IMPORTANT above + - "๐Ÿงช CI Tests & Build" + - "๐Ÿ” CodeQL" + - "๐Ÿ”’ Dependency Review" + - "๐Ÿš€ Next Release (v4)" + - "๐Ÿš‘ Hotfixes Release (v4)" + - "๐ŸŒฟ Branch Retention" + - "๐Ÿท๏ธ PR Labeler" + - "๐Ÿท๏ธ PR Title Normalizer" + - "๐Ÿ‘‹ Welcome Contributor" + - "๐Ÿ”€ Hotfix PR Redirector (v4)" + - "๐Ÿš€ Member Auto-Enable Auto-Merge" + - "๐Ÿค– Dependabot Auto-Merge" + - "๐Ÿ” Dependabot Auto-Recreate" + - "๐Ÿ“œ CLA" + - "๐Ÿ“ฅ PR Notify" types: [completed] + branches: [next, hotfixes] workflow_dispatch: # manual re-evaluation # Serialize per repo: each run re-resolves the release PR + re-gates the head, # so queue (don't cancel) to avoid racing a merge that's already in flight. +# GitHub keeps one pending run per group and a newer arrival replaces it โ€” that +# is harmless, since every run re-reads approval + check state from the API. concurrency: group: release-merge-${{ github.repository }} cancel-in-progress: false From 78c0072b61b60e22f711a627b53d23ffc6fbd3e1 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Mon, 28 Sep 2026 00:09:20 -0700 Subject: [PATCH 10/14] ci: add the bundle-size workflow and keep the template release-merge list --- .github/workflows/bundle-size.yml | 48 +++++++++++++++++++++++++++++ .github/workflows/release-merge.yml | 1 + 2 files changed, 49 insertions(+) create mode 100644 .github/workflows/bundle-size.yml diff --git a/.github/workflows/bundle-size.yml b/.github/workflows/bundle-size.yml new file mode 100644 index 0000000..f1fc4c7 --- /dev/null +++ b/.github/workflows/bundle-size.yml @@ -0,0 +1,48 @@ +# +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/bundle-size.yml +# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) +# @Author: Nate Corcoran +# @Email: +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# + +# Individual repo: .github/workflows/bundle-size.yml +# +# Only relevant for runtime libraries where bundle size matters (e.g. +# @cldmv/slothlet). Skip this template for tool repos / meta repos. +# +# Fork-PR caveat: builds PR-supplied code, so we use `pull_request` +# (NOT pull_request_target). Fork builds run safely without secrets; +# comment posting fails for fork PRs because the token is read-only. +# Maintainer can run via workflow_dispatch after reviewing the code. +# +# Batch 5.4 from tmp/plan-future-workflows.md. +name: ๐Ÿ“Š Bundle Size + +on: + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + branches: [master, main] + workflow_dispatch: + +permissions: + contents: read + pull-requests: write + +jobs: + diff: + uses: CLDMV/.github/.github/workflows/reusable-bundle-size.yml@v4 + with: + build_command: "npm run build:ci" + dist_paths: "bin/**,src/**,hooks/**,messages/**,docs/**" + # warning_pct: 5 + # warning_bytes: 500 + # comment_mode: "update" + # Optional. Without these, the size-diff comment is posted by + # github-actions[bot]. With these, it's posted by your CLDMV bot App. + # Note: fork PRs can't access org secrets, so the bot attribution only + # applies to same-repo PRs; fork PRs fall back to GITHUB_TOKEN. + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/release-merge.yml b/.github/workflows/release-merge.yml index 78546be..25c832c 100644 --- a/.github/workflows/release-merge.yml +++ b/.github/workflows/release-merge.yml @@ -57,6 +57,7 @@ on: - "๐Ÿงช CI Tests & Build" - "๐Ÿ” CodeQL" - "๐Ÿ”’ Dependency Review" + - "๐Ÿ“Š Bundle Size" - "๐Ÿš€ Next Release (v4)" - "๐Ÿš‘ Hotfixes Release (v4)" - "๐ŸŒฟ Branch Retention" From b3d203b35dacf97d59b2de65c0558c9800bc8765 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 21:34:44 +0000 Subject: [PATCH 11/14] deps: bump the patch group across 1 directory with 7 updates Bumps the patch group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [chalk](https://github.com/chalk/chalk) | `6.0.0` | `6.0.1` | | [@cldmv/eslint-plugin-jsonv](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv) | `1.0.3` | `1.0.10` | | [@cldmv/jsonv](https://github.com/CLDMV/jsonv) | `1.0.7` | `1.0.9` | | [@cldmv/prettier-plugin-jsonv](https://github.com/CLDMV/jsonv-prettier-plugin-jsonv) | `1.0.1` | `1.0.6` | | [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.1` | `5.0.2` | | [prettier](https://github.com/prettier/prettier) | `3.9.8` | `3.9.9` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.2` | Updates `chalk` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/chalk/chalk/releases) - [Commits](https://github.com/chalk/chalk/compare/v6.0.0...v6.0.1) Updates `@cldmv/eslint-plugin-jsonv` from 1.0.3 to 1.0.10 - [Release notes](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/releases) - [Commits](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/commits/v1.0.10) Updates `@cldmv/jsonv` from 1.0.7 to 1.0.9 - [Release notes](https://github.com/CLDMV/jsonv/releases) - [Changelog](https://github.com/CLDMV/jsonv/blob/master/CHANGELOG.md) - [Commits](https://github.com/CLDMV/jsonv/compare/v1.0.7...v1.0.9) Updates `@cldmv/prettier-plugin-jsonv` from 1.0.1 to 1.0.6 - [Release notes](https://github.com/CLDMV/jsonv-prettier-plugin-jsonv/releases) - [Commits](https://github.com/CLDMV/jsonv-prettier-plugin-jsonv/commits/v1.0.6) Updates `@vitest/coverage-v8` from 5.0.1 to 5.0.2 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/coverage-v8) Updates `prettier` from 3.9.8 to 3.9.9 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](https://github.com/prettier/prettier/compare/3.9.8...3.9.9) Updates `vitest` from 5.0.1 to 5.0.2 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest) --- updated-dependencies: - dependency-name: chalk dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patch - dependency-name: "@cldmv/eslint-plugin-jsonv" dependency-version: 1.0.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch - dependency-name: "@cldmv/jsonv" dependency-version: 1.0.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch - dependency-name: "@cldmv/prettier-plugin-jsonv" dependency-version: 1.0.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch - dependency-name: "@vitest/coverage-v8" dependency-version: 5.0.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch - dependency-name: prettier dependency-version: 3.9.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch - dependency-name: vitest dependency-version: 5.0.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch ... Signed-off-by: dependabot[bot] --- package-lock.json | 255 ++++++++++++++++++++++------------------------ 1 file changed, 120 insertions(+), 135 deletions(-) diff --git a/package-lock.json b/package-lock.json index e779116..7af4de4 100644 --- a/package-lock.json +++ b/package-lock.json @@ -127,9 +127,9 @@ } }, "node_modules/@cldmv/eslint-plugin-jsonv": { - "version": "1.0.3", - "resolved": "https://registry.npmjs.org/@cldmv/eslint-plugin-jsonv/-/eslint-plugin-jsonv-1.0.3.tgz", - "integrity": "sha512-P/AHUOaKnOV98qUfbBKgZ85uz3jVRSM/yjc6yKrAjaS5s5BEqpnVxIbQYcvfnPxopcA/IsCsedUjl9E7s3bM8A==", + "version": "1.0.10", + "resolved": "https://registry.npmjs.org/@cldmv/eslint-plugin-jsonv/-/eslint-plugin-jsonv-1.0.10.tgz", + "integrity": "sha512-BtkGK0Jo6nir7GL3JpY6eEAqX/8XzibMgPbT3S+vkhWulVd+47xx+oUwxvaEvj24XyVaIKqloHzAWYtnqXIGDQ==", "dev": true, "license": "Apache-2.0", "engines": { @@ -144,9 +144,9 @@ } }, "node_modules/@cldmv/jsonv": { - "version": "1.0.7", - "resolved": "https://registry.npmjs.org/@cldmv/jsonv/-/jsonv-1.0.7.tgz", - "integrity": "sha512-roUT+c6lz2yBAlumCMufRGNwJs48uG1XWSM0xpSrYw5K13Vrk/OiBKjtXPrDa6ylU0+9qVg5tizLtE0fpKwb6w==", + "version": "1.0.9", + "resolved": "https://registry.npmjs.org/@cldmv/jsonv/-/jsonv-1.0.9.tgz", + "integrity": "sha512-L84D+ocPzCg/Q88HvrVjxt7UMQ6PxHe7kbAj6Uor/eFE0/HkB8xuPoyB+ssa2vRwleFVZ+q3RXLxt8BT1ZM0Ow==", "dev": true, "license": "Apache-2.0", "engines": { @@ -158,11 +158,14 @@ } }, "node_modules/@cldmv/prettier-plugin-jsonv": { - "version": "1.0.1", - "resolved": "https://registry.npmjs.org/@cldmv/prettier-plugin-jsonv/-/prettier-plugin-jsonv-1.0.1.tgz", - "integrity": "sha512-TsgxoXQhGO7aNABbKSd/xcuwrrNtvhvzVtWkiuH6QHOE346x3iZsHtk1IqHq9xPv8Knv/C+53ScYaFjAodhUSQ==", + "version": "1.0.6", + "resolved": "https://registry.npmjs.org/@cldmv/prettier-plugin-jsonv/-/prettier-plugin-jsonv-1.0.6.tgz", + "integrity": "sha512-eRi160SbGfPUl8CELaNBxH34Kp14F3eQ76pvNBbuV4IlyXbEflcecwnY+WKuYooQbNZveR5/hn+76DH117kB8A==", "dev": true, "license": "Apache-2.0", + "engines": { + "node": ">=18.0.0" + }, "funding": { "type": "github", "url": "https://github.com/sponsors/shinrai" @@ -586,9 +589,9 @@ "license": "MIT" }, "node_modules/@oxc-project/types": { - "version": "0.150.0", - "resolved": "https://registry.npmjs.org/@oxc-project/types/-/types-0.150.0.tgz", - "integrity": "sha512-rDS5/31E9HfPl/CIzGrn0DOlvBbXFseQ5URJ9sYMfstbKLD/c6Gm9vmRzRGDdAXyOIL4zmO37lc9RIwYqVruZw==", + "version": "0.151.0", + "resolved": "https://registry.npmjs.org/@oxc-project/types/-/types-0.151.0.tgz", + "integrity": "sha512-J1yXrIlNDZVzE3ada310xeAw7nH8yCAyLPuUIsjKatFPmfn5bS1oW+cM+QsGOtVWd5nhSpbwZWx/rue+r5Z+PA==", "dev": true, "license": "MIT", "peer": true, @@ -597,9 +600,9 @@ } }, "node_modules/@rolldown/binding-android-arm-eabi": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.9.tgz", - "integrity": "sha512-tNISae1QEf/vkb3xkRcjV5SEdzPE97We5IVaa2Z8jSszQPZ8U60B/YCYpw4QI7VidYsBtKavczXf+DyDs9WGxw==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.11.tgz", + "integrity": "sha512-A5kXfGKvKWWZE0TtPrfsvT+q4Y5d1QG8gGUzpYjGydM+fARM9MuX90PrXYXe0XbsDVgyxxNzHo6giCj90bsFNw==", "cpu": [ "arm" ], @@ -615,9 +618,9 @@ } }, "node_modules/@rolldown/binding-android-arm64": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.9.tgz", - "integrity": "sha512-YC8YsI30o606GTZi0VyzYlsDKFP8W61i/QzayHDkLbNEz/IShqAmTa+hsJRj13xTHA0H+6fk4b2UmGn+Q/cMlg==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.11.tgz", + "integrity": "sha512-z6cTycz+iJ4PVkuL4HHW4DfTfoeU/2nqYYuSOrTmH7yHK5Y0LCOnA03V4ZNxavyVaU1oOqUgIg2klN/s+USGOA==", "cpu": [ "arm64" ], @@ -633,9 +636,9 @@ } }, "node_modules/@rolldown/binding-darwin-arm64": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.9.tgz", - "integrity": "sha512-IwhlH3qK5urrY8hZiEgGkHKEFN901p/p2bjxCxJlr4GyNnF7wYpUvK+Y43uaRYuC4hpfjzbR3SJC3arX1jGvmw==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.11.tgz", + "integrity": "sha512-jShvqNtP6vDC6/A5JOAzbVV+DkgHqhl/ScVCJEbt+TUY6QYz7YnXcrg3sLtFBniro0f/Ld50ZwCWA6f7KYD1nQ==", "cpu": [ "arm64" ], @@ -651,9 +654,9 @@ } }, "node_modules/@rolldown/binding-darwin-x64": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.9.tgz", - "integrity": "sha512-XxpJfVzFh+jilRxIXUqcfYAYcunIc/XEzIizsOL1fcJee5Sf7H3mH8WlLmfHfluz5amqR88QQo9izKtmMlavAw==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.11.tgz", + "integrity": "sha512-f2i2xiNWq1Z1l2++q2fuhZRdLAT3aqxD6vRNm1RAxpUoBcdqNB3C0s1Bt+K+PbEx2F5F4gQp6hqKkphCY/xF9w==", "cpu": [ "x64" ], @@ -669,9 +672,9 @@ } }, "node_modules/@rolldown/binding-freebsd-x64": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.9.tgz", - "integrity": "sha512-kSfvhmgeWyfkbT3p/1s5vSgboogoah2zkm9fX2zjg2hHxSV7T4KhMWRUUaRk4OXNqoD3QAUeRqLcs1aZOK4U1g==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.11.tgz", + "integrity": "sha512-4Ir5FSOKIAMr4r0kExpt1s3bMgzJU3rA45AYOHtQpls0oNeqcYBKrWMlckrYH4KCfGLfkfn1tN1dmZPMVsdXow==", "cpu": [ "x64" ], @@ -687,9 +690,9 @@ } }, "node_modules/@rolldown/binding-linux-arm-gnueabihf": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.9.tgz", - "integrity": "sha512-1RVzG17pxqbTfYLC352JlLt6kKLG+6Hr30n8DlIJqsnV5luUDd2Qdx9Ayw1Cabfyb1K9k0jXEZ7evxkRoT+uiw==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.11.tgz", + "integrity": "sha512-/gnRDM+39BROzAN/k1OZjDPnDMcZxB/0EUxKjONO5yVkNEvlsoMDrxGNKgZi/ttFriS2gwlDNzB65pvNbFOXIQ==", "cpu": [ "arm" ], @@ -705,9 +708,9 @@ } }, "node_modules/@rolldown/binding-linux-arm64-gnu": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.9.tgz", - "integrity": "sha512-BXqPvZ2drqVD+/Z8UpKwcs4Mp7grM+eGFku4CAEKrEtcbAsUpzREphK1sogCRZGreVPiMkiiBtw0n3TPteuqvw==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.11.tgz", + "integrity": "sha512-PFaK8HwvAHbaKbBcDNQihjMKYvFnA5hiENx/l5tphTDz1E0WFp32l0A7aq7lyUwGsRw/xSrNIy/gIK4thrSCrw==", "cpu": [ "arm64" ], @@ -726,9 +729,9 @@ } }, "node_modules/@rolldown/binding-linux-arm64-musl": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.9.tgz", - "integrity": "sha512-11vWvo8YDwLzukt27J3aYDWU+gg2P7J+ZOmiJ0hkF5BXZDW7pVya7r40MXDy6ya0i9KamoENSVKIugvJNgFXIA==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.11.tgz", + "integrity": "sha512-AskzJUIKRLPxkruR1wLKewGbOw+EYfU/9lOrBFj4AFrEA8hPpKFnODWNu2WLaNs0QNkEb9QIJufmVZZIL/bJlg==", "cpu": [ "arm64" ], @@ -747,9 +750,9 @@ } }, "node_modules/@rolldown/binding-linux-ppc64-gnu": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.9.tgz", - "integrity": "sha512-a1tijMkdwsIARtc0F39ApURROkf3NwqinI6TOiSSWCTR7dT96dffNvMUtDHnq64wKNTIZOIlzKrFvvFUznJiyw==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.11.tgz", + "integrity": "sha512-qlUGAheh2yh8afH7QBgx0PrRHN85hKnNd78x8MeMhXivuevgd8vgf6/CstOzmNKY/lLTHvNTrPy98cLnAugzJw==", "cpu": [ "ppc64" ], @@ -768,9 +771,9 @@ } }, "node_modules/@rolldown/binding-linux-s390x-gnu": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.9.tgz", - "integrity": "sha512-x6SQNdAvv4c3hWqTMaWuawzMX9myaCs/yEmlGsxJzkdClnHW7FbrjQuSiRDhuSYzEYoEMhsaJy9qHG/XNemJPQ==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.11.tgz", + "integrity": "sha512-secpEad+0vCbSfn8upFySkDskv+bGPk3THSDS9Y89yc4rb4kzqHp8Dmyd9BkQW4SnhNXBZCl/6CrO//hZahNJQ==", "cpu": [ "s390x" ], @@ -808,9 +811,9 @@ } }, "node_modules/@rolldown/binding-linux-x64-musl": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.9.tgz", - "integrity": "sha512-P7VWAmV+WdJluH7ovnRGoiv2i8To7GAZ+kGzfGup635cyL7SyYl3lSUaA3Gp5THf0n/Co5EyEqb2zbqq+nMOHQ==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.11.tgz", + "integrity": "sha512-Is78i9A8Ui4SqcxUwFJ9uMmjDn58IbVTjFWYdQestFEgeuEmHMLGNriXnVJKkwG2YiZjw8cP0zCTyDMdDGtOOg==", "cpu": [ "x64" ], @@ -829,9 +832,9 @@ } }, "node_modules/@rolldown/binding-openharmony-arm64": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.9.tgz", - "integrity": "sha512-1qixtsE4BK8h+yS3BfmZ09UhA7O/N4IACva6YBr7EBvCJraByTuRcgOTaiA62Tm0vey3UcKXLOaoGHtYmNGEVg==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.11.tgz", + "integrity": "sha512-dUCXneZ87INUMyQ0D+C0HrEBNUPNXHaPmU5GTjyKTJEiussw9Kaj5Ln8UztPe4epV/ffvgNBEadksdYhmW6xJA==", "cpu": [ "arm64" ], @@ -847,9 +850,9 @@ } }, "node_modules/@rolldown/binding-win32-arm64-msvc": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.9.tgz", - "integrity": "sha512-ok8IQjcEPs1AKZfuEUznVBrJw+gK4soq+bx8b1X2XoMqVClarc1q5JDmVtWXY1xfr6ZuHTAsPXHTgTrqKTZeww==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.11.tgz", + "integrity": "sha512-jByxb6qfd+bH1xUd0qnfFnb17i9sWBPY2tOavJ0l3tdr3OTu+Kvtm8cd/JV5nFt657b1VqGltxg9olOEfofXWw==", "cpu": [ "arm64" ], @@ -865,9 +868,9 @@ } }, "node_modules/@rolldown/binding-win32-x64-msvc": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.9.tgz", - "integrity": "sha512-Ip2mXoU0hM0boq3Rf+ekuT653OROSo6aSYcPT1VHE4q52KvyxgFkQgrgb/IEsxOuvQ2fZZbs8khJAyCEPM24/g==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.11.tgz", + "integrity": "sha512-/PzKqzAJ03i19oy2ItPvyvaVjOjBCNnfaJs8yvUdGBKmiESgnrJSQ2awd81QzFbbnAmu7YO9ZnJrDCb9VSJPRA==", "cpu": [ "x64" ], @@ -993,9 +996,9 @@ "license": "MIT" }, "node_modules/@vitest/coverage-v8": { - "version": "5.0.1", - "resolved": "https://registry.npmjs.org/@vitest/coverage-v8/-/coverage-v8-5.0.1.tgz", - "integrity": "sha512-FRC8ACiudC3dI6MTplzRSYWHDRnIv2IPfbzs4FdoJNsMal/35sWV8hwIfV8ZcqzSPy+uXHeMVONt9CEqtOU17w==", + "version": "5.0.2", + "resolved": "https://registry.npmjs.org/@vitest/coverage-v8/-/coverage-v8-5.0.2.tgz", + "integrity": "sha512-3ffHBEi8DOOBLwIGBhOBZbRfYFYWjMUuxZicONdhuFEFEG5AVsMOSrVeuROskqnqpbOmEJwxM2eTVZ9N3a1t+A==", "dev": true, "license": "MIT", "dependencies": { @@ -1012,8 +1015,8 @@ "url": "https://opencollective.com/vitest" }, "peerDependencies": { - "@vitest/browser": "5.0.1", - "vitest": "5.0.1" + "@vitest/browser": "5.0.2", + "vitest": "5.0.2" }, "peerDependenciesMeta": { "@vitest/browser": { @@ -1045,14 +1048,14 @@ } }, "node_modules/@vitest/mocker": { - "version": "5.0.1", - "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-5.0.1.tgz", - "integrity": "sha512-6K1DoBNAPGvuOcSsGA4D6x+5zEEff/KmOOP3uetT2TrGpVfI+HRHRnJJfKi5ib/g1vx8IYHQD8s0pbJz8WQI7Q==", + "version": "5.0.2", + "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-5.0.2.tgz", + "integrity": "sha512-Z5FS00Q1SJHkB35xATsmWGdQ5WA1/0MV3CDjqyv7GavHv1OfOj145MNfHOlHk7QLes21dKFDHr8EO2zvL+9WGA==", "dev": true, "license": "MIT", "dependencies": { "@jridgewell/trace-mapping": "0.3.31", - "@vitest/spy": "5.0.1", + "@vitest/spy": "5.0.2", "estree-walker": "^3.0.3", "magic-string": "^1.2.3" }, @@ -1073,9 +1076,9 @@ } }, "node_modules/@vitest/spy": { - "version": "5.0.1", - "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-5.0.1.tgz", - "integrity": "sha512-rbto/mF/SGERxEgYOek7Xm6B9b+y+mVoo+f4b2LymYO8zM1b7uB5nHuhVMTP2hxdzgxvGiZYGxGIaMvL5y180Q==", + "version": "5.0.2", + "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-5.0.2.tgz", + "integrity": "sha512-Ijc7T1nT9efNb5LxvjaBrEqw3f/QwUv5EE0nKqZxgqsaV/FxAAZ8baGylA8X/Z2oS4Lp+K74Jr6dTJsDKxJDeg==", "dev": true, "license": "MIT", "funding": { @@ -1251,9 +1254,9 @@ } }, "node_modules/chalk": { - "version": "6.0.0", - "resolved": "https://registry.npmjs.org/chalk/-/chalk-6.0.0.tgz", - "integrity": "sha512-2uNTXIuTTxk7ciZgAU1BQcgnchcG0xXnrs6jzkQfj9SsRa9M2s5zE8WT96hS6KmG4MzWHSrvH43DF1m4XRkrFg==", + "version": "6.0.1", + "resolved": "https://registry.npmjs.org/chalk/-/chalk-6.0.1.tgz", + "integrity": "sha512-/Ce6KNm3vIbWdMlNna6RVIZ/ICQxnJxCicet5LBKK9ZffBkqzDw0xh9EiKSljdRtiIQ1S1z4YgcscUUGzNCWrA==", "license": "MIT", "engines": { "node": ">=22" @@ -2337,9 +2340,9 @@ } }, "node_modules/magic-string": { - "version": "1.4.1", - "resolved": "https://registry.npmjs.org/magic-string/-/magic-string-1.4.1.tgz", - "integrity": "sha512-8lyCu36ErXR0J9uaGKlKQoiLZKmtI63YGLE8G2o9jyRPdr4X47LusSOwgOJOzcVtp81fTAAjxR7BwKz682Jhow==", + "version": "1.4.2", + "resolved": "https://registry.npmjs.org/magic-string/-/magic-string-1.4.2.tgz", + "integrity": "sha512-vG+rjFRj1PqdIBozIxAGMjPlOhaVe+GXpbttY/iSK7rGcJRMlwNJO7dcUwmUqkymsFLJiNGI06t4D7Fr7yRC9g==", "dev": true, "license": "MIT", "dependencies": { @@ -3566,9 +3569,9 @@ } }, "node_modules/prettier": { - "version": "3.9.8", - "resolved": "https://registry.npmjs.org/prettier/-/prettier-3.9.8.tgz", - "integrity": "sha512-WRFq3Wn3WId7LLROfMLdH7xaFr2jR62wU8nLO6rQUOLOxNZUviyJQs1M0iIhLexSFy+L+w0ch66wtoO2jRjG0A==", + "version": "3.9.9", + "resolved": "https://registry.npmjs.org/prettier/-/prettier-3.9.9.tgz", + "integrity": "sha512-Z/CJHIkdujO/OtN7nXUii0Rf3VT5SRuhjBA82Xvu2XhBUgX3nhP67T0LHceBdQLex7OOFGTox+Q5Yg8Jk2Qivg==", "dev": true, "license": "MIT", "bin": { @@ -3621,14 +3624,14 @@ } }, "node_modules/rolldown": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/rolldown/-/rolldown-1.2.9.tgz", - "integrity": "sha512-hx/Pv0N1haXRb11qkfnK5MXB/iqr7i0yjWQqmO9uHqZpBgQSqzc8UsSnEpalsh+j1I8qQ2CkXAkJC8Br3dKSlg==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/rolldown/-/rolldown-1.2.11.tgz", + "integrity": "sha512-qpSwIyz0jHQq5qXBTNxFmE6664rJ7O+4TvPFOiOaBSrz8IOHc1koKKSqTM2H6u1UG1+TveuC6vaDHKXFOvb1Kw==", "dev": true, "license": "MIT", "peer": true, "dependencies": { - "@oxc-project/types": "=0.150.0", + "@oxc-project/types": "=0.151.0", "@rolldown/pluginutils": "^1.0.0" }, "bin": { @@ -3638,27 +3641,27 @@ "node": "^20.19.0 || >=22.12.0" }, "optionalDependencies": { - "@rolldown/binding-android-arm-eabi": "1.2.9", - "@rolldown/binding-android-arm64": "1.2.9", - "@rolldown/binding-darwin-arm64": "1.2.9", - "@rolldown/binding-darwin-x64": "1.2.9", - "@rolldown/binding-freebsd-x64": "1.2.9", - "@rolldown/binding-linux-arm-gnueabihf": "1.2.9", - "@rolldown/binding-linux-arm64-gnu": "1.2.9", - "@rolldown/binding-linux-arm64-musl": "1.2.9", - "@rolldown/binding-linux-ppc64-gnu": "1.2.9", - "@rolldown/binding-linux-s390x-gnu": "1.2.9", - "@rolldown/binding-linux-x64-gnu": "1.2.9", - "@rolldown/binding-linux-x64-musl": "1.2.9", - "@rolldown/binding-openharmony-arm64": "1.2.9", - "@rolldown/binding-win32-arm64-msvc": "1.2.9", - "@rolldown/binding-win32-x64-msvc": "1.2.9" + "@rolldown/binding-android-arm-eabi": "1.2.11", + "@rolldown/binding-android-arm64": "1.2.11", + "@rolldown/binding-darwin-arm64": "1.2.11", + "@rolldown/binding-darwin-x64": "1.2.11", + "@rolldown/binding-freebsd-x64": "1.2.11", + "@rolldown/binding-linux-arm-gnueabihf": "1.2.11", + "@rolldown/binding-linux-arm64-gnu": "1.2.11", + "@rolldown/binding-linux-arm64-musl": "1.2.11", + "@rolldown/binding-linux-ppc64-gnu": "1.2.11", + "@rolldown/binding-linux-s390x-gnu": "1.2.11", + "@rolldown/binding-linux-x64-gnu": "1.2.11", + "@rolldown/binding-linux-x64-musl": "1.2.11", + "@rolldown/binding-openharmony-arm64": "1.2.11", + "@rolldown/binding-win32-arm64-msvc": "1.2.11", + "@rolldown/binding-win32-x64-msvc": "1.2.11" } }, "node_modules/rolldown/node_modules/@rolldown/binding-linux-x64-gnu": { - "version": "1.2.9", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.9.tgz", - "integrity": "sha512-9s0AZ8BFK5/n7B/TBoa2yJE3gI3KURrbXcPBlsAsvjU4VeJKgE90y1YtNxyEUIcHPQkg6/yfF3qihUrcM/Kf0Q==", + "version": "1.2.11", + "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.11.tgz", + "integrity": "sha512-mOVBT3dPpkWm8XBWPmU4bf+U6dYDLeMo/9ojUmis4N0L5uu10qra5vOyngZ7/PSdoE4G9KvRt4bloRxNjLas7A==", "cpu": [ "x64" ], @@ -3699,13 +3702,6 @@ "node": ">=8" } }, - "node_modules/siginfo": { - "version": "2.0.0", - "resolved": "https://registry.npmjs.org/siginfo/-/siginfo-2.0.0.tgz", - "integrity": "sha512-ybx0WO1/8bSBLEWXZvEd7gMW3Sn3JFlW3TvX1nREbDLRNQNaeNN8WK0meBwPdAaOI7TtRRRJn/Es1zhrrCHu7g==", - "dev": true, - "license": "ISC" - }, "node_modules/skin-tone": { "version": "2.0.0", "resolved": "https://registry.npmjs.org/skin-tone/-/skin-tone-2.0.0.tgz", @@ -3728,13 +3724,6 @@ "node": ">=0.10.0" } }, - "node_modules/stackback": { - "version": "0.0.2", - "resolved": "https://registry.npmjs.org/stackback/-/stackback-0.0.2.tgz", - "integrity": "sha512-1XMJE5fQo1jGH6Y/7ebnwPOBEkIEnT4QF32d5R1+VXdXveM0IBMJt8zfaxX1P3QhVwrYe+576+jkANtSS2mBbw==", - "dev": true, - "license": "MIT" - }, "node_modules/std-env": { "version": "4.2.0", "resolved": "https://registry.npmjs.org/std-env/-/std-env-4.2.0.tgz", @@ -3980,9 +3969,9 @@ } }, "node_modules/vite": { - "version": "8.3.0", - "resolved": "https://registry.npmjs.org/vite/-/vite-8.3.0.tgz", - "integrity": "sha512-lhZBVvEHefgE+HQZC9O7EBJgCU/nVzFNl7vkS4RE0APtWLP02/8QVIkQtzBxPquh7lq5/78NHipTj7ODQ6XuyQ==", + "version": "8.3.1", + "resolved": "https://registry.npmjs.org/vite/-/vite-8.3.1.tgz", + "integrity": "sha512-/bvH9E9tmCXRGp2uXY3WbOldqpTwFkbha/8ANaEQ6VkxhH60KyqLwgZq6lG2y+4uT55x9+9eUHMpQ7uGnOCKjA==", "dev": true, "license": "MIT", "peer": true, @@ -3990,7 +3979,7 @@ "lightningcss": "^1.33.0", "picomatch": "^4.0.7", "postcss": "^8.5.28", - "rolldown": "~1.2.6", + "rolldown": "~1.2.9", "tinyglobby": "^0.2.17" }, "bin": { @@ -4059,14 +4048,14 @@ } }, "node_modules/vitest": { - "version": "5.0.1", - "resolved": "https://registry.npmjs.org/vitest/-/vitest-5.0.1.tgz", - "integrity": "sha512-iA95lQbKEkvrtTkdAgnWbXfbipWiiWe/hDl2P5tMi6WFwD76G0NxXAGp/M9EOcYupeGJRr6wppMc7CoA41TQjg==", + "version": "5.0.2", + "resolved": "https://registry.npmjs.org/vitest/-/vitest-5.0.2.tgz", + "integrity": "sha512-7MQrx9pDv5aHiUcovIb/70Ys3tgtkUVgCtledvKdCmEO+/1Dicq5ZqoSxOW034m03oqC+oHOKui2dM6qtMLoJg==", "dev": true, "license": "MIT", "dependencies": { "@types/chai": "^5.2.2", - "@vitest/mocker": "5.0.1", + "@vitest/mocker": "5.0.2", "chai": "^6.2.2", "es-module-lexer": "^2.3.2", "expect-type": "^1.4.0", @@ -4074,10 +4063,10 @@ "obug": "^2.1.4", "picomatch": "^4.0.7", "std-env": "^4.2.0", - "tinybench": "6.1.4", - "tinyexec": "1.3.0", + "tinybench": "^6.1.4", + "tinyexec": "^1.3.0", "tinyglobby": "^0.2.17", - "why-is-node-running": "^2.3.0" + "why-is-node-running": "^3.2.1" }, "bin": { "vitest": "vitest.mjs" @@ -4092,12 +4081,12 @@ "@edge-runtime/vm": "*", "@opentelemetry/api": "^1.9.0", "@types/node": "^22.0.0 || >=24.0.0", - "@vitest/browser-playwright": "5.0.1", - "@vitest/browser-preview": "5.0.1", + "@vitest/browser-playwright": "5.0.2", + "@vitest/browser-preview": "5.0.2", "@vitest/browser-webdriverio": "^5.0.0-beta.5 || >=5.0.0", - "@vitest/coverage-istanbul": "5.0.1", - "@vitest/coverage-v8": "5.0.1", - "@vitest/ui": "5.0.1", + "@vitest/coverage-istanbul": "5.0.2", + "@vitest/coverage-v8": "5.0.2", + "@vitest/ui": "5.0.2", "happy-dom": "*", "jsdom": "*", "vite": "^6.4.0 || ^7.0.0 || ^8.0.0" @@ -4158,20 +4147,16 @@ } }, "node_modules/why-is-node-running": { - "version": "2.3.0", - "resolved": "https://registry.npmjs.org/why-is-node-running/-/why-is-node-running-2.3.0.tgz", - "integrity": "sha512-hUrmaWBdVDcxvYqnyh09zunKzROWjbZTiNy8dBEjkS7ehEDQibXJ7XvlmtbwuTclUiIyN+CyXQD4Vmko8fNm8w==", + "version": "3.2.2", + "resolved": "https://registry.npmjs.org/why-is-node-running/-/why-is-node-running-3.2.2.tgz", + "integrity": "sha512-NKUzAelcoCXhXL4dJzKIwXeR8iEVqsA0Lq6Vnd0UXvgaKbzVo4ZTHROF2Jidrv+SgxOQ03fMinnNhzZATxOD3A==", "dev": true, "license": "MIT", - "dependencies": { - "siginfo": "^2.0.0", - "stackback": "0.0.2" - }, "bin": { "why-is-node-running": "cli.js" }, "engines": { - "node": ">=8" + "node": ">=20.11" } }, "node_modules/word-wrap": { From 2339b59977f5cc64b7dbf13526056456890d850d Mon Sep 17 00:00:00 2001 From: Shinrai Date: Fri, 2 Oct 2026 12:26:58 -0700 Subject: [PATCH 12/14] chore: adopt the shared CLDMV fix-headers config and stamp uniform file headers --- .configs/eslint.config.mjs | 15 +++++++ .configs/fix-headers.json | 3 ++ .configs/tsconfig.dts.jsonc | 19 ++------ .configs/vitest.config.mjs | 15 +++++++ .github/dependabot.yml | 16 ++++--- .github/workflows/branch-retention.yml | 16 ++++--- .github/workflows/bundle-size.yml | 16 ++++--- .github/workflows/ci.yml | 16 ++++--- .github/workflows/cla.yml | 16 ++++--- .github/workflows/codeql.yml | 16 ++++--- .github/workflows/dependabot-auto-merge.yml | 16 ++++--- .github/workflows/dependabot-recreate.yml | 16 ++++--- .github/workflows/dependency-review.yml | 16 ++++--- .github/workflows/feature-pr.yml | 15 ++++--- .github/workflows/hotfix-redirector.yml | 16 ++++--- .github/workflows/hotfixes-release.yml | 16 ++++--- .github/workflows/labeler.yml | 16 ++++--- .github/workflows/master-commit-audit.yml | 16 ++++--- .github/workflows/member-auto-merge.yml | 16 ++++--- .github/workflows/next-release.yml | 16 ++++--- .github/workflows/next-reset.yml | 16 ++++--- .github/workflows/pr-notify.yml | 16 ++++--- .github/workflows/pr-title-normalizer.yml | 16 ++++--- .github/workflows/provenance.yml | 16 ++++--- .github/workflows/publish.yml | 16 ++++--- .github/workflows/release-merge.yml | 15 ++++--- .github/workflows/release-notify.yml | 16 ++++--- .github/workflows/scorecard.yml | 16 ++++--- .github/workflows/stale.yml | 16 ++++--- .github/workflows/tag-health.yml | 16 ++++--- .../workflows/update-major-version-tags.yml | 16 ++++--- .github/workflows/v4-bootstrap.yml | 16 ++++--- .github/workflows/welcome.yml | 16 ++++--- bin/git-embedded.mjs | 14 ++++++ package-lock.json | 43 +++++++++++++++++++ package.json | 5 ++- src/api/cli/doctor.mjs | 15 +++++++ src/api/cli/export.mjs | 15 +++++++ src/api/cli/init.mjs | 15 +++++++ src/api/cli/install-hooks.mjs | 15 +++++++ src/api/cli/install-template.mjs | 15 +++++++ src/api/cli/link.mjs | 15 +++++++ src/api/cli/print-hook-script.mjs | 15 +++++++ src/api/cli/record.mjs | 15 +++++++ src/api/cli/restore.mjs | 15 +++++++ src/api/cli/sync.mjs | 15 +++++++ src/api/cli/uninstall-hooks.mjs | 15 +++++++ src/api/cli/version.mjs | 15 +++++++ src/api/commander/custom-help.mjs | 15 +++++++ src/api/detect/dispatcher.mjs | 15 +++++++ src/api/detect/husky.mjs | 15 +++++++ src/api/detect/lefthook.mjs | 15 +++++++ src/api/detect/pre-commit.mjs | 15 +++++++ src/api/detect/run.mjs | 15 +++++++ src/api/detect/simple-git-hooks.mjs | 15 +++++++ src/api/embedded/branch.mjs | 15 +++++++ src/api/embedded/gitlinks.mjs | 15 +++++++ src/api/embedded/manifest.mjs | 15 +++++++ src/api/embedded/record.mjs | 15 +++++++ src/api/embedded/registry.mjs | 15 +++++++ src/api/embedded/resolve.mjs | 15 +++++++ src/api/embedded/restore.mjs | 15 +++++++ src/api/embedded/sync.mjs | 15 +++++++ src/api/git.mjs | 15 +++++++ src/api/install/dispatcher.mjs | 15 +++++++ src/api/install/hooks.mjs | 15 +++++++ src/api/install/template.mjs | 15 +++++++ src/api/link/batch.mjs | 15 +++++++ src/api/link/copy-executable.mjs | 15 +++++++ src/api/link/elevate-windows.mjs | 15 +++++++ src/api/log.mjs | 15 +++++++ src/api/messages/load.mjs | 15 +++++++ src/api/paths.mjs | 15 +++++++ src/api/prompt.mjs | 15 +++++++ src/api/report.mjs | 15 +++++++ src/lib/elevate-windows-child.mjs | 15 +++++++ tests/_setup.mjs | 15 +++++++ tests/cli-coverage.test.vitest.mjs | 28 ++++-------- tests/cli-hooks.test.vitest.mjs | 21 ++++----- tests/cli-provisioning.test.vitest.mjs | 15 +++++++ tests/commander-help.test.vitest.mjs | 15 +++++++ tests/detect-coverage.test.vitest.mjs | 37 ++++------------ tests/detect-foreign.test.vitest.mjs | 15 +++++++ tests/detect-hooks.test.vitest.mjs | 26 ++++------- tests/dispatcher-classify.test.vitest.mjs | 15 +++++++ tests/embedded-coverage.test.vitest.mjs | 15 +++++++ tests/embedded-provisioning.test.vitest.mjs | 15 +++++++ tests/embedded-topup.test.vitest.mjs | 15 +++++++ tests/helpers.test.vitest.mjs | 15 +++++++ tests/hook-guards.test.vitest.mjs | 23 ++++------ tests/install-hooks.test.vitest.mjs | 15 +++++++ tests/install-link.test.vitest.mjs | 25 ++++------- tests/link-coverage.test.vitest.mjs | 27 ++++-------- tests/root-coverage.test.vitest.mjs | 15 +++++++ tests/run-vitest.mjs | 15 +++++++ 95 files changed, 1224 insertions(+), 319 deletions(-) create mode 100644 .configs/fix-headers.json diff --git a/.configs/eslint.config.mjs b/.configs/eslint.config.mjs index 2fcff2f..ad7ba47 100644 --- a/.configs/eslint.config.mjs +++ b/.configs/eslint.config.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /.configs/eslint.config.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:07-07:00 (1790968807) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import js from "@eslint/js"; import globals from "globals"; import json from "@eslint/json"; diff --git a/.configs/fix-headers.json b/.configs/fix-headers.json new file mode 100644 index 0000000..f5dd35f --- /dev/null +++ b/.configs/fix-headers.json @@ -0,0 +1,3 @@ +{ + "extends": "@cldmv/configs/fix-headers.json" +} diff --git a/.configs/tsconfig.dts.jsonc b/.configs/tsconfig.dts.jsonc index 96bf4cf..974a9dd 100644 --- a/.configs/tsconfig.dts.jsonc +++ b/.configs/tsconfig.dts.jsonc @@ -1,27 +1,16 @@ /** - * @Project: @cldmv/slothlet + * + * @Project: @cldmv/git-embedded * @Filename: /.configs/tsconfig.dts.jsonc * @Date: 2025-09-09T08:06:19-07:00 (1757430379) * @Author: Nate Corcoran * @Email: * ----- * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) - * @Last modified time: 2026-04-28 00:45:54 -07:00 (1777362354) + * @Last modified time: 2026-10-02T12:20:07-07:00 (1790968807) * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. - */ - -/* - * @Project: @cldmv/slothlet - * @Filename: /.configs/tsconfig.dts.jsonc - * @Date: 2025-09-09T08:06:19-07:00 (1757430379) - * @Author: Nate Corcoran - * @Email: - * ----- - * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) - * @Last modified time: 2026-04-28 00:44:01 -07:00 (1777362241) - * ----- - * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * */ { diff --git a/.configs/vitest.config.mjs b/.configs/vitest.config.mjs index 649a048..68e33cc 100644 --- a/.configs/vitest.config.mjs +++ b/.configs/vitest.config.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /.configs/vitest.config.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:07-07:00 (1790968807) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { defineConfig } from "vitest/config"; import { fileURLToPath } from "node:url"; import path from "node:path"; diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 77dbc1b..0bcfe57 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/dependabot.yml -# @Date: 2026-05-26 00:00:00 -07:00 (1782460800) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/dependabot.yml +# @Date: 2026-05-26T00:00:00-07:00 (1779778800) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:07-07:00 (1790968807) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/dependabot.yml diff --git a/.github/workflows/branch-retention.yml b/.github/workflows/branch-retention.yml index fd6c51f..9298813 100644 --- a/.github/workflows/branch-retention.yml +++ b/.github/workflows/branch-retention.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/branch-retention.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/branch-retention.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:07-07:00 (1790968807) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/branch-retention.yml diff --git a/.github/workflows/bundle-size.yml b/.github/workflows/bundle-size.yml index f1fc4c7..b84262f 100644 --- a/.github/workflows/bundle-size.yml +++ b/.github/workflows/bundle-size.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/bundle-size.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/bundle-size.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:07-07:00 (1790968807) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/bundle-size.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1ebf523..b181d18 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/ci.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/ci.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:08-07:00 (1790968808) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/ci.yml diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index 1b84f47..ab65837 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/cla.yml -# @Date: 2026-07-19 00:00:00 -07:00 (1784523600) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/cla.yml +# @Date: 2026-07-19T00:00:00-07:00 (1784444400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:08-07:00 (1790968808) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/cla.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 1c705ed..3f8b9dd 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/codeql.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/codeql.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:08-07:00 (1790968808) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/codeql.yml diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index ada21db..842587b 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/dependabot-auto-merge.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/dependabot-auto-merge.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:08-07:00 (1790968808) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/dependabot-auto-merge.yml diff --git a/.github/workflows/dependabot-recreate.yml b/.github/workflows/dependabot-recreate.yml index 12ca937..55c5d03 100644 --- a/.github/workflows/dependabot-recreate.yml +++ b/.github/workflows/dependabot-recreate.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/dependabot-recreate.yml -# @Date: 2026-07-31 00:00:00 -07:00 (1785481200) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/dependabot-recreate.yml +# @Date: 2026-07-31T00:00:00-07:00 (1785481200) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:08-07:00 (1790968808) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/dependabot-recreate.yml diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 72227a5..9ece48b 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/dependency-review.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/dependency-review.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:08-07:00 (1790968808) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/dependency-review.yml diff --git a/.github/workflows/feature-pr.yml b/.github/workflows/feature-pr.yml index 1b7f7c1..1f30d7e 100644 --- a/.github/workflows/feature-pr.yml +++ b/.github/workflows/feature-pr.yml @@ -1,9 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/feature-pr.yml -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/feature-pr.yml +# @Date: 2026-07-18T23:04:02-07:00 (1784441042) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:08-07:00 (1790968808) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/feature-pr.yml diff --git a/.github/workflows/hotfix-redirector.yml b/.github/workflows/hotfix-redirector.yml index c9980ae..03792ba 100644 --- a/.github/workflows/hotfix-redirector.yml +++ b/.github/workflows/hotfix-redirector.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/hotfix-redirector.yml -# @Date: 2026-05-22 00:00:00 -07:00 (1779778800) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/hotfix-redirector.yml +# @Date: 2026-05-22T00:00:00-07:00 (1779433200) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:09-07:00 (1790968809) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/hotfix-redirector.yml diff --git a/.github/workflows/hotfixes-release.yml b/.github/workflows/hotfixes-release.yml index 42d71e4..2b481c5 100644 --- a/.github/workflows/hotfixes-release.yml +++ b/.github/workflows/hotfixes-release.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/hotfixes-release.yml -# @Date: 2026-05-22 00:00:00 -07:00 (1779778800) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/hotfixes-release.yml +# @Date: 2026-05-22T00:00:00-07:00 (1779433200) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:09-07:00 (1790968809) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/hotfixes-release.yml diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml index 72cbbbc..7a0d283 100644 --- a/.github/workflows/labeler.yml +++ b/.github/workflows/labeler.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/labeler.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/labeler.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:09-07:00 (1790968809) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/labeler.yml diff --git a/.github/workflows/master-commit-audit.yml b/.github/workflows/master-commit-audit.yml index e6447a7..1396d4b 100644 --- a/.github/workflows/master-commit-audit.yml +++ b/.github/workflows/master-commit-audit.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/master-commit-audit.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/master-commit-audit.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:09-07:00 (1790968809) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/master-commit-audit.yml diff --git a/.github/workflows/member-auto-merge.yml b/.github/workflows/member-auto-merge.yml index edd5334..f832d16 100644 --- a/.github/workflows/member-auto-merge.yml +++ b/.github/workflows/member-auto-merge.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/member-auto-merge.yml -# @Date: 2026-05-28 00:00:00 -07:00 (1780210800) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/member-auto-merge.yml +# @Date: 2026-05-28T00:00:00-07:00 (1779951600) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:09-07:00 (1790968809) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/member-auto-merge.yml diff --git a/.github/workflows/next-release.yml b/.github/workflows/next-release.yml index 0ffbb3b..93bb416 100644 --- a/.github/workflows/next-release.yml +++ b/.github/workflows/next-release.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/next-release.yml -# @Date: 2026-05-22 00:00:00 -07:00 (1779778800) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/next-release.yml +# @Date: 2026-05-22T00:00:00-07:00 (1779433200) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:09-07:00 (1790968809) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/next-release.yml diff --git a/.github/workflows/next-reset.yml b/.github/workflows/next-reset.yml index 5f0c498..336db10 100644 --- a/.github/workflows/next-reset.yml +++ b/.github/workflows/next-reset.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/next-reset.yml -# @Date: 2026-05-22 00:00:00 -07:00 (1779778800) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/next-reset.yml +# @Date: 2026-05-22T00:00:00-07:00 (1779433200) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:10-07:00 (1790968810) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/next-reset.yml diff --git a/.github/workflows/pr-notify.yml b/.github/workflows/pr-notify.yml index 549d55d..8cde42f 100644 --- a/.github/workflows/pr-notify.yml +++ b/.github/workflows/pr-notify.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/pr-notify.yml -# @Date: 2026-05-26 00:00:00 -07:00 (1780124400) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/pr-notify.yml +# @Date: 2026-05-26T00:00:00-07:00 (1779778800) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:10-07:00 (1790968810) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/pr-notify.yml diff --git a/.github/workflows/pr-title-normalizer.yml b/.github/workflows/pr-title-normalizer.yml index 9f91d8c..c4fd869 100644 --- a/.github/workflows/pr-title-normalizer.yml +++ b/.github/workflows/pr-title-normalizer.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/pr-title-normalizer.yml -# @Date: 2026-05-22 00:00:00 -07:00 (1779778800) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/pr-title-normalizer.yml +# @Date: 2026-05-22T00:00:00-07:00 (1779433200) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:10-07:00 (1790968810) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/pr-title-normalizer.yml diff --git a/.github/workflows/provenance.yml b/.github/workflows/provenance.yml index 12d9255..caa2836 100644 --- a/.github/workflows/provenance.yml +++ b/.github/workflows/provenance.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/provenance.yml -# @Date: 2026-09-05 00:00:00 -07:00 (1788591600) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/provenance.yml +# @Date: 2026-09-05T00:00:00-07:00 (1788591600) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:10-07:00 (1790968810) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # SLSA build provenance (.intoto.jsonl) for this repo's published releases. diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 3cc34a4..4f7ff55 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/publish.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/publish.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:10-07:00 (1790968810) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/publish.yml diff --git a/.github/workflows/release-merge.yml b/.github/workflows/release-merge.yml index 25c832c..69863ec 100644 --- a/.github/workflows/release-merge.yml +++ b/.github/workflows/release-merge.yml @@ -1,9 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/release-merge.yml -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/release-merge.yml +# @Date: 2026-09-27T12:52:17-07:00 (1790538737) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:11-07:00 (1790968811) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/release-merge.yml diff --git a/.github/workflows/release-notify.yml b/.github/workflows/release-notify.yml index 8956a1e..198a2ef 100644 --- a/.github/workflows/release-notify.yml +++ b/.github/workflows/release-notify.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/release-notify.yml -# @Date: 2026-07-19 00:00:00 -07:00 (1784523600) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/release-notify.yml +# @Date: 2026-07-19T00:00:00-07:00 (1784444400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:11-07:00 (1790968811) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/release-notify.yml diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index d2221ef..61ff976 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/scorecard.yml -# @Date: 2026-07-19 00:00:00 -07:00 (1784523600) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/scorecard.yml +# @Date: 2026-07-19T00:00:00-07:00 (1784444400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:11-07:00 (1790968811) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/scorecard.yml diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index 989998e..199a4af 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/stale.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/stale.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:12-07:00 (1790968812) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/stale.yml diff --git a/.github/workflows/tag-health.yml b/.github/workflows/tag-health.yml index cd1b2b3..e85f8ca 100644 --- a/.github/workflows/tag-health.yml +++ b/.github/workflows/tag-health.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/tag-health.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/tag-health.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:12-07:00 (1790968812) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/tag-health.yml diff --git a/.github/workflows/update-major-version-tags.yml b/.github/workflows/update-major-version-tags.yml index 96e54bc..fefa866 100644 --- a/.github/workflows/update-major-version-tags.yml +++ b/.github/workflows/update-major-version-tags.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/update-major-version-tags.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/update-major-version-tags.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:12-07:00 (1790968812) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/update-major-version-tags.yml diff --git a/.github/workflows/v4-bootstrap.yml b/.github/workflows/v4-bootstrap.yml index 808b248..ea5ff73 100644 --- a/.github/workflows/v4-bootstrap.yml +++ b/.github/workflows/v4-bootstrap.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/v4-bootstrap.yml -# @Date: 2026-05-26 00:00:00 -07:00 (1780124400) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/v4-bootstrap.yml +# @Date: 2026-05-26T00:00:00-07:00 (1779778800) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:13-07:00 (1790968813) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/v4-bootstrap.yml diff --git a/.github/workflows/welcome.yml b/.github/workflows/welcome.yml index e45d095..0452511 100644 --- a/.github/workflows/welcome.yml +++ b/.github/workflows/welcome.yml @@ -1,10 +1,14 @@ # -# @Project: @cldmv/git-embedded -# @Filename: /.github/workflows/welcome.yml -# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) -# @Author: Nate Corcoran -# @Email: -# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# @Project: @cldmv/git-embedded +# @Filename: /.github/workflows/welcome.yml +# @Date: 2026-05-20T00:00:00-07:00 (1779260400) +# @Author: Nate Corcoran +# @Email: +# ----- +# @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) +# @Last modified time: 2026-10-02T12:20:13-07:00 (1790968813) +# ----- +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # # Individual repo: .github/workflows/welcome.yml diff --git a/bin/git-embedded.mjs b/bin/git-embedded.mjs index 00fd2b2..38d0c0a 100755 --- a/bin/git-embedded.mjs +++ b/bin/git-embedded.mjs @@ -1,4 +1,18 @@ #!/usr/bin/env node +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /bin/git-embedded.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:13-07:00 (1790968813) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ import slothlet from "@cldmv/slothlet"; import fs from "node:fs"; diff --git a/package-lock.json b/package-lock.json index e779116..fb297f5 100644 --- a/package-lock.json +++ b/package-lock.json @@ -20,7 +20,9 @@ "git-embedded": "bin/git-embedded.mjs" }, "devDependencies": { + "@cldmv/configs": "^1.2.0", "@cldmv/eslint-plugin-jsonv": "^1.0.3", + "@cldmv/fix-headers": "^2.1.1", "@cldmv/jsonv": "^1.0.2", "@cldmv/prettier-plugin-jsonv": "^1.0.1", "@cldmv/vitest-runner": "^1.2.0", @@ -126,6 +128,17 @@ "keyv": "^5.6.0" } }, + "node_modules/@cldmv/configs": { + "version": "1.2.0", + "resolved": "https://registry.npmjs.org/@cldmv/configs/-/configs-1.2.0.tgz", + "integrity": "sha512-FDmlxOx6ceKuD5zTamUy9XOfAC4opeOaLxWqZz9okKxj8TsTZP6dN7W0VccRYRdw4606NvXjhdZqOPibcNpXmQ==", + "dev": true, + "license": "Apache-2.0", + "funding": { + "type": "github", + "url": "https://github.com/sponsors/shinrai" + } + }, "node_modules/@cldmv/eslint-plugin-jsonv": { "version": "1.0.3", "resolved": "https://registry.npmjs.org/@cldmv/eslint-plugin-jsonv/-/eslint-plugin-jsonv-1.0.3.tgz", @@ -143,6 +156,36 @@ "@cldmv/jsonv": "^1.0.2" } }, + "node_modules/@cldmv/fix-headers": { + "version": "2.1.1", + "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.1.1.tgz", + "integrity": "sha512-08xW44RvtrKUCTOjUFKHyrDvx6rT70zGqgRR+tdW0R9ElZrHwSg25xCRrZD+U7Dmj5fK9KmtuOWPjZtJYSfzYA==", + "dev": true, + "license": "Apache-2.0", + "dependencies": { + "ignore": "^7.0.5" + }, + "bin": { + "fix-headers": "bin/fix-headers.mjs" + }, + "engines": { + "node": ">=22.12.0" + }, + "funding": { + "type": "github", + "url": "https://github.com/sponsors/shinrai" + } + }, + "node_modules/@cldmv/fix-headers/node_modules/ignore": { + "version": "7.0.12", + "resolved": "https://registry.npmjs.org/ignore/-/ignore-7.0.12.tgz", + "integrity": "sha512-/8UvqAPU9DGTI9k4mxtf49U37Isfwr8Uts96+SBHIkFxPJnHS0Ew4f00sM4Scd8V8EjM0jUNtVDdv1kPdt35lg==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">= 4" + } + }, "node_modules/@cldmv/jsonv": { "version": "1.0.7", "resolved": "https://registry.npmjs.org/@cldmv/jsonv/-/jsonv-1.0.7.tgz", diff --git a/package.json b/package.json index dd97f98..de0578d 100644 --- a/package.json +++ b/package.json @@ -76,7 +76,8 @@ "lint:fix": "eslint --config .configs/eslint.config.mjs . --fix", "format": "prettier --config .configs/.prettierrc --write .", "format:check": "prettier --config .configs/.prettierrc --check .", - "build": "echo 'no build step - stopgap for CI coverage-badge; see tracking issue'" + "build": "echo 'no build step - stopgap for CI coverage-badge; see tracking issue'", + "fix:headers": "fix-headers --config .configs/fix-headers.json" }, "dependencies": { "@cldmv/slothlet": "^3.7.0", @@ -87,7 +88,9 @@ "marked-terminal": "^7.3.0" }, "devDependencies": { + "@cldmv/configs": "^1.2.0", "@cldmv/eslint-plugin-jsonv": "^1.0.3", + "@cldmv/fix-headers": "^2.1.1", "@cldmv/jsonv": "^1.0.2", "@cldmv/prettier-plugin-jsonv": "^1.0.1", "@cldmv/vitest-runner": "^1.2.0", diff --git a/src/api/cli/doctor.mjs b/src/api/cli/doctor.mjs index ae793e7..7cd63c9 100644 --- a/src/api/cli/doctor.mjs +++ b/src/api/cli/doctor.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/doctor.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:13-07:00 (1790968813) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/export.mjs b/src/api/cli/export.mjs index ad29f4e..df82b4f 100644 --- a/src/api/cli/export.mjs +++ b/src/api/cli/export.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/export.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:13-07:00 (1790968813) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/init.mjs b/src/api/cli/init.mjs index c6cf1ed..22f2eec 100644 --- a/src/api/cli/init.mjs +++ b/src/api/cli/init.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/init.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:14-07:00 (1790968814) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/install-hooks.mjs b/src/api/cli/install-hooks.mjs index a87d574..0ce62ee 100644 --- a/src/api/cli/install-hooks.mjs +++ b/src/api/cli/install-hooks.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/install-hooks.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:14-07:00 (1790968814) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; import { CancelledByUser } from "../link/batch.mjs"; diff --git a/src/api/cli/install-template.mjs b/src/api/cli/install-template.mjs index c50981e..9330bc6 100644 --- a/src/api/cli/install-template.mjs +++ b/src/api/cli/install-template.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/install-template.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:14-07:00 (1790968814) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/link.mjs b/src/api/cli/link.mjs index 8b01f14..92ece7e 100644 --- a/src/api/cli/link.mjs +++ b/src/api/cli/link.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/link.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:14-07:00 (1790968814) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/print-hook-script.mjs b/src/api/cli/print-hook-script.mjs index 45d95fa..330eb7b 100644 --- a/src/api/cli/print-hook-script.mjs +++ b/src/api/cli/print-hook-script.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/print-hook-script.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:15-07:00 (1790968815) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; const NAME_TO_SOURCE = { diff --git a/src/api/cli/record.mjs b/src/api/cli/record.mjs index d1eab92..38d418c 100644 --- a/src/api/cli/record.mjs +++ b/src/api/cli/record.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/record.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:15-07:00 (1790968815) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/restore.mjs b/src/api/cli/restore.mjs index 174b61c..b17382f 100644 --- a/src/api/cli/restore.mjs +++ b/src/api/cli/restore.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/restore.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:15-07:00 (1790968815) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/sync.mjs b/src/api/cli/sync.mjs index 7de2a29..cdca301 100644 --- a/src/api/cli/sync.mjs +++ b/src/api/cli/sync.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/sync.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:15-07:00 (1790968815) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/uninstall-hooks.mjs b/src/api/cli/uninstall-hooks.mjs index 559a355..dfc838b 100644 --- a/src/api/cli/uninstall-hooks.mjs +++ b/src/api/cli/uninstall-hooks.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/uninstall-hooks.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:15-07:00 (1790968815) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/cli/version.mjs b/src/api/cli/version.mjs index a246a6e..3c655ff 100644 --- a/src/api/cli/version.mjs +++ b/src/api/cli/version.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/cli/version.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:16-07:00 (1790968816) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; export const spec = { diff --git a/src/api/commander/custom-help.mjs b/src/api/commander/custom-help.mjs index f4b6e36..7d9a25e 100644 --- a/src/api/commander/custom-help.mjs +++ b/src/api/commander/custom-help.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/commander/custom-help.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:16-07:00 (1790968816) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + /** * Build a `Help` subclass that renders colorized, multi-line help with the * look the rest of the CLDMV CLIs use. The bin entry passes commander's diff --git a/src/api/detect/dispatcher.mjs b/src/api/detect/dispatcher.mjs index 147c41a..14d488a 100644 --- a/src/api/detect/dispatcher.mjs +++ b/src/api/detect/dispatcher.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/detect/dispatcher.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:16-07:00 (1790968816) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; export const REQUIRED_HOOKS = ["post-checkout", "post-merge", "post-rewrite", "reference-transaction"]; diff --git a/src/api/detect/husky.mjs b/src/api/detect/husky.mjs index c39fc64..57e5c86 100644 --- a/src/api/detect/husky.mjs +++ b/src/api/detect/husky.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/detect/husky.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:16-07:00 (1790968816) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/detect/lefthook.mjs b/src/api/detect/lefthook.mjs index 0944038..b297d23 100644 --- a/src/api/detect/lefthook.mjs +++ b/src/api/detect/lefthook.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/detect/lefthook.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:16-07:00 (1790968816) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; const CONFIG_NAMES = ["lefthook.yml", "lefthook.yaml", ".lefthook.yml", ".lefthook.yaml"]; diff --git a/src/api/detect/pre-commit.mjs b/src/api/detect/pre-commit.mjs index 577efd4..e488fe3 100644 --- a/src/api/detect/pre-commit.mjs +++ b/src/api/detect/pre-commit.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/detect/pre-commit.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:17-07:00 (1790968817) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; function readHead(p, n = 4) { diff --git a/src/api/detect/run.mjs b/src/api/detect/run.mjs index 98a88d5..427bc7c 100644 --- a/src/api/detect/run.mjs +++ b/src/api/detect/run.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/detect/run.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:17-07:00 (1790968817) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/detect/simple-git-hooks.mjs b/src/api/detect/simple-git-hooks.mjs index 48ca3bc..483cff6 100644 --- a/src/api/detect/simple-git-hooks.mjs +++ b/src/api/detect/simple-git-hooks.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/detect/simple-git-hooks.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:17-07:00 (1790968817) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/embedded/branch.mjs b/src/api/embedded/branch.mjs index 8e829c9..3114537 100644 --- a/src/api/embedded/branch.mjs +++ b/src/api/embedded/branch.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/branch.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:18-07:00 (1790968818) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; function git(args, opts = {}) { diff --git a/src/api/embedded/gitlinks.mjs b/src/api/embedded/gitlinks.mjs index 409ef49..ce42cf6 100644 --- a/src/api/embedded/gitlinks.mjs +++ b/src/api/embedded/gitlinks.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/gitlinks.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:18-07:00 (1790968818) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; function git(args, opts = {}) { diff --git a/src/api/embedded/manifest.mjs b/src/api/embedded/manifest.mjs index 711f567..9ed3cfe 100644 --- a/src/api/embedded/manifest.mjs +++ b/src/api/embedded/manifest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/manifest.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:18-07:00 (1790968818) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/embedded/record.mjs b/src/api/embedded/record.mjs index 3e57727..a80d458 100644 --- a/src/api/embedded/record.mjs +++ b/src/api/embedded/record.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/record.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:18-07:00 (1790968818) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/embedded/registry.mjs b/src/api/embedded/registry.mjs index c28cba9..84889c9 100644 --- a/src/api/embedded/registry.mjs +++ b/src/api/embedded/registry.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/registry.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:19-07:00 (1790968819) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; function git(args, opts = {}) { diff --git a/src/api/embedded/resolve.mjs b/src/api/embedded/resolve.mjs index 3c5e96a..0c5518a 100644 --- a/src/api/embedded/resolve.mjs +++ b/src/api/embedded/resolve.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/resolve.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:19-07:00 (1790968819) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/embedded/restore.mjs b/src/api/embedded/restore.mjs index bdb8545..500a498 100644 --- a/src/api/embedded/restore.mjs +++ b/src/api/embedded/restore.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/restore.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:20-07:00 (1790968820) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; function git(args, opts = {}) { diff --git a/src/api/embedded/sync.mjs b/src/api/embedded/sync.mjs index 2132718..d87739c 100644 --- a/src/api/embedded/sync.mjs +++ b/src/api/embedded/sync.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/embedded/sync.mjs + * @Date: 2026-07-18T23:04:02-07:00 (1784441042) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:20-07:00 (1790968820) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; function git(args, opts = {}) { diff --git a/src/api/git.mjs b/src/api/git.mjs index 9bcef4d..b67b40a 100644 --- a/src/api/git.mjs +++ b/src/api/git.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/git.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:20-07:00 (1790968820) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; function run(args, opts = {}) { diff --git a/src/api/install/dispatcher.mjs b/src/api/install/dispatcher.mjs index 78a3b08..70b538a 100644 --- a/src/api/install/dispatcher.mjs +++ b/src/api/install/dispatcher.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/install/dispatcher.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:21-07:00 (1790968821) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; import { STANDARD_HOOK_NAMES } from "../detect/dispatcher.mjs"; diff --git a/src/api/install/hooks.mjs b/src/api/install/hooks.mjs index b3c08c8..2a6b9f6 100644 --- a/src/api/install/hooks.mjs +++ b/src/api/install/hooks.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/install/hooks.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:21-07:00 (1790968821) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; export const PACKAGE_HOOK_MAP = { diff --git a/src/api/install/template.mjs b/src/api/install/template.mjs index 61d9771..b9a94d8 100644 --- a/src/api/install/template.mjs +++ b/src/api/install/template.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/install/template.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:21-07:00 (1790968821) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/link/batch.mjs b/src/api/link/batch.mjs index d5d340f..aa69846 100644 --- a/src/api/link/batch.mjs +++ b/src/api/link/batch.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/link/batch.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:21-07:00 (1790968821) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; const WIN_PRIV_NOT_HELD = "EPERM"; diff --git a/src/api/link/copy-executable.mjs b/src/api/link/copy-executable.mjs index e5e0d6a..1a2f045 100644 --- a/src/api/link/copy-executable.mjs +++ b/src/api/link/copy-executable.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/link/copy-executable.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:22-07:00 (1790968822) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/link/elevate-windows.mjs b/src/api/link/elevate-windows.mjs index 18150a9..5e4be83 100644 --- a/src/api/link/elevate-windows.mjs +++ b/src/api/link/elevate-windows.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/link/elevate-windows.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:23-07:00 (1790968823) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; const ERROR_CANCELLED = 1223; diff --git a/src/api/log.mjs b/src/api/log.mjs index f8d0e17..aa2936e 100644 --- a/src/api/log.mjs +++ b/src/api/log.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/log.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:23-07:00 (1790968823) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/messages/load.mjs b/src/api/messages/load.mjs index 9cf3ef7..817ae29 100644 --- a/src/api/messages/load.mjs +++ b/src/api/messages/load.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/messages/load.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:23-07:00 (1790968823) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; const KIND_TO_FILE = { diff --git a/src/api/paths.mjs b/src/api/paths.mjs index becc71d..7c32270 100644 --- a/src/api/paths.mjs +++ b/src/api/paths.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/paths.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:24-07:00 (1790968824) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/prompt.mjs b/src/api/prompt.mjs index a1846a9..156ecaa 100644 --- a/src/api/prompt.mjs +++ b/src/api/prompt.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/prompt.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:24-07:00 (1790968824) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { context } from "@cldmv/slothlet/runtime"; /** diff --git a/src/api/report.mjs b/src/api/report.mjs index e8169ef..ee6b886 100644 --- a/src/api/report.mjs +++ b/src/api/report.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/api/report.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:24-07:00 (1790968824) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { self, context } from "@cldmv/slothlet/runtime"; const KIND_LABELS = { diff --git a/src/lib/elevate-windows-child.mjs b/src/lib/elevate-windows-child.mjs index 704d404..d072730 100755 --- a/src/lib/elevate-windows-child.mjs +++ b/src/lib/elevate-windows-child.mjs @@ -1,4 +1,19 @@ #!/usr/bin/env node +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /src/lib/elevate-windows-child.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:24-07:00 (1790968824) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + // // Elevated child process: reads a JSON file with an array of // { source, target } entries and creates symbolic links for each. diff --git a/tests/_setup.mjs b/tests/_setup.mjs index 6cb3b63..c1cf015 100644 --- a/tests/_setup.mjs +++ b/tests/_setup.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/_setup.mjs + * @Date: 2026-05-24T21:13:00-07:00 (1779682380) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:24-07:00 (1790968824) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import slothlet from "@cldmv/slothlet"; import fs from "node:fs"; import path from "node:path"; diff --git a/tests/cli-coverage.test.vitest.mjs b/tests/cli-coverage.test.vitest.mjs index e2a4d3f..1a30cdc 100644 --- a/tests/cli-coverage.test.vitest.mjs +++ b/tests/cli-coverage.test.vitest.mjs @@ -1,28 +1,16 @@ /** + * * @Project: @cldmv/git-embedded * @Filename: /tests/cli-coverage.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:25-07:00 (1790968825) + * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. * - * Gap-closing behavior tests for the CLI wrapper commands (src/api/cli/*.mjs), - * driven through the composed slothlet api against REAL temp git repos in the - * same house style as cli-hooks.test.vitest.mjs / cli-provisioning.test.vitest.mjs. Each test - * targets an uncovered path the existing suites do not exercise: - * - * - link: full command coverage (blocksClone refusals, clone/add - * failures, outside-worktree guards, the non-repo add path). - * - install-hooks: the switch default, the no-gitDir + all-skipped install - * paths, heal/bootstrap copy-fallback, the git-config - * failure, the CancelledByUser + re-throw catch arms, and - * the "no git repo" post-bootstrap branch. - * - init: the git-config failure warn arm. - * - export: the missing-exclude catch, the no-trailing-newline prefix, - * and the non-repo root fallback. - * - install-template: the nothing-installed (all-skipped) branch. - * - record/restore/sync: the no-branch / no-note LABEL arms and the - * unknown-outcome LABEL fallbacks. - * - * Temp git repos live under the repo's own tmp/ (never the system /tmp), and a - * GIT_CEILING so a non-repo temp dir there is genuinely seen as a non-repo. */ import { afterEach, beforeAll, beforeEach, describe, expect, it, vi } from "vitest"; diff --git a/tests/cli-hooks.test.vitest.mjs b/tests/cli-hooks.test.vitest.mjs index 5583c59..1494c67 100644 --- a/tests/cli-hooks.test.vitest.mjs +++ b/tests/cli-hooks.test.vitest.mjs @@ -1,21 +1,16 @@ /** + * * @Project: @cldmv/git-embedded * @Filename: /tests/cli-hooks.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:25-07:00 (1790968825) + * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. * - * Behavior tests for the CLI wrapper commands that manage git hooks and print - * misc info, driven through the composed slothlet api against REAL temp git - * repos (per the house style). Covers: - * - * - install-hooks: the detection-driven switch (refuse / suggest-dispatcher / - * heal-then-install / install), the per-repo install (owned-copy + foreign - * skip), the dispatcher bootstrap (+ global core.hooksPath), and the heal. - * - uninstall-hooks: removes only git-embedded-owned hooks, keeps foreign ones, - * reports "none found", and refuses outside a repo. - * - install-template: templateDir resolution, confirm gate, --force overwrite. - * - print-hook-script: known-name passthrough to stdout + unknown-name refusal. - * - version / doctor / init: the small wrappers around package.json, detection, - * and the install-hooks + advice-silencing composition. */ import { afterEach, beforeAll, beforeEach, describe, expect, it, vi } from "vitest"; diff --git a/tests/cli-provisioning.test.vitest.mjs b/tests/cli-provisioning.test.vitest.mjs index 3da2161..3d411a0 100644 --- a/tests/cli-provisioning.test.vitest.mjs +++ b/tests/cli-provisioning.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/cli-provisioning.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:25-07:00 (1790968825) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeAll, beforeEach, describe, expect, it, vi } from "vitest"; import fs from "node:fs"; import os from "node:os"; diff --git a/tests/commander-help.test.vitest.mjs b/tests/commander-help.test.vitest.mjs index 5769c97..44579e4 100644 --- a/tests/commander-help.test.vitest.mjs +++ b/tests/commander-help.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/commander-help.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:25-07:00 (1790968825) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeEach, describe, expect, it } from "vitest"; import chalk from "chalk"; import { Command, Help } from "commander"; diff --git a/tests/detect-coverage.test.vitest.mjs b/tests/detect-coverage.test.vitest.mjs index c600d54..537e002 100644 --- a/tests/detect-coverage.test.vitest.mjs +++ b/tests/detect-coverage.test.vitest.mjs @@ -1,37 +1,16 @@ /** + * * @Project: @cldmv/git-embedded * @Filename: /tests/detect-coverage.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:26-07:00 (1790968826) + * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. * - * Targeted coverage-closing tests for src/api/detect/*. tests/detect-hooks.test.vitest.mjs, - * tests/detect-foreign.test.vitest.mjs, and tests/dispatcher-classify.test.vitest.mjs cover the - * baseline detection patterns; this file adds only the edge cases those don't - * reach, closing dispatcher.mjs, husky.mjs, pre-commit.mjs, lefthook.mjs, and - * run.mjs to 100% lines/statements/functions/branches: - * - * - src/api/detect/dispatcher.mjs โ€” falsy `dir`, an unreadable dir, a - * directory-shaped `_dispatch` (readFileSync EISDIR), relative symlink - * targets, the copy-cluster hashing loop's skip/unreadable/losing-bucket - * branches, the all-different-content (no cluster) case, a dotted - * non-hook-only dir, a symlink pointing at an unrelated decoy file, and the - * TOCTOU-style fs-race branches (lstatSync/readlinkSync/statSync/ - * realpathSync throwing after an earlier check already confirmed the path) - * simulated via targeted fs spies since a real filesystem race can't be - * fabricated deterministically. - * - src/api/detect/husky.mjs โ€” falsy repoRoot, a malformed package.json - * (wispSync throws), and the dependencies-only husky fallback. - * - src/api/detect/pre-commit.mjs โ€” falsy gitDir, a gitDir with no hooks - * subdir, and the readHead catch (a subdirectory entry in hooks/). - * - src/api/detect/lefthook.mjs โ€” the readHead catch (a subdirectory entry - * in hooks/). - * - src/api/detect/run.mjs โ€” the `effectiveHooksPath || systemPath` - * fallback, triggered by a cwd that doesn't exist on disk (so - * getEffectiveHooksPath's git spawn fails) while the system hooksPath - * scope is still readable (getAllHooksPathScopes ignores its cwd - * argument and reads from the real process cwd). - * - * Scratch fixtures live under this repo's tmp/ (never the system /tmp), are - * tracked per-test, and are removed in afterEach/afterAll. */ import { afterAll, afterEach, beforeAll, beforeEach, describe, expect, it, vi } from "vitest"; diff --git a/tests/detect-foreign.test.vitest.mjs b/tests/detect-foreign.test.vitest.mjs index 38943df..1d6727b 100644 --- a/tests/detect-foreign.test.vitest.mjs +++ b/tests/detect-foreign.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/detect-foreign.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:26-07:00 (1790968826) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeAll, describe, expect, it } from "vitest"; import fs from "node:fs"; import os from "node:os"; diff --git a/tests/detect-hooks.test.vitest.mjs b/tests/detect-hooks.test.vitest.mjs index cd8768c..772002f 100644 --- a/tests/detect-hooks.test.vitest.mjs +++ b/tests/detect-hooks.test.vitest.mjs @@ -1,26 +1,16 @@ /** + * * @Project: @cldmv/git-embedded * @Filename: /tests/detect-hooks.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:26-07:00 (1790968826) + * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. * - * Coverage tests for the hook-manager detectors and the detect orchestrator: - * - * - src/api/detect/lefthook.mjs โ€” config-name variants, the gitDir - * hooks-header scan (headerIn), and the null/no-match branches. - * - src/api/detect/pre-commit.mjs โ€” the gitDir hooks-header scan and the - * null/no-match branches. - * - src/api/detect/simple-git-hooks.mjs โ€” the package.json key path (with its - * parsed config), the standalone `.simple-git-hooks.json` path, and the - * wispSync-throws โ†’ pkg=null branch. - * - src/api/detect/run.mjs โ€” the whole classifier: foreign-manager - * precedence (husky > lefthook > simple-git-hooks > pre-commit), effective - * core.hooksPath sub-classification (canonical / missing / non-conforming / - * bare / empty), system-scope hooksPath, init.templateDir fallback, and none. - * - * The detectors are pure-fs and are driven directly with fabricated - * repoRoot/gitDir args (matching tests/detect-foreign.test.vitest.mjs). run() shells - * out to real git, so it is driven against real temp repos with a hermetic git - * environment (matching tests/embedded-provisioning.test.vitest.mjs). */ import { afterEach, beforeAll, beforeEach, describe, expect, it } from "vitest"; diff --git a/tests/dispatcher-classify.test.vitest.mjs b/tests/dispatcher-classify.test.vitest.mjs index d6cc60e..d7fc217 100644 --- a/tests/dispatcher-classify.test.vitest.mjs +++ b/tests/dispatcher-classify.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/dispatcher-classify.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:27-07:00 (1790968827) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeAll, describe, expect, it } from "vitest"; import fs from "node:fs"; import os from "node:os"; diff --git a/tests/embedded-coverage.test.vitest.mjs b/tests/embedded-coverage.test.vitest.mjs index 964c4b8..7c16b8e 100644 --- a/tests/embedded-coverage.test.vitest.mjs +++ b/tests/embedded-coverage.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/embedded-coverage.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:27-07:00 (1790968827) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + /** * Coverage closure for the embedded engine. These target the error/edge/defensive * branches that embedded-provisioning.test.vitest.mjs and embedded-topup.test.vitest.mjs leave diff --git a/tests/embedded-provisioning.test.vitest.mjs b/tests/embedded-provisioning.test.vitest.mjs index 8c0f253..adbc9c5 100644 --- a/tests/embedded-provisioning.test.vitest.mjs +++ b/tests/embedded-provisioning.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/embedded-provisioning.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:27-07:00 (1790968827) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeAll, beforeEach, describe, expect, it, vi } from "vitest"; import fs from "node:fs"; import os from "node:os"; diff --git a/tests/embedded-topup.test.vitest.mjs b/tests/embedded-topup.test.vitest.mjs index f333f7f..1dc640c 100644 --- a/tests/embedded-topup.test.vitest.mjs +++ b/tests/embedded-topup.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/embedded-topup.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:27-07:00 (1790968827) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + /** * Branch top-up coverage for the embedded engine's smaller modules. These * exercise the error paths, ambiguous/edge inputs, and layer-precedence diff --git a/tests/helpers.test.vitest.mjs b/tests/helpers.test.vitest.mjs index ddf6d44..a9457a7 100644 --- a/tests/helpers.test.vitest.mjs +++ b/tests/helpers.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/helpers.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:28-07:00 (1790968828) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeAll, beforeEach, describe, expect, it, vi } from "vitest"; import fs from "node:fs"; import os from "node:os"; diff --git a/tests/hook-guards.test.vitest.mjs b/tests/hook-guards.test.vitest.mjs index c4bdaaa..d8bc86f 100644 --- a/tests/hook-guards.test.vitest.mjs +++ b/tests/hook-guards.test.vitest.mjs @@ -1,23 +1,16 @@ /** + * * @Project: @cldmv/git-embedded * @Filename: /tests/hook-guards.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:28-07:00 (1790968828) + * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. * - * Behavior tests for the two guard hooks, driven through REAL git operations - * with the hooks installed into the parent's .git/hooks: - * - * - reference-transaction (embedded.guard = precise | strict | off): which - * HEAD moves are allowed/blocked given each child's dirty state and the - * pins in the NEW commit. Covers the plumbing fact that a plain commit - * emits a HEAD transaction line, the precise rule (dirty + would-re-pin), - * strict's all-clean + pins-current-on-append policy, and the drifted-child - * hole a naive pin-delta rule would miss. - * - * - pre-push (embedded.pushRecurse = check | on-demand | off): parent pushes - * are rejected while a newly-pinned child commit is unreachable from the - * child's origin, allowed once the child is pushed (on-demand publishes the - * child's branch to do that automatically), and unrelated (pin-less) pushes - * from a children-less clone stay allowed. */ import { afterEach, beforeEach, describe, expect, it } from "vitest"; diff --git a/tests/install-hooks.test.vitest.mjs b/tests/install-hooks.test.vitest.mjs index 2b3e558..2debba8 100644 --- a/tests/install-hooks.test.vitest.mjs +++ b/tests/install-hooks.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/install-hooks.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:28-07:00 (1790968828) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeAll, beforeEach, describe, expect, it } from "vitest"; import fs from "node:fs"; import os from "node:os"; diff --git a/tests/install-link.test.vitest.mjs b/tests/install-link.test.vitest.mjs index aba9be3..13c1048 100644 --- a/tests/install-link.test.vitest.mjs +++ b/tests/install-link.test.vitest.mjs @@ -1,25 +1,16 @@ /** + * * @Project: @cldmv/git-embedded * @Filename: /tests/install-link.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:29-07:00 (1790968829) + * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. * - * Behavior tests for the install-dispatch + link-batch layer, driven through - * the composed slothlet api against REAL files in temp dirs: - * - * - api.install.dispatcher (bootstrap|heal): writes hooks/_dispatch from the - * packaged template and fans out links to the standard hook names; heal only - * adds the missing ones without rewriting the dispatcher; unknown op throws. - * - api.install.template: seeds a `git init` templateDir/hooks with the package - * hooks, honoring the foreign-hook skip and the --force override. - * - api.link.batch: symlink (default) / hardlink (noSymlinks) mechanisms, the - * overwrite pre-removal, the copy fallback when a symlink can't be made, and - * the throw paths when no mechanism succeeds. - * - api.link.copyExecutable: copy + +x bit, the overwrite pre-removal branch, - * and the overwrite:false branch. - * - * The Windows deferred-symlink โ†’ UAC-elevation path in link/batch.mjs is - * guarded by `process.platform === "win32"` and is not reachable on POSIX CI; - * it is not exercised here (see notes). */ import { afterEach, beforeAll, beforeEach, describe, expect, it } from "vitest"; diff --git a/tests/link-coverage.test.vitest.mjs b/tests/link-coverage.test.vitest.mjs index d6a8261..7d8a07b 100644 --- a/tests/link-coverage.test.vitest.mjs +++ b/tests/link-coverage.test.vitest.mjs @@ -1,27 +1,16 @@ /** + * * @Project: @cldmv/git-embedded * @Filename: /tests/link-coverage.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:30-07:00 (1790968830) + * ----- * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. * - * Coverage-completing behavior tests for the link + install-hooks layer, - * complementing tests/install-link.test.vitest.mjs and tests/install-hooks.test.vitest.mjs. - * Everything here is driven through the composed slothlet api against REAL - * files in temp dirs; the branches that only fire on Windows (privilege-denied - * symlink โ†’ UAC batch) or on a copy/chmod failure are exercised by: - * - * - Pinning `process.platform` to "win32" for the duration of a single - * synchronous `api.link.batch` call, then restoring it. - * - Injecting controlled failures into the fs primitives the leaf calls - * (`symlinkSync`, `linkSync`, `chmodSync`) โ€” the leaf reads them off the - * shared node:fs object at call time, so a temporary property swap makes the - * documented fallback/branch fire without needing a real cross-volume mount - * or a real UAC prompt. - * - Overriding `api.link.elevateWindows` (the Windows-only helper is excluded - * from coverage and cannot run on POSIX) with a stub that returns each of the - * result shapes the batch caller must handle: cancelled, failed, succeeded. - * - * All stubs are restored in a finally before any assertion runs, so a failed - * expectation can never leave process.platform or fs mutated for later tests. */ import { afterEach, beforeAll, beforeEach, describe, expect, it } from "vitest"; diff --git a/tests/root-coverage.test.vitest.mjs b/tests/root-coverage.test.vitest.mjs index 599c714..38950f4 100644 --- a/tests/root-coverage.test.vitest.mjs +++ b/tests/root-coverage.test.vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/root-coverage.test.vitest.mjs + * @Date: 2026-08-02T23:38:12-07:00 (1785739092) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:30-07:00 (1790968830) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + import { afterEach, beforeAll, beforeEach, describe, expect, it, vi } from "vitest"; import fs from "node:fs"; import os from "node:os"; diff --git a/tests/run-vitest.mjs b/tests/run-vitest.mjs index 92a9c27..af6027a 100644 --- a/tests/run-vitest.mjs +++ b/tests/run-vitest.mjs @@ -1,3 +1,18 @@ +/** + * + * @Project: @cldmv/git-embedded + * @Filename: /tests/run-vitest.mjs + * @Date: 2026-07-20T04:26:48+00:00 (1784521608) + * @Author: Nate Corcoran + * @Email: + * ----- + * @Last modified by: Nate Corcoran (Shinrai@users.noreply.github.com) + * @Last modified time: 2026-10-02T12:20:31-07:00 (1790968831) + * ----- + * @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. + * + */ + /** * @fileoverview OOM-safe Vitest runner for git-embedded โ€” delegates to * @cldmv/vitest-runner, which spawns each test file in its own child process and From 7966b2059ce445077623864e100df227d470f169 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Fri, 2 Oct 2026 13:56:27 -0700 Subject: [PATCH 13/14] ci: stop the skipped PR-run mirror from satisfying Required PR Check MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit On an in-repo feature PR, the `pull_request` run skips the `required-check` job because the push run owns the status. A skipped job still posts a check run under its name, and GitHub treats a skipped required check as satisfied. The push run's mirror is only created once `ci` finishes, so for the whole test window the only `โœ… Required PR Check` on the head SHA was the skipped one, and the PR could merge while tests were still running. Give the job a conditional name so the skipped path posts under a different name and the required check stays pending until the push run reports. Synced from CLDMV/.github#346. --- .github/workflows/ci.yml | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1ebf523..49b6c91 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -304,7 +304,21 @@ jobs: # automatically โ€” no `pull_request` round-trip needed for non-fork # non-release PRs. required-check: - name: โœ… Required PR Check + # The name is conditional on purpose. On an in-repo feature PR the + # `pull_request` run skips this job (the push run owns the status), and + # a skipped job still posts a check run under its name. GitHub treats a + # SKIPPED required check as satisfied โ€” so if the skipped job were named + # `โœ… Required PR Check`, it would green-light the ruleset (and enable + # auto-merge) while the push run's real mirror hadn't been created yet + # (it only appears once `ci` finishes), letting a PR merge mid-test or + # even override a red result. An expression name keeps the skipped job + # off the required name: GitHub does not evaluate the name of a skipped + # job, so it shows up as the raw expression text (still not the + # required name), while every path that runs evaluates to + # `โœ… Required PR Check`. The condition is written out anyway so the + # name stays correct if GitHub ever starts evaluating it, and must stay + # identical to the `if:` below. + name: ${{ (github.event_name != 'pull_request' || github.event.pull_request.head.repo.fork == true || github.event.pull_request.head.ref == 'next' || github.event.pull_request.head.ref == 'hotfixes') && 'โœ… Required PR Check' || 'โญ๏ธ Required PR Check (reported by the push run)' }} needs: ci # Mirror the `ci` job's gating exactly. The four cases that run: # 1. push events (job needs CI run) @@ -312,8 +326,8 @@ jobs: # 3. release PRs from `next` โ†’ master/main (push covers SHA but commit-gate skips chore-bump) # 4. release PRs from `hotfixes` โ†’ master/main (same reason) # In-repo feature PRs targeting `next` / `hotfixes` skip on - # pull_request โ€” push on the head branch already posted the status - # on the SHA, and mirroring here would overwrite it. + # pull_request โ€” the push run on the head branch reports the status + # on the SHA. See the `name:` above for why the skipped job is renamed. if: | always() && ( github.event_name != 'pull_request' || From b1fcf1f54ccfe0b0e41ed2a3ee5c4cfa9b2551ea Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 21:43:28 +0000 Subject: [PATCH 14/14] deps: bump the patch group with 2 updates Bumps the patch group with 2 updates: [@cldmv/eslint-plugin-jsonv](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv) and [@cldmv/jsonv](https://github.com/CLDMV/jsonv). Updates `@cldmv/eslint-plugin-jsonv` from 1.0.10 to 1.0.13 - [Release notes](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/releases) - [Commits](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/compare/v1.0.10...v1.0.13) Updates `@cldmv/jsonv` from 1.0.9 to 1.1.1 - [Release notes](https://github.com/CLDMV/jsonv/releases) - [Changelog](https://github.com/CLDMV/jsonv/blob/master/CHANGELOG.md) - [Commits](https://github.com/CLDMV/jsonv/compare/v1.0.9...v1.1.1) --- updated-dependencies: - dependency-name: "@cldmv/eslint-plugin-jsonv" dependency-version: 1.0.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch - dependency-name: "@cldmv/jsonv" dependency-version: 1.1.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: patch ... Signed-off-by: dependabot[bot] --- package-lock.json | 21 +++++++++++++-------- 1 file changed, 13 insertions(+), 8 deletions(-) diff --git a/package-lock.json b/package-lock.json index 6544151..ea25427 100644 --- a/package-lock.json +++ b/package-lock.json @@ -140,20 +140,25 @@ } }, "node_modules/@cldmv/eslint-plugin-jsonv": { - "version": "1.0.10", - "resolved": "https://registry.npmjs.org/@cldmv/eslint-plugin-jsonv/-/eslint-plugin-jsonv-1.0.10.tgz", - "integrity": "sha512-BtkGK0Jo6nir7GL3JpY6eEAqX/8XzibMgPbT3S+vkhWulVd+47xx+oUwxvaEvj24XyVaIKqloHzAWYtnqXIGDQ==", + "version": "1.0.13", + "resolved": "https://registry.npmjs.org/@cldmv/eslint-plugin-jsonv/-/eslint-plugin-jsonv-1.0.13.tgz", + "integrity": "sha512-mz8YQCmwZn5/VGFCSWvR38FzNaNP6HCe/PYGxvq/RZGty/aGEH5xiolpD6iCuHlRXcrd/NWqpPJSTyU9mwZKxA==", "dev": true, "license": "Apache-2.0", + "dependencies": { + "@eslint/core": "^1.2.1", + "@eslint/plugin-kit": "^0.7.3" + }, "engines": { - "node": ">=18.0.0" + "node": "^20.19.0 || ^22.13.0 || >=24" }, "funding": { "type": "github", "url": "https://github.com/sponsors/shinrai" }, "peerDependencies": { - "@cldmv/jsonv": "^1.0.2" + "@cldmv/jsonv": "^1.1.0", + "eslint": "^9.13.0 || ^10.0.0" } }, "node_modules/@cldmv/fix-headers": { @@ -187,9 +192,9 @@ } }, "node_modules/@cldmv/jsonv": { - "version": "1.0.9", - "resolved": "https://registry.npmjs.org/@cldmv/jsonv/-/jsonv-1.0.9.tgz", - "integrity": "sha512-L84D+ocPzCg/Q88HvrVjxt7UMQ6PxHe7kbAj6Uor/eFE0/HkB8xuPoyB+ssa2vRwleFVZ+q3RXLxt8BT1ZM0Ow==", + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/@cldmv/jsonv/-/jsonv-1.1.1.tgz", + "integrity": "sha512-2eGO5hc08x3++HSxgzNGJibNzulVIaqn6yoGUUelvKrnL6dMNAlaL/sjIpCdPBToNlD6SwRqtgTDoxqivn5yzw==", "dev": true, "license": "Apache-2.0", "engines": {