diff --git a/.github/workflows/bundle-size.yml b/.github/workflows/bundle-size.yml new file mode 100644 index 0000000..3e93b2c --- /dev/null +++ b/.github/workflows/bundle-size.yml @@ -0,0 +1,49 @@ +# +# @Project: gitmulti +# @Filename: /.github/workflows/bundle-size.yml +# @Date: 2026-05-20 00:00:00 -07:00 (1779606000) +# @Author: Nate Corcoran +# @Email: +# @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. +# + +# Individual repo: .github/workflows/bundle-size.yml +# +# Only relevant for runtime libraries where bundle size matters (e.g. +# @cldmv/slothlet). Skip this template for tool repos / meta repos. +# +# Fork-PR caveat: builds PR-supplied code, so we use `pull_request` +# (NOT pull_request_target). Fork builds run safely without secrets; +# comment posting fails for fork PRs because the token is read-only. +# Maintainer can run via workflow_dispatch after reviewing the code. +# +# Batch 5.4 from tmp/plan-future-workflows.md. +name: ๐Ÿ“Š Bundle Size + +on: + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + branches: [master, main] + workflow_dispatch: + +permissions: + contents: read + pull-requests: write + +jobs: + diff: + uses: CLDMV/.github/.github/workflows/reusable-bundle-size.yml@v4 + with: + build_command: "npm run build:ci" + # Leading `*` is required: the measure step only walks directories, so a bare top-level filename matches nothing. + dist_paths: "*gitmulti.js" + # warning_pct: 5 + # warning_bytes: 500 + # comment_mode: "update" + # Optional. Without these, the size-diff comment is posted by + # github-actions[bot]. With these, it's posted by your CLDMV bot App. + # Note: fork PRs can't access org secrets, so the bot attribution only + # applies to same-repo PRs; fork PRs fall back to GITHUB_TOKEN. + secrets: + BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} + BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2c4850c..a832932 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -267,7 +267,7 @@ jobs: # โ”€โ”€ Type check (runs inside the coverage-badge job) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ # Skipped deliberately: plain JavaScript package with no TypeScript sources # or shipped type declarations, so there is no meaningful JS type-check to - # run. ESLint is the static-analysis net. + # run. There is no type check or lint check in this repo yet. type_check_command: ${{ github.event.inputs.type_check_command || 'npm run test:types' }} skip_type_check: true diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index cb24ae3..2f801b0 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -51,7 +51,7 @@ jobs: bump_types: "patch,minor" # merge_method defaults to "merge" โ€” Dependabot PRs target next / hotfixes, # whose rulesets are merge-only. Override only if your branches differ. - merge_method: "squash" + # merge_method: "merge" # also_for_actors: "renovate[bot]" # extend if you adopt Renovate secrets: BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} diff --git a/.github/workflows/release-merge.yml b/.github/workflows/release-merge.yml index 086a454..fed525d 100644 --- a/.github/workflows/release-merge.yml +++ b/.github/workflows/release-merge.yml @@ -1,6 +1,8 @@ # # @Project: gitmulti # @Filename: /.github/workflows/release-merge.yml +# @Author: Nate Corcoran +# @Email: # @Copyright: Copyright (c) 2013-2026 Catalyzed Motivation Inc. All rights reserved. # @@ -55,6 +57,7 @@ on: - "๐Ÿงช CI Tests & Build" - "๐Ÿ” CodeQL" - "๐Ÿ”’ Dependency Review" + - "๐Ÿ“Š Bundle Size" - "๐Ÿš€ Next Release (v4)" - "๐Ÿš‘ Hotfixes Release (v4)" - "๐ŸŒฟ Branch Retention"