fix(ci): sync remotion lockfile - #8
Conversation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
WalkthroughUpdates the release bundle job to run longer, switches remotion setup to Node 24 with ChangesRelease workflow and HEVC script fixes
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
🧹 Nitpick comments (1)
.github/workflows/release.yml (1)
22-22: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winSet
persist-credentials: falseon the checkout step.No subsequent step in this workflow needs git authentication — release uploads use an explicit
GH_TOKENsecret. The defaultpersist-credentials: truestores theGITHUB_TOKENin.git/config, unnecessarily widening the credential exposure surface.🔒️ Proposed fix
- uses: actions/checkout@v4 + with: + persist-credentials: false🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml at line 22, The checkout step in the release workflow currently leaves the default git credential persistence enabled, which is unnecessary for this job. Update the actions/checkout setup in the release workflow to set persist-credentials to false so the GITHUB_TOKEN is not written into .git/config, while keeping the rest of the release flow unchanged since upload steps already use GH_TOKEN explicitly.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In @.github/workflows/release.yml:
- Line 22: The checkout step in the release workflow currently leaves the
default git credential persistence enabled, which is unnecessary for this job.
Update the actions/checkout setup in the release workflow to set
persist-credentials to false so the GITHUB_TOKEN is not written into
.git/config, while keeping the rest of the release flow unchanged since upload
steps already use GH_TOKEN explicitly.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 6b44ab2f-95b5-45a2-8904-7a9555120d19
⛔ Files ignored due to path filters (1)
remotion/package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (2)
.github/workflows/release.ymlremotion/to-hevc.sh
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
🧹 Nitpick comments (1)
.github/workflows/release.yml (1)
26-39: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueNode 24 +
npm installswitch looks correct.The lockfile was regenerated with npm 11 (Node 24), so bumping the setup-node action to Node 24 for CI consistency is the right call. The switch from
npm citonpm installis a deliberate, well-documented workaround for npm's bundled-wasm-deps validation failure.One minor trade-off to keep in mind:
npm installcan resolve and write new versions into the lockfile during CI (changes are ephemeral since CI doesn't commit), so builds may be slightly less reproducible than withnpm ci. If the upstream npm issue (Missing@emnapi/corefrom lock file) is resolved in a future npm release, consider reverting tonpm cito restore strict lockfile enforcement.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 26 - 39, The release workflow now uses Node 24 and npm install, which can update package-lock.json during CI and make builds less strictly reproducible. Keep the actions/setup-node@v4 Node 24 setup and the Install remotion deps step as-is for the current npm workaround, but make sure the workflow does not persist lockfile changes and add a clear note to revert back to npm ci once the bundled-wasm npm issue is fixed. Refer to the setup-node and Install remotion deps steps when updating this workflow.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In @.github/workflows/release.yml:
- Around line 26-39: The release workflow now uses Node 24 and npm install,
which can update package-lock.json during CI and make builds less strictly
reproducible. Keep the actions/setup-node@v4 Node 24 setup and the Install
remotion deps step as-is for the current npm workaround, but make sure the
workflow does not persist lockfile changes and add a clear note to revert back
to npm ci once the bundled-wasm npm issue is fixed. Refer to the setup-node and
Install remotion deps steps when updating this workflow.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 17295583-fb83-4814-a5b2-f860a239a20e
📒 Files selected for processing (1)
.github/workflows/release.yml
* fix(ci): sync remotion lockfile — npm ci missed @emnapi bundled deps * fix(ci): node 24 on runner — npm 10 rejects npm-11 lockfile * fix(ci): npm install not npm ci — bundled-wasm lock validation broken * fix(ci): allow_sw for videotoolbox on VM runners, 120min timeout * fix(ci): 180min timeout — software HEVC transcode needs ~155min total ---------
npm cion the macOS runner failed —package-lock.jsonwas missing bundled optional deps (@emnapi/core,@emnapi/runtimeunder@tailwindcss/oxide-wasm32-wasi). Regenerated withnpm install --package-lock-only;npm ci --dry-runpasses.Full release CI test running from this branch: https://github.com/MrDemonWolf/obs-setup/actions/runs/28907868927
🤖 Generated with Claude Code
Summary by CodeRabbit
Bug Fixes
Chores