Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
fcb5761
chore(deps)(deps): bump similar from 3.1.1 to 3.1.2 (#201)
dependabot[bot] Aug 9, 2026
c917411
chore(deps)(deps): bump clap from 4.6.4 to 4.6.5 (#202)
dependabot[bot] Aug 9, 2026
0453e1a
chore(deps)(deps): bump pyo3 from 0.29.0 to 0.29.2 (#204)
dependabot[bot] Aug 9, 2026
6d2568e
chore(deps)(deps): bump aho-corasick from 1.1.4 to 1.1.5 (#203)
dependabot[bot] Aug 10, 2026
5386057
chore(deps)(deps): bump the all-dependencies group with 2 updates (#205)
dependabot[bot] Aug 10, 2026
cee06d3
chore(deps): update pre-commit hook astral-sh/ruff-pre-commit to v0.1…
Aug 10, 2026
14c27d4
chore(deps): update pre-commit hook asottile/pyupgrade to v3.21.2 (#8)
Aug 10, 2026
62fd306
chore(deps): update codecov/codecov-action digest to 0fb7174 (#5)
Aug 10, 2026
cca93fd
chore(deps): update softprops/action-gh-release digest to 3bb1273 (#7)
Aug 10, 2026
9011ae1
chore(deps): update dtolnay/rust-toolchain digest to 4360b52
nikolay-e Aug 10, 2026
358ab8a
fix: QA sweep — exclusion-only disclosure, scala panic, harness parity
nikolay-e Aug 10, 2026
d104d21
refactor: extract helpers flagged by Sonar cognitive-complexity
nikolay-e Aug 10, 2026
98f5867
QA.md: unbind version-file count, add surface-flip note, cut stale FP
nikolay-e Aug 13, 2026
9febaeb
docs: dedupe CLAUDE.md against CONTRIBUTING, fix stale paths
nikolay-e Aug 13, 2026
08b7a19
chore(deps)(deps): bump thiserror from 2.0.19 to 2.0.20 (#220)
dependabot[bot] Aug 16, 2026
1b74211
chore(deps)(deps): bump tree-sitter-scala from 0.26.0 to 0.26.2 (#221)
dependabot[bot] Aug 16, 2026
5165e20
chore(deps)(deps): bump clap from 4.6.5 to 4.6.6 (#222)
dependabot[bot] Aug 16, 2026
b7d03a5
chore(deps)(deps): bump the all-dependencies group with 2 updates (#223)
dependabot[bot] Aug 16, 2026
b204267
chore(deps): ignore mcp 2.x majors, bump huggingface-hub floor
nikolay-e Aug 16, 2026
1b3a8d2
fix: per-run deadlines, secret-path disclosure, dead-wiring cleanup
nikolay-e Aug 16, 2026
c58afb5
QA.md: unbind pytest count, pin mid-compile-edit trap for corpus runs
nikolay-e Aug 16, 2026
78a0d3c
chore(deps): block mcp>=2 by version range, not just semver class
nikolay-e Aug 16, 2026
c948435
Release version 1.14.0
github-actions[bot] Aug 16, 2026
0663cef
chore: packaging manifests for 1.14.0
github-actions[bot] Aug 16, 2026
d08eb8c
docs: cut CHANGELOG 1.14.0 section
nikolay-e Aug 16, 2026
14612a8
fix: edge-cap dedup, script type=, scala imports, pub-use order, sig …
nikolay-e Aug 16, 2026
b56e85b
docs+perf: file-star measured net-negative (#208), gate reps alloc, t…
nikolay-e Aug 16, 2026
f0fe9fb
fix: substituted signature stub carries changed role on both surfaces…
nikolay-e Aug 16, 2026
7da93d3
docs: cut CHANGELOG 1.15.0 section
nikolay-e Aug 18, 2026
f3cc415
docs: cut CHANGELOG 1.15.0 section
nikolay-e Aug 18, 2026
6acaccc
chore: QA.md #123 drift fix, renovate python<3.14 CI-matrix gate
nikolay-e Aug 18, 2026
6224b94
chore: QA.md #123 drift fix, renovate python<3.14 CI-matrix gate
nikolay-e Aug 18, 2026
f2e738c
Revert "chore(deps): update dependency python (#13)"
nikolay-e Aug 18, 2026
e47b13d
refactor: MCP legacy tools to legacy.py; engine ALPHA default; QA notes
nikolay-e Aug 18, 2026
889ed24
refactor: unify harness selection path, split change-set resolve (#225)
nikolay-e Aug 18, 2026
496aca5
test: temp_project fixture returns instead of yield (S9100)
nikolay-e Aug 18, 2026
d45631c
QA.md: self-eat breadth post-#211 gates (0.4x, was 4-5x)
nikolay-e Aug 18, 2026
5a48084
Release version 1.15.0
github-actions[bot] Aug 19, 2026
9626343
ci: idempotent npm publish, smoke retry guard with hard fail
nikolay-e Aug 18, 2026
e9995ad
chore: packaging manifests for 1.15.0
github-actions[bot] Aug 19, 2026
32a38b0
ci: idempotent npm publish, smoke retry guard with hard fail
nikolay-e Aug 18, 2026
fc99033
chore(deps): update docker/dockerfile docker tag to v1.26 (#14)
Aug 19, 2026
92bed54
chore(deps): update dependency python (#13)
Aug 19, 2026
3908721
chore(deps): update pre-commit hook rhysd/actionlint to v1.7.12 (#12)
Aug 19, 2026
972a214
chore(deps): update pre-commit hook pycqa/pylint to v4.0.7 (#11)
Aug 19, 2026
7a78c3a
chore(deps): update pre-commit hook gitleaks/gitleaks to v8.29.1 (#10)
Aug 19, 2026
cc47e51
chore: packaging manifests for 1.15.0
github-actions[bot] Aug 19, 2026
d09e33a
merge: reconcile mirror after 1.15.0 finalize and renovate automerges
nikolay-e Aug 19, 2026
993c0fb
fix+refactor: admission gates (#211), --alpha wire, leverage sweep
nikolay-e Aug 18, 2026
ae1386c
refactor: pub(crate) sweep unlocks dead-code lint; kill drifted copies
nikolay-e Aug 20, 2026
48955bb
ci: pin Rust toolchain in the four jobs that compile the extension
nikolay-e Aug 20, 2026
ee229ef
ci: unpin rustfmt/clippy components so building needs only cargo
nikolay-e Aug 20, 2026
684538a
refactor: dedup edges/parsers/config against helpers that already exi…
nikolay-e Aug 20, 2026
6cc4c21
refactor: one discovery routine for the 16 builders that shared its s…
nikolay-e Aug 20, 2026
870ce14
refactor: one path-display and one deleted/renamed source in pipeline
nikolay-e Aug 20, 2026
ca8e7a6
refactor: one token-count formula for pipeline and in-memory harness
nikolay-e Aug 20, 2026
09cad03
refactor: delete three exact duplicates, one of them a lying name
nikolay-e Aug 21, 2026
a24c07a
refactor: constructors for the two repeated struct literals
nikolay-e Aug 21, 2026
1ff4d2d
ci: uv sync --locked everywhere; uv.lock back under a drift gate
nikolay-e Aug 25, 2026
4792fb3
fix(deps): pip increase-if-necessary ends the weekly numpy/scipy crash
nikolay-e Aug 25, 2026
2a29366
chore(deps)(deps): bump tree-sitter-graphql from 0.1.0 to 0.2.0 (#236)
dependabot[bot] Aug 25, 2026
dc3ea63
QA.md: the cargo --lib count here was 171, the real one is 250
nikolay-e Aug 25, 2026
0ce4db0
chore(deps): update pre-commit hook astral-sh/ruff-pre-commit to v0.1…
Aug 26, 2026
c3b2132
chore(deps): update pre-commit hook adrienverge/yamllint to v1.38.0 (…
Aug 26, 2026
9cad189
chore(deps): update pre-commit hook abravalheri/validate-pyproject to…
Aug 26, 2026
51f3bc9
chore(deps): update docker/setup-buildx-action action to v4.3.0 (#16)
Aug 26, 2026
622b86e
chore(deps): update dependency python (#15)
Aug 26, 2026
3d067ab
ci: uv sync --no-build so no dependency setup script runs (S8541)
nikolay-e Aug 25, 2026
6735d25
docs(site): stumble fixes — budget/tau flags, stage click, hero counters
nikolay-e Aug 25, 2026
95fe64d
chore(deps)(deps): bump similar from 3.1.2 to 3.2.0 (#235)
dependabot[bot] Aug 26, 2026
0285023
chore(deps)(deps): bump tree-sitter-graphql from 0.1.0 to 0.2.0 (#236)
dependabot[bot] Aug 26, 2026
5bd7933
Merge remote-tracking branch 'github/main'
nikolay-e Aug 25, 2026
7bb8421
meta: link the author's site from the PyPI sidebar
nikolay-e Aug 26, 2026
cccd80c
docs: unpin the rotted corpus count; gate commit-subject length
nikolay-e Aug 26, 2026
82d54ad
chore(deps)(deps-dev): update maturin requirement
dependabot[bot] Aug 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "diffctx",
"displayName": "diffctx",
"version": "1.13.0",
"version": "1.15.0",
"description": "Smart git diff context for LLMs and AI agents: budgeted fragment selection, deterministic, MCP server included",
"author": {
"name": "Nikolay Eremeev",
Expand Down
45 changes: 45 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,42 @@
version: 2
updates:
# uv.lock only. `versioning-strategy: lockfile-only` keeps this entry off
# pyproject.toml's ranges, which the pip entry below owns — without the split
# both ecosystems see the same pyproject and open the same PR twice.
- package-ecosystem: "uv"
directory: "/"
versioning-strategy: "lockfile-only"
schedule:
interval: "weekly"
day: "saturday"
time: "10:00"
timezone: "Europe/Berlin"
cooldown:
default-days: 3
labels:
- "dependencies"
assignees:
- "nikolay-e"
commit-message:
prefix: "chore(deps)"
include: "scope"
groups:
all-dependencies:
patterns:
- "*"

- package-ecosystem: "pip"
directory: "/"
# Raise a floor only when the declared range genuinely cannot admit the new
# version. The default (`increase`) rewrites the floor to the newest
# resolvable version on every run, and when that version already IS the
# floor the rewrite is a no-op that dependabot-core raises
# `Expected content to change!` on — numpy and scipy in
# requirements-eval.txt hit exactly that (their newest release supporting
# this project's `requires-python = ">=3.10"` floor is the version already
# written there), failing every weekly pip run since 2026-08-15. Security
# updates still get through: a fix that the range excludes IS necessary.
versioning-strategy: "increase-if-necessary"
schedule:
interval: "weekly"
day: "saturday"
Expand All @@ -16,6 +51,16 @@ updates:
commit-message:
prefix: "chore(deps)"
include: "scope"
ignore:
# mcp 2.x is a breaking SDK rewrite; the <2.0 pin in pyproject.toml is a
# deliberate compatibility decision (see the comment there). PR #219
# widened the bound mechanically and every test matrix failed at import.
# `versions` in addition to `update-types`: a "update requirement" range
# widening is not classified as semver-major (PR #224 got through), the
# explicit range is what actually blocks it.
- dependency-name: "mcp"
update-types: ["version-update:semver-major"]
versions: [">=2.0.0"]
groups:
all-dependencies:
patterns:
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/cd.yml
Original file line number Diff line number Diff line change
Expand Up @@ -359,7 +359,7 @@ jobs:
git checkout "$TAG_NAME"

- name: Set up Rust
uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: '1.92.0'

Expand Down Expand Up @@ -712,12 +712,12 @@ jobs:
# binaries in particular have no package index vouching for them the way
# the wheels have PyPI's attestations (#147).
- name: Attest build provenance for release assets
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: ./release-assets/*

- name: Create GitHub Release with wheel and sdist assets
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v2
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
with:
tag_name: ${{ needs.prepare-version.outputs.tag_name }}
name: Release ${{ needs.prepare-version.outputs.version }}
Expand Down Expand Up @@ -825,7 +825,7 @@ jobs:
ref: ${{ needs.prepare-version.outputs.tag_name }}

- name: Set up Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0

- name: Login to ghcr
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
Expand Down Expand Up @@ -875,7 +875,7 @@ jobs:
merge-multiple: true

- name: Set up Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0

- name: Login to ghcr
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
Expand Down
102 changes: 65 additions & 37 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,10 +24,22 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- name: Set up uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.12'
enable-cache: true

# This job runs the cargo fmt and clippy hooks, so it is the one place
# that needs those components; rust-toolchain.toml deliberately does not
# pin them (see the comment there). It also compiles the extension, so
# cargo has to be on PATH at the pinned version rather than whatever the
# runner image happens to ship.
- name: Install Rust
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"
components: rustfmt, clippy

- name: Cache pre-commit
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
Expand All @@ -37,9 +49,8 @@ jobs:

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install pre-commit
pip install -e ".[dev]"
uv sync --locked --no-build --extra dev
echo "$PWD/.venv/bin" >> "$GITHUB_PATH"

- name: Run pre-commit
run: pre-commit run --all-files
Expand All @@ -58,7 +69,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install Rust
uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"

Expand All @@ -83,7 +94,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install Rust
uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"

Expand Down Expand Up @@ -160,17 +171,23 @@ jobs:
- name: Checkout Code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python 3.10
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- name: Set up uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.10'
cache: 'pip'
cache-dependency-path: 'pyproject.toml'
enable-cache: true

# Same reason as the pre-commit job: installing this package compiles the
# native extension, so cargo has to be on PATH at the pinned version.
- name: Install Rust
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"

- name: Install Linters and Type Checker
run: |
python -m pip install --upgrade pip
pip install .[dev]
uv sync --locked --no-build --extra dev
echo "$PWD/.venv/bin" >> "$GITHUB_PATH"

- name: Run Linters and Formatters Check
run: |
Expand All @@ -193,7 +210,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install Rust
uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"
components: rustfmt, clippy
Expand Down Expand Up @@ -252,15 +269,14 @@ jobs:
- name: Checkout Code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- name: Set up uv with Python ${{ matrix.python-version }}
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: ${{ matrix.python-version }}
cache: 'pip'
cache-dependency-path: 'pyproject.toml'
enable-cache: true

- name: Install Rust
uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"
components: rustfmt, clippy
Expand All @@ -275,20 +291,16 @@ jobs:
key: cargo-${{ runner.os }}-py${{ matrix.python-version }}-${{ hashFiles('Cargo.lock') }}
restore-keys: cargo-${{ runner.os }}-py${{ matrix.python-version }}-

- name: Install build backend
run: |
python -m pip install --upgrade pip
pip install "maturin>=1.10,<1.11"

- name: Build and install diffctx (with Rust _diffctx) and dev deps
shell: bash
env:
PYO3_USE_ABI3_FORWARD_COMPATIBILITY: "1"
run: |
# PEP 660 editable install — maturin builds the Rust extension and
# pip installs everything (diffctx + [dev,full,mcp] extras). Skip build
# isolation since we just installed maturin in this env.
pip install -e ".[dev,full,mcp]" --no-build-isolation
# Editable install of the project plus every extra the suite needs.
# uv provisions maturin in its own build environment, so the build
# backend is not a separate step and cannot drift from pyproject.
uv sync --locked --no-build --extra dev --extra full --extra mcp
echo "$PWD/.venv/bin" >> "$GITHUB_PATH"

- name: Run Tests with Coverage
shell: bash
Expand All @@ -302,7 +314,7 @@ jobs:

- name: Upload coverage reports to Codecov
if: runner.os == 'Linux' && matrix.python-version == '3.12'
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v5
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: ./coverage.xml
Expand Down Expand Up @@ -332,15 +344,23 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- name: Set up uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.12'
enable-cache: true

# Installing this package compiles the native extension, so cargo must
# be on PATH at the pinned version.
- name: Install Rust
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
uv sync --locked --no-build --extra dev
echo "$PWD/.venv/bin" >> "$GITHUB_PATH"

- name: Check cyclomatic complexity
run: |
Expand Down Expand Up @@ -369,15 +389,23 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- name: Set up uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.12'
enable-cache: true

# Installing this package compiles the native extension, so cargo must
# be on PATH at the pinned version.
- name: Install Rust
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
uv sync --locked --no-build --extra dev
echo "$PWD/.venv/bin" >> "$GITHUB_PATH"

- name: Check import contracts
run: lint-imports
2 changes: 1 addition & 1 deletion .github/workflows/eval-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
- uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0

- name: Login to ghcr
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/nightly-full-eval.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install Rust
uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: "1.92.0"

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/publish-crate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ jobs:
echo "Publishing diffctx $VERSION"

- name: Set up Rust
uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: '1.92.0'

Expand Down
27 changes: 22 additions & 5 deletions .github/workflows/publish-extras.yml
Original file line number Diff line number Diff line change
Expand Up @@ -116,9 +116,19 @@ jobs:
console.log('checksums.json: ' + n + ' assets, all version-tagged');
"

# Idempotent like the PyPI step's skip-existing: a rerun after a
# smoke-only failure must not die on "cannot publish over previously
# published versions" (observed on 1.15.0).
- name: Publish
working-directory: ./packaging/npm
run: npm publish --access public --provenance
env:
VERSION: ${{ github.event.inputs.version }}
run: |
if npm view "diffctx@$VERSION" version >/dev/null 2>&1; then
echo "diffctx@$VERSION already on the registry; skipping publish"
else
npm publish --access public --provenance
fi

# install.js is the script every `npx diffctx` runs, and nothing executed
# it before this step existed. --ignore-scripts keeps npm from running
Expand All @@ -131,14 +141,21 @@ jobs:
WORK=$(mktemp -d)
cd "$WORK"
npm init -y >/dev/null
for attempt in 1 2 3 4 5; do
installed=0
# Registry propagation took >100s on 1.15.0; without the installed
# guard the loop used to fall through to a MODULE_NOT_FOUND that
# hid the real failure.
for attempt in 1 2 3 4 5 6 7 8 9 10; do
# Sonar S8543 (unlocked dependency versions) is marked false
# positive in SonarCloud: VERSION is the exact just-published
# version and the package has zero dependencies.
if npm install --ignore-scripts "diffctx@$VERSION"; then break; fi
if npm install --ignore-scripts "diffctx@$VERSION"; then installed=1; break; fi
echo "npm registry not settled yet (attempt $attempt); retrying"
sleep 20
sleep 30
done
if [ "$installed" != 1 ]; then
echo "diffctx@$VERSION never became installable"; exit 1
fi
node node_modules/diffctx/install.js
./node_modules/.bin/diffctx --version

Expand All @@ -158,7 +175,7 @@ jobs:
fi

- name: Set up Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0

- name: Login to Docker Hub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
Expand Down
Loading
Loading