Skip to content

🚀 release: harden engine and restore package build channels - #12

Merged
warengonzaga merged 2 commits into
mainfrom
dev
Oct 6, 2026
Merged

warengonzaga merged 2 commits into
mainfrom
dev

Conversation

@warengonzaga

@warengonzaga warengonzaga commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Promote the engine optimization, Markdown nesting hardening, and restored default package build channels to main.

Repeated content assets are validated once per compilation, and rendering no longer deep-copies the Markdown tree. Routes, sanitization, diagnostics, and successful output remain unchanged. Excessive nesting produces a source-attributed CONTENT_TOO_DEEP diagnostic with no partial site; unrelated errors still propagate.

Build Flow now inherits development, PR, and manual publication defaults for both npm and GitHub Packages. It retains npm OIDC, strict Bun checks, Node 22/24/26 validation, and the requirement that both registries succeed before a GitHub Release. The documentation explains the dev, pr, patch, wip, and latest channels and why the orchestrated main path does not use standalone staging builds.

Validation:

  • Lint, TypeScript, build, dependency audit, and 92 tests / 300 assertions passed for the reviewed source.
  • The same packed build passed Node 22.0.0, 22.16.0, 24.21.0, and 26.10.0, including parsing and rendering overflow regressions.
  • Seven event/policy/version scenarios and the pinned CI profile resolver passed. PR ⚙️ setup: restore default package build channels #13 published 0.1.0-pr.cab0713 to both registries; npm provenance and tarball integrity were verified, and GitHub Packages visibility was confirmed public.
  • Synthetic 120-page Node 24 comparisons preserved exact output, with local medians improving from 708.4 to 608.2 ms for articles and 1042.6 to 747.1 ms for repeated images. Asset realpath/stat calls fell from 2,400 each to one each. Timings vary by workload and environment.
  • Fresh promotion checks and the final Clean Workflow review are recorded on this PR.

Use a regular merge commit for the dev-to-main promotion. An eligible main push validates and finalizes the release source/version, publishes packages to both registries, and creates the GitHub Release only after both uploads and the package job succeed.

@warengonzaga warengonzaga added the performance [Type] Optimization, speed, or resource usage improvements [issues, PRs] label Oct 6, 2026
Copilot AI balanced review requested due to automatic review settings October 6, 2026 11:02
@warengonzaga warengonzaga added security [Type] Security vulnerability or hardening [issues, PRs] core [Area] Core logic, business rules, and primary functionality [issues, PRs] labels Oct 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The optimizations preserve existing contracts, and the new failure behavior has focused regression and runtime coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Optimizes asset and Markdown processing while adding atomic diagnostics for excessive nesting.

Changes:

  • Caches validated assets per compilation and removes unnecessary AST cloning.
  • Converts parsing/rendering stack overflows into CONTENT_TOO_DEEP diagnostics.
  • Adds regression and supported-Node smoke coverage.
File Description
src/​index.ts Handles excessive nesting atomically.
src/​links.ts Reuses validated asset metadata.
src/​markdown.ts Removes raw HTML during parsing and avoids cloning.
src/​project.ts Removes unused project fields.
tests/​compile.test.ts Covers asset reuse and validation.
tests/​markdown.test.ts Verifies raw HTML removal and tree stability.
scripts/​smoke.mjs Tests nesting diagnostics under Node.
README.md Documents the new diagnostic.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@warengonzaga warengonzaga left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean Workflow completed for dev@a53efd7552a351183f1fbdeb1fae364d04d32719 against main@6be146f09a0a4898d8e05f1b96d9c6995a938e1d. No actionable findings or merge blockers remain.

The eight-file promotion exactly matches the reviewed implementation. GitHub test merge 6da980a preserves main’s existing changelog; workflow permissions, publication policy, package version, and lockfile are unchanged. Asset/path safeguards, sanitizer behavior, deterministic output, and diagnostics-only failure semantics remain intact.

Validation: 92 tests / 300 assertions, lint, typecheck, build, dependency audit, exact-output benchmark comparisons, and packed consumers on Node 22.0.0, 22.16.0, 24.21.0, and 26.10.0. Both the dev-push and promotion Build Flow runs passed, as did code quality. Copilot completed on this head with no findings. All review/comment/thread collections were fetched; no unresolved threads or reviewer requests remain. GitHub reports CLEAN and MERGEABLE.

CodeQL limitation: the check retains a nonblocking comparison warning for the retired build.yml category from before the workflow rename. The current build-flow.yml scan exists on main and the PR merge; PR analysis 1900064494 completed 87 rules with zero findings and no error/warning. Existing upstream action deprecation notices are unrelated to this source change.

Ready for a regular dev-to-main merge commit. Left open for the maintainer’s merge decision; package/release jobs are intentionally skipped on dev and PR events.

@warengonzaga warengonzaga added the ready [Status] Triaged and ready to be picked up [issues] label Oct 6, 2026
@warengonzaga warengonzaga self-assigned this Oct 6, 2026
* ⚙️ setup: restore default development package builds

* ⚙️ setup: inherit default package publishing channels
@warengonzaga warengonzaga added the infra [Area] Build system, CI/CD, deployment, config, and DevOps [issues, PRs] label Oct 6, 2026
@warengonzaga warengonzaga changed the title 🚀 release: streamline engine and harden markdown diagnostics 🚀 release: harden engine and restore package build channels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🚀 Development Build

Development version ready for integration testing

📦 Package Information

  • Package: @wgtechlabs/mdd-engine
  • Version: 0.1.0-dev.8a1ef77
  • Dist-tag: dev

📥 Installation Instructions

NPM Registry

npm install @wgtechlabs/mdd-engine@0.1.0-dev.8a1ef77
npm install @wgtechlabs/mdd-engine@dev  # Use dist-tag

View on NPM Registry

GitHub Packages

npm install @wgtechlabs/mdd-engine@0.1.0-dev.8a1ef77
npm install @wgtechlabs/mdd-engine@dev  # Use dist-tag

View on GitHub Packages

🔒 Security Audit

✅ No vulnerabilities found


This package was built automatically by the Package Build Flow action.

@warengonzaga warengonzaga left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean Workflow completed at 4650301809a69815f04910bccfb492d43c6682d0 against main 6be146f09a0a4898d8e05f1b96d9c6995a938e1d. No actionable findings or merge blockers remain in the combined twelve-file promotion.

The engine source, tests, smoke checks, dependencies, and runtime settings match the previously reviewed engine revision. The added workflow/documentation changes restore the pinned publication defaults without weakening strict Bun validation, supported Node checks, npm OIDC, or the requirement that both registries succeed before GitHub Release. Independent integration review found no issues. GitHub's test merge 8a1ef77ef3dda34ca7d27eaf000dd101b29e3a03 preserves main's existing changelog; its other root entries match dev. No source fixes or thread resolutions were needed.

Current validation:

  • Promotion Build Flow and dev Build Flow both passed: Node 22/24/26 validation, lint, typecheck, 92 tests / 300 assertions, build, packed consumer smoke checks, dependency audit, Gitleaks, and CodeQL.
  • Code Quality passed. Current PR CodeQL analysis 1900528279 ran 87 rules with zero findings and no scan errors or warnings.
  • Dev published 0.1.0-dev.4650301; the promotion test merge published 0.1.0-dev.8a1ef77. Both versions were verified in npm and GitHub Packages. Both tarballs have verified SHA-512 integrity, the expected 15 files, MIT metadata/license, and 12 compiled files matching the validated build. npm's dev tag is 0.1.0-dev.8a1ef77; latest remains 0.1.0. The automatic PR installation comment matches the promotion build.
  • Current head/base and all feedback collections were refreshed. No unresolved review threads or pending reviewer requests; GitHub reports CLEAN and MERGEABLE.

Coverage notes: Copilot's earlier review covers the unchanged engine revision; it did not automatically rerun for the added workflow/docs changes, which were reviewed directly and independently. The neutral CodeQL comparison check still references retired build.yml; the current build-flow.yml scan is successful. Manual/patch channels have policy/version coverage but no live publication in this review. A stable main publication is not claimed here.

Ready for a regular dev-to-main merge commit. This is a review comment, not self-approval. PR #12 remains open for the maintainer's merge decision.

@warengonzaga
warengonzaga merged commit 8b376aa into main Oct 6, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core [Area] Core logic, business rules, and primary functionality [issues, PRs] infra [Area] Build system, CI/CD, deployment, config, and DevOps [issues, PRs] performance [Type] Optimization, speed, or resource usage improvements [issues, PRs] ready [Status] Triaged and ready to be picked up [issues] security [Type] Security vulnerability or hardening [issues, PRs]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants