Repository navigation
🚀 release: harden engine and restore package build channels - #12
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The optimizations preserve existing contracts, and the new failure behavior has focused regression and runtime coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Optimizes asset and Markdown processing while adding atomic diagnostics for excessive nesting.
Changes:
- Caches validated assets per compilation and removes unnecessary AST cloning.
- Converts parsing/rendering stack overflows into
CONTENT_TOO_DEEPdiagnostics. - Adds regression and supported-Node smoke coverage.
| File | Description |
|---|---|
src/index.ts |
Handles excessive nesting atomically. |
src/links.ts |
Reuses validated asset metadata. |
src/markdown.ts |
Removes raw HTML during parsing and avoids cloning. |
src/project.ts |
Removes unused project fields. |
tests/compile.test.ts |
Covers asset reuse and validation. |
tests/markdown.test.ts |
Verifies raw HTML removal and tree stability. |
scripts/smoke.mjs |
Tests nesting diagnostics under Node. |
README.md |
Documents the new diagnostic. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
warengonzaga
left a comment
There was a problem hiding this comment.
Clean Workflow completed for dev@a53efd7552a351183f1fbdeb1fae364d04d32719 against main@6be146f09a0a4898d8e05f1b96d9c6995a938e1d. No actionable findings or merge blockers remain.
The eight-file promotion exactly matches the reviewed implementation. GitHub test merge 6da980a preserves main’s existing changelog; workflow permissions, publication policy, package version, and lockfile are unchanged. Asset/path safeguards, sanitizer behavior, deterministic output, and diagnostics-only failure semantics remain intact.
Validation: 92 tests / 300 assertions, lint, typecheck, build, dependency audit, exact-output benchmark comparisons, and packed consumers on Node 22.0.0, 22.16.0, 24.21.0, and 26.10.0. Both the dev-push and promotion Build Flow runs passed, as did code quality. Copilot completed on this head with no findings. All review/comment/thread collections were fetched; no unresolved threads or reviewer requests remain. GitHub reports CLEAN and MERGEABLE.
CodeQL limitation: the check retains a nonblocking comparison warning for the retired build.yml category from before the workflow rename. The current build-flow.yml scan exists on main and the PR merge; PR analysis 1900064494 completed 87 rules with zero findings and no error/warning. Existing upstream action deprecation notices are unrelated to this source change.
Ready for a regular dev-to-main merge commit. Left open for the maintainer’s merge decision; package/release jobs are intentionally skipped on dev and PR events.
* ⚙️ setup: restore default development package builds * ⚙️ setup: inherit default package publishing channels
🚀 Development BuildDevelopment version ready for integration testing 📦 Package Information
📥 Installation InstructionsNPM Registrynpm install @wgtechlabs/mdd-engine@0.1.0-dev.8a1ef77
npm install @wgtechlabs/mdd-engine@dev # Use dist-tagGitHub Packagesnpm install @wgtechlabs/mdd-engine@0.1.0-dev.8a1ef77
npm install @wgtechlabs/mdd-engine@dev # Use dist-tag🔒 Security Audit✅ No vulnerabilities found This package was built automatically by the Package Build Flow action. |
warengonzaga
left a comment
There was a problem hiding this comment.
Clean Workflow completed at 4650301809a69815f04910bccfb492d43c6682d0 against main 6be146f09a0a4898d8e05f1b96d9c6995a938e1d. No actionable findings or merge blockers remain in the combined twelve-file promotion.
The engine source, tests, smoke checks, dependencies, and runtime settings match the previously reviewed engine revision. The added workflow/documentation changes restore the pinned publication defaults without weakening strict Bun validation, supported Node checks, npm OIDC, or the requirement that both registries succeed before GitHub Release. Independent integration review found no issues. GitHub's test merge 8a1ef77ef3dda34ca7d27eaf000dd101b29e3a03 preserves main's existing changelog; its other root entries match dev. No source fixes or thread resolutions were needed.
Current validation:
- Promotion Build Flow and dev Build Flow both passed: Node 22/24/26 validation, lint, typecheck, 92 tests / 300 assertions, build, packed consumer smoke checks, dependency audit, Gitleaks, and CodeQL.
- Code Quality passed. Current PR CodeQL analysis
1900528279ran 87 rules with zero findings and no scan errors or warnings. - Dev published
0.1.0-dev.4650301; the promotion test merge published0.1.0-dev.8a1ef77. Both versions were verified in npm and GitHub Packages. Both tarballs have verified SHA-512 integrity, the expected 15 files, MIT metadata/license, and 12 compiled files matching the validated build. npm'sdevtag is0.1.0-dev.8a1ef77;latestremains0.1.0. The automatic PR installation comment matches the promotion build. - Current head/base and all feedback collections were refreshed. No unresolved review threads or pending reviewer requests; GitHub reports CLEAN and MERGEABLE.
Coverage notes: Copilot's earlier review covers the unchanged engine revision; it did not automatically rerun for the added workflow/docs changes, which were reviewed directly and independently. The neutral CodeQL comparison check still references retired build.yml; the current build-flow.yml scan is successful. Manual/patch channels have policy/version coverage but no live publication in this review. A stable main publication is not claimed here.
Ready for a regular dev-to-main merge commit. This is a review comment, not self-approval. PR #12 remains open for the maintainer's merge decision.
Promote the engine optimization, Markdown nesting hardening, and restored default package build channels to main.
Repeated content assets are validated once per compilation, and rendering no longer deep-copies the Markdown tree. Routes, sanitization, diagnostics, and successful output remain unchanged. Excessive nesting produces a source-attributed
CONTENT_TOO_DEEPdiagnostic with no partial site; unrelated errors still propagate.Build Flow now inherits development, PR, and manual publication defaults for both npm and GitHub Packages. It retains npm OIDC, strict Bun checks, Node 22/24/26 validation, and the requirement that both registries succeed before a GitHub Release. The documentation explains the
dev,pr,patch,wip, andlatestchannels and why the orchestrated main path does not use standalonestagingbuilds.Validation:
0.1.0-pr.cab0713to both registries; npm provenance and tarball integrity were verified, and GitHub Packages visibility was confirmed public.Use a regular merge commit for the dev-to-main promotion. An eligible main push validates and finalizes the release source/version, publishes packages to both registries, and creates the GitHub Release only after both uploads and the package job succeed.