Repository navigation
Ts bun impl #3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ts bun impl #3
Changes from all commits
d5fd184
e63c77d
29f6a69
273b564
5c65074
78f4a9b
21818ed
c6f7919
47c7e85
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| # position fixtures depend on their exact line endings (\n, \r\n, lone \r); keeps | ||
| # autocrlf on Windows from rewriting them | ||
| src/position/testdata/*.jsonc -text |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,157 +16,73 @@ concurrency: | |
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| # All six release targets must compile. Cross-compilation on ubuntu runners is | ||
| # far cheaper than native arm runners and asserts exactly what we need here: | ||
| # that the code builds everywhere we ship. | ||
| build: | ||
| name: build ${{ matrix.goos }}/${{ matrix.goarch }} | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 10 | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - {goos: linux, goarch: amd64} | ||
| - {goos: linux, goarch: arm64} | ||
| - {goos: darwin, goarch: amd64} | ||
| - {goos: darwin, goarch: arm64} | ||
| - {goos: windows, goarch: amd64} | ||
| - {goos: windows, goarch: arm64} | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - uses: actions/setup-go@v5 | ||
| with: | ||
| go-version-file: go.mod | ||
| cache: true | ||
|
|
||
| - name: Build | ||
| env: | ||
| GOOS: ${{ matrix.goos }} | ||
| GOARCH: ${{ matrix.goarch }} | ||
| run: go build ./... | ||
|
|
||
| # Tests run natively. The race detector is restricted to linux/amd64: it needs | ||
| # cgo and a C toolchain, and running it on every leg buys no extra signal while | ||
| # costing minutes. | ||
| # Coverage is enabled by default via bunfig.toml (text + lcov reporters), so a plain | ||
| # `bun test` already produces both — no extra flag or third-party service needed. | ||
| test: | ||
| name: test ${{ matrix.os }} | ||
| runs-on: ${{ matrix.os }} | ||
| timeout-minutes: 10 | ||
| # Mapped here because the `secrets` context is not available in a | ||
| # step-level `if`, but `env` is. | ||
| env: | ||
| CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | ||
| timeout-minutes: 5 | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - {os: ubuntu-latest, race: true} | ||
| - {os: macos-latest, race: false} | ||
| - {os: windows-latest, race: false} | ||
| os: [ubuntu-latest, macos-latest, windows-latest] | ||
| steps: | ||
| # schemas/ is a symlink into the devcontainer-spec submodule — without this, | ||
| # both tsc's text-import resolution and the schema tests' readdirSync see an | ||
| # empty/missing directory. | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - uses: actions/setup-go@v5 | ||
| with: | ||
| go-version-file: go.mod | ||
| cache: true | ||
| submodules: recursive | ||
|
|
||
| - name: Vet | ||
| run: go vet ./... | ||
|
|
||
| - name: Test | ||
| if: ${{ !matrix.race }} | ||
| run: go test ./... | ||
| - uses: oven-sh/setup-bun@v2 | ||
| with: | ||
| bun-version: "1.4.2" | ||
|
|
||
| - name: Test with race detector and coverage | ||
| if: ${{ matrix.race }} | ||
| run: go test -race -coverprofile=coverage.out -covermode=atomic ./... | ||
| - run: bun install --frozen-lockfile | ||
|
|
||
| # Coverage reporting that needs no secret and no third-party service: | ||
| # the number lands in the job summary, the profile in an artifact. | ||
| - name: Coverage summary | ||
| if: ${{ matrix.race }} | ||
| run: | | ||
| go tool cover -func=coverage.out | tail -1 | ||
| { | ||
| echo '### Coverage' | ||
| echo | ||
| echo '```' | ||
| go tool cover -func=coverage.out | tail -25 | ||
| echo '```' | ||
| } >> "$GITHUB_STEP_SUMMARY" | ||
| - run: bun test | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win Initialize the schema submodule before running tests.
🤖 Prompt for AI Agents |
||
|
|
||
| - name: Upload coverage profile | ||
| if: ${{ matrix.race }} | ||
| # One copy is enough; the lcov content doesn't vary by OS. | ||
| - name: Upload coverage | ||
| if: matrix.os == 'ubuntu-latest' | ||
| uses: actions/upload-artifact@v4 | ||
| with: | ||
| name: coverage-profile | ||
| path: coverage.out | ||
| if-no-files-found: error | ||
| name: coverage | ||
| path: coverage/lcov.info | ||
|
|
||
| # Publishes trend data only when a token is configured. Gated on the | ||
| # secret rather than left to fail invisibly: a tokenless upload is | ||
| # rejected by Codecov while still reporting the step as successful. | ||
| - name: Publish to Codecov | ||
| if: ${{ matrix.race && env.CODECOV_TOKEN != '' }} | ||
| uses: codecov/codecov-action@v5 | ||
| with: | ||
| files: coverage.out | ||
| token: ${{ env.CODECOV_TOKEN }} | ||
| fail_ci_if_error: false | ||
|
|
||
| # Go fuzzes one target per invocation, and its corpus of "interesting" inputs is | ||
| # a machine-local cache by design — not something to commit. The seed corpus | ||
| # (f.Add, plus any crasher checked in) already runs as an ordinary test in the | ||
| # `test` job; this job is the part that explores inputs nobody has seen yet. | ||
| # | ||
| # Time-boxed rather than exhaustive: the point is steady pressure on every PR. | ||
| # On a failure the toolchain writes the reproducer under testdata/fuzz/, so it | ||
| # is uploaded — committing that file turns the crash into a permanent test. | ||
| fuzz: | ||
| name: fuzz | ||
| # tsc is the correctness gate; prettier only checks formatting. Neither needs more | ||
| # than one OS. | ||
| check: | ||
| name: typecheck & format | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 10 | ||
| timeout-minutes: 5 | ||
| steps: | ||
| # Same reason as the test job: tsc resolves schemas/*.schema.json through the | ||
| # devcontainer-spec submodule symlink. | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - uses: actions/setup-go@v5 | ||
| with: | ||
| go-version-file: go.mod | ||
| cache: true | ||
| submodules: recursive | ||
|
|
||
| - name: Fuzz | ||
| run: make fuzz FUZZTIME=60s | ||
|
|
||
| - name: Upload crash reproducers | ||
| if: failure() | ||
| uses: actions/upload-artifact@v4 | ||
| - uses: oven-sh/setup-bun@v2 | ||
| with: | ||
| name: fuzz-crashers | ||
| path: "**/testdata/fuzz/**" | ||
| if-no-files-found: ignore | ||
| bun-version: "1.4.2" | ||
|
|
||
| - run: bun install --frozen-lockfile | ||
| - run: bunx tsc --noEmit | ||
| - run: bun run format:check | ||
|
|
||
| # Lint results are platform-independent, so this runs once rather than three | ||
| # times. It also exercises a Makefile target, which keeps CI and the local | ||
| # `make check` entry point from drifting apart. | ||
| lint: | ||
| name: lint | ||
| # Proves the compile step itself doesn't break on every PR, without paying for the | ||
| # full 8-target release matrix (that's a separate, on-tag job). | ||
| build-smoke: | ||
| name: build smoke | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 10 | ||
| timeout-minutes: 5 | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - uses: actions/setup-go@v5 | ||
| - uses: oven-sh/setup-bun@v2 | ||
| with: | ||
| go-version-file: go.mod | ||
| cache: true | ||
| bun-version: "1.4.2" | ||
|
|
||
| - name: Check formatting | ||
| run: make fmt-check | ||
|
|
||
| - name: golangci-lint | ||
| uses: golangci/golangci-lint-action@v9 | ||
| with: | ||
| version: v2.13.2 | ||
| - run: bun install --frozen-lockfile | ||
| - run: bun run build | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,75 @@ | ||
| name: Schema drift | ||
|
|
||
| # schemas/ is a symlink into the pinned devcontainer-spec submodule, not an | ||
| # independent copy — so there is no local file to diff against upstream. What can | ||
| # actually go stale is the pin itself: this job compares the submodule's checked-out | ||
| # commit against devcontainers/spec's remote main and opens a PR bumping the pin | ||
| # (and regenerating the Ajv validators against the new schema content) on drift. | ||
| # Never fails the build — a stale pin is worth a PR, not a red CI run. | ||
|
|
||
| on: | ||
| schedule: | ||
| - cron: "0 6 * * 1" # weekly, Monday 06:00 UTC | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: write | ||
| pull-requests: write | ||
|
|
||
| jobs: | ||
| check-drift: | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 10 | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| with: | ||
| submodules: recursive | ||
|
|
||
| - name: Compare pinned commit against upstream main | ||
| id: drift | ||
| run: | | ||
| pinned="$(git -C devcontainer-spec rev-parse HEAD)" | ||
| upstream="$(git ls-remote https://github.com/devcontainers/spec.git refs/heads/main | cut -f1)" | ||
| echo "pinned=$pinned" >> "$GITHUB_OUTPUT" | ||
| echo "upstream=$upstream" >> "$GITHUB_OUTPUT" | ||
| if [ "$pinned" = "$upstream" ]; then | ||
| echo "drifted=false" >> "$GITHUB_OUTPUT" | ||
| else | ||
| echo "drifted=true" >> "$GITHUB_OUTPUT" | ||
| fi | ||
|
|
||
| - uses: oven-sh/setup-bun@v2 | ||
| if: steps.drift.outputs.drifted == 'true' | ||
|
|
||
| - name: Bump the pin and regenerate validators | ||
| if: steps.drift.outputs.drifted == 'true' | ||
| run: | | ||
| git -C devcontainer-spec checkout "${{ steps.drift.outputs.upstream }}" | ||
|
|
||
| retrieved="$(date -u +%Y-%m-%d)" | ||
| tmp="$(mktemp)" | ||
| jq --arg commit "${{ steps.drift.outputs.upstream }}" \ | ||
| --arg retrieved "$retrieved" \ | ||
| 'map_values(.commit = $commit | .retrieved = $retrieved | .url |= sub("/spec/[^/]+/schemas/"; "/spec/" + $commit + "/schemas/"))' \ | ||
| src/schema/provenance.json > "$tmp" | ||
| mv "$tmp" src/schema/provenance.json | ||
|
|
||
| bun install | ||
| bun run scripts/build-validators.ts | ||
|
|
||
| - name: Open a PR | ||
| if: steps.drift.outputs.drifted == 'true' | ||
| uses: peter-evans/create-pull-request@v6 | ||
| with: | ||
| commit-message: "chore: bump devcontainer-spec to ${{ steps.drift.outputs.upstream }}" | ||
| title: "chore: bump devcontainer-spec pin to ${{ steps.drift.outputs.upstream }}" | ||
| body: | | ||
| `devcontainers/spec`'s `main` moved from `${{ steps.drift.outputs.pinned }}` | ||
| to `${{ steps.drift.outputs.upstream }}`. This bumps the submodule pin, | ||
| refreshes `src/schema/provenance.json`, and regenerates the Ajv validators | ||
| against the new schema content. | ||
|
|
||
| Opened automatically by the schema-drift workflow — review the schema diff | ||
| before merging. | ||
| branch: chore/schema-drift | ||
| delete-branch: true |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,20 +1,34 @@ | ||
| # Build output | ||
| /dist/ | ||
| /bin/ | ||
| /dcx | ||
| /dcx.exe | ||
| # dependencies (bun install) | ||
| node_modules | ||
|
|
||
| # Test and coverage artefacts | ||
| *.test | ||
| *.out | ||
| coverage.* | ||
| # output | ||
| out | ||
| dist | ||
| *.tgz | ||
|
|
||
| # Editor and OS noise | ||
| .DS_Store | ||
| .idea/ | ||
| *.swp | ||
| # code coverage | ||
| coverage | ||
| *.lcov | ||
|
|
||
| # logs | ||
| logs | ||
| _.log | ||
| report.[0-9]_.[0-9]_.[0-9]_.[0-9]_.json | ||
|
|
||
| # dotenv environment variable files | ||
| .env | ||
| .env.development.local | ||
| .env.test.local | ||
| .env.production.local | ||
| .env.local | ||
|
|
||
| # Extension build output | ||
| extensions/vscode/node_modules/ | ||
| extensions/vscode/out/ | ||
| extensions/vscode/*.vsix | ||
| # caches | ||
| .eslintcache | ||
| .cache | ||
| *.tsbuildinfo | ||
|
|
||
| # IntelliJ based IDEs | ||
| .idea | ||
|
|
||
| # Finder (MacOS) folder config | ||
| .DS_Store |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| [submodule "devcontainer-spec"] | ||
| path = devcontainer-spec | ||
| url = https://github.com/devcontainers/spec.git |
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,13 @@ | ||
| # .gitignore is honoured automatically; these are tracked but not ours to format. | ||
|
|
||
| # Upstream spec submodule and schemas vendored from it | ||
| devcontainer-spec | ||
| schemas | ||
|
|
||
| # Fixtures may be deliberately malformed | ||
| testdata | ||
|
|
||
| bun.lock | ||
|
|
||
| # Standalone Ajv output, generated by scripts/build-validators.ts — committed, not ours to format | ||
| src/schema/generated |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,10 @@ | ||
| { | ||
| "$schema": "https://json.schemastore.org/prettierrc", | ||
| "printWidth": 100, | ||
| "tabWidth": 2, | ||
| "useTabs": false, | ||
| "semi": true, | ||
| "singleQuote": false, | ||
| "trailingComma": "all", | ||
| "endOfLine": "lf" | ||
| } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: lonhutt/dcx
Length of output: 3274
🤖 get_repo_knowledge executed:
get_repo_knowledge lonhutt/dcx /tmp/coderabbit-repo-knowledge/lonhutt-dcx-81b708c3/architectureLength of output: 3109
🏁 Script executed:
Repository: lonhutt/dcx
Length of output: 3207
🏁 Script executed:
Repository: lonhutt/dcx
Length of output: 290
Sensitive Data Exposure
Reachability: External
Exploitability: Moderate
CWE: CWE-522 — Insufficiently Protected Credentials
Disable persisted checkout credentials in all three jobs.
actions/checkout@v4persists the read-scoped token before these jobs run dependency installation and repository code. Setpersist-credentials: falseon each checkout step. The workflow commands, package scripts, and lockfile do not require authenticated Git access.Disable credential persistence
Apply this change to all three checkout steps.
🤖 Prompt for AI Agents
Sources: Learnings, Linters/SAST tools