chore: add CI workflow - #7
Conversation
Co-authored-by: Cursor <cursoragent@cursor.com>
📝 WalkthroughWalkthroughAdded a GitHub Actions workflow that runs on pull requests and pushes to ChangesCI Verification
Estimated code review effort: 2 (Simple) | ~10 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| uses: actions/checkout@v6 | ||
|
|
||
| - name: Set up Bun | ||
| uses: oven-sh/setup-bun@v2 |
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)
25-26: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick winUse a pinned Bun version for CI.
bun-version: latestcan change the runtime without a repository change. It also bypassessetup-bun's default lookup ofpackageManagerandengines.bun. Use the repository's declared version or a committed.bun-versionfile instead. (github.com)Proposed deterministic setup
- bun-version: latest + bun-version-file: .bun-version🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/ci.yml around lines 25 - 26, Update the Bun setup step’s bun-version configuration to use the repository’s declared Bun version or committed .bun-version file instead of latest, preserving the existing setup-bun workflow while making CI runtime selection deterministic.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Around line 21-24: Update the actions/checkout and oven-sh/setup-bun
references in the CI workflow to immutable full commit SHAs instead of the
mutable v6 and v2 tags, preserving their existing action versions and
configuration.
---
Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 25-26: Update the Bun setup step’s bun-version configuration to
use the repository’s declared Bun version or committed .bun-version file instead
of latest, preserving the existing setup-bun workflow while making CI runtime
selection deterministic.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 21ff79b3-8f21-4969-8d85-e7653b97577d
📒 Files selected for processing (1)
.github/workflows/ci.yml
| uses: actions/checkout@v6 | ||
|
|
||
| - name: Set up Bun | ||
| uses: oven-sh/setup-bun@v2 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/ci.yml
printf '%s\n' '--- action references ---'
rg -n 'uses:' .github/workflows
printf '%s\n' '--- repository pinning guidance ---'
rg -n -i 'pin|commit sha|checkout@|setup-bun@|dependabot' .github README.md .github 2>/dev/null || true
printf '%s\n' '--- remote tag metadata ---'
if command -v gh >/dev/null 2>&1; then
for spec in 'actions/checkout:v6' 'oven-sh/setup-bun:v2'; do
repo=${spec%:*}
tag=${spec#*:}
printf '%s\n' "$spec"
gh api "repos/$repo/git/ref/tags/$tag" --jq '{object_sha:.object.sha,object_type:.object.type}' || true
done
else
printf '%s\n' 'gh is unavailable'
fiRepository: nino-ts/http
Length of output: 2141
Pin action references to full commit SHAs.
actions/checkout@v6 and oven-sh/setup-bun@v2 use mutable tags. Pin both actions to full commit SHAs to prevent tag movement from changing executed code.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yml around lines 21 - 24, Update the actions/checkout
and oven-sh/setup-bun references in the CI workflow to immutable full commit
SHAs instead of the mutable v6 and v2 tags, preserving their existing action
versions and configuration.
Summary
Test plan
Summary by CodeRabbit