Skip to content

chore: add CI workflow - #7

Merged
joaovjo merged 1 commit into
mainfrom
chore/sprint-27-ci
Aug 11, 2026
Merged

joaovjo merged 1 commit into
mainfrom
chore/sprint-27-ci

Conversation

@joaovjo

@joaovjo joaovjo commented Aug 11, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Add GitHub Actions CI (bun test + biome lint) on PR/push to main

Test plan

  • bun test local
  • bun run lint local
  • CI green on PR

Summary by CodeRabbit

  • Tests
    • Added automated checks for pull requests and updates to the main branch.
    • Verifies dependency installation, tests, and linting on Ubuntu.
    • Cancels outdated runs to avoid redundant checks.

Co-authored-by: Cursor <cursoragent@cursor.com>
@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Added a GitHub Actions workflow that runs on pull requests and pushes to main. The workflow uses Bun to install frozen dependencies, run tests, and run linting on Ubuntu.

Changes

CI Verification

Layer / File(s) Summary
Workflow triggers and verification job
.github/workflows/ci.yml
The workflow runs for pull requests and main pushes. It uses read-only repository access, cancels superseded runs, checks out the code, installs locked dependencies with Bun, and runs tests and linting.

Estimated code review effort: 2 (Simple) | ~10 minutes

Poem

A rabbit checks the workflow run,
Bun hops through tests beneath the sun.
Frozen locks stay neat and tight,
Linting keeps each line just right.
Pull requests and pushes play—
Green checks greet the day.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the added GitHub Actions CI workflow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/ci.yml
uses: actions/checkout@v6

- name: Set up Bun
uses: oven-sh/setup-bun@v2

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)

25-26: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

Use a pinned Bun version for CI.

bun-version: latest can change the runtime without a repository change. It also bypasses setup-bun's default lookup of packageManager and engines.bun. Use the repository's declared version or a committed .bun-version file instead. (github.com)

Proposed deterministic setup
-          bun-version: latest
+          bun-version-file: .bun-version
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 25 - 26, Update the Bun setup step’s
bun-version configuration to use the repository’s declared Bun version or
committed .bun-version file instead of latest, preserving the existing setup-bun
workflow while making CI runtime selection deterministic.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Around line 21-24: Update the actions/checkout and oven-sh/setup-bun
references in the CI workflow to immutable full commit SHAs instead of the
mutable v6 and v2 tags, preserving their existing action versions and
configuration.

---

Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 25-26: Update the Bun setup step’s bun-version configuration to
use the repository’s declared Bun version or committed .bun-version file instead
of latest, preserving the existing setup-bun workflow while making CI runtime
selection deterministic.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 21ff79b3-8f21-4969-8d85-e7653b97577d

📥 Commits

Reviewing files that changed from the base of the PR and between 5980f52 and 502601c.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

Comment thread .github/workflows/ci.yml
Comment on lines +21 to +24
uses: actions/checkout@v6

- name: Set up Bun
uses: oven-sh/setup-bun@v2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/ci.yml
printf '%s\n' '--- action references ---'
rg -n 'uses:' .github/workflows
printf '%s\n' '--- repository pinning guidance ---'
rg -n -i 'pin|commit sha|checkout@|setup-bun@|dependabot' .github README.md .github 2>/dev/null || true
printf '%s\n' '--- remote tag metadata ---'
if command -v gh >/dev/null 2>&1; then
  for spec in 'actions/checkout:v6' 'oven-sh/setup-bun:v2'; do
    repo=${spec%:*}
    tag=${spec#*:}
    printf '%s\n' "$spec"
    gh api "repos/$repo/git/ref/tags/$tag" --jq '{object_sha:.object.sha,object_type:.object.type}' || true
  done
else
  printf '%s\n' 'gh is unavailable'
fi

Repository: nino-ts/http

Length of output: 2141


Pin action references to full commit SHAs.

actions/checkout@v6 and oven-sh/setup-bun@v2 use mutable tags. Pin both actions to full commit SHAs to prevent tag movement from changing executed code.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 21 - 24, Update the actions/checkout
and oven-sh/setup-bun references in the CI workflow to immutable full commit
SHAs instead of the mutable v6 and v2 tags, preserving their existing action
versions and configuration.

@joaovjo
joaovjo merged commit 2534d74 into main Aug 11, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants