ci: gate the artifact that actually ships, not only the ones in pull requests - #129
Merged
Merged
Conversation
…requests
`scripts/check-dist-links.mjs` was wired into docs-pr-check.yml alone, and that
workflow is `pull_request`-only. So the job that uploads to GitHub Pages ran
`npm ci`, `npm run docs:build`, `touch .nojekyll`, `upload-pages-artifact`, with
nothing between the build and the upload.
Two ways a broken site shipped past a green history:
- a direct push to main was ungated entirely;
- two pull requests, each green against its own base, can combine into a broken
artifact that neither run examined.
The step goes BEFORE `.nojekyll` and the upload, so a bad artifact is never
published rather than published and then reported.
No `continue-on-error`, no `|| true`, and deliberately not `if: always()`. A
failed build leaves no artifact, and measuring an absent or stale dist is the
exact failure this exists to prevent; the script refuses to run when dist is
missing, so a green result here always means it read the bytes this job is about
to upload.
Verified on this branch, not assumed:
npm run docs:build exit 0
node scripts/check-dist-links.mjs exit 0 - 219 pages, 107,738 absolute
references, 474 distinct targets, canaries
passing
...and the gate proved load-bearing here the same way it was in the pull-request
workflow. With `link: '/why'` changed to `'/whyy'` in the config.ts navbar:
npm run docs:build exit 0 <- the hole
node scripts/check-dist-links.mjs exit 1 <- 424 dead references, 212 pages
Restored, rebuilt, both green again.
This does not make docs-pr-check.yml redundant; the coverage map in that file says
why. It reports a REPOSITORY path a contributor can act on, and it runs on a
source-only change. This one is the last thing between a build and the live site.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
scripts/check-dist-links.mjswas wired intodocs-pr-check.ymlalone — and that workflow ispull_request-only. So the job that uploads to GitHub Pages ran:…with nothing between the build and the upload.
Two ways a broken site shipped past a green history
mainwas ungated entirely —docs-pr-check.ymlnever firesWhere the step goes, and why there
Between Build docs and
.nojekyll— before the upload, so a bad artifact is never published rather than published and then reported.No
continue-on-error, no|| true, and deliberately notif: always(). A failed build leaves no artifact, and measuring an absent or stale dist is the exact failure this exists to prevent. The script refuses to run when dist is missing, so a green result here always means it read the bytes this job is about to upload.Verified on this branch
And proved load-bearing here the same way it was in the PR workflow —
link: '/why'→'/whyy'in the config.ts navbar:Restored, rebuilt, both green again. Only
deploy-docs.ymlis modified; YAML re-parsed to confirm the step sits at index 4 between build (3) and.nojekyll(5), with keysname,runonly.This does not make
docs-pr-check.ymlredundantThe coverage map in that file says why. It reports a repository path a contributor can act on (this one reports dist paths), and it runs on a source-only change. This step is the last thing between a build and the live site.