Skip to content

ci: move validate to ubuntu-latest; enforce version bump at publish - #37

Merged
robgilbreath merged 3 commits into
mainfrom
chore/repo-standard/hosted-runners
Sep 1, 2026
Merged

robgilbreath merged 3 commits into
mainfrom
chore/repo-standard/hosted-runners

Conversation

@robgilbreath

@robgilbreath robgilbreath commented Sep 1, 2026 •

Copy link
Copy Markdown
Collaborator

Two commits, two fixes; together they are what has kept every Validate run red since June.

1. runs-on: self-hosted -> ubuntu-latest (pncit/.github#3)

The org's self-hosted runner group has allows_public_repositories: false (correctly — it keeps fork PRs off the fleet), so this public repo's validate job could never be scheduled. npm-publish.yml was already on ubuntu-latest.

  • validate.yml: runs-on: ubuntu-latest, plus actions/setup-node (node-version-file: .nvmrc) before verify-node-toolchain. That vendored action asserts node/npm majors against the org vars (NODE_MAJOR_VERSION=24 / NPM_MAJOR_VERSION=11) and previously relied on the self-hosted box having Node 24 preinstalled; on the hosted image it would have checked Ubuntu's system Node. Node 24 bundles npm 11, so the check passes as-is. validate-codebase runs setup-node again afterwards — cache hit.
  • Comments: the same-repo if gate is now a policy choice rather than a runner-safety requirement; dropped the stale "node-quickbooks uses self-hosted" aside in the publish workflow (Move validate/publish to ubuntu-latest; release 2.0.53 node-quickbooks#13 moves it too).

Nothing in the workflow depended on runner-local state: npm ci hits registry.npmjs.org, no cached paths or local registries.

2. Version gate moves to publish (#33, Option 3)

The Verify version changed step in validate.yml ran on every PR and failed 100% of Dependabot PRs, since Dependabot never bumps the package's own version.

The gate's purpose is to prevent an unversioned release. npm-publish.yml already enforces that on its own: it only fires via workflow_run on a push to main after a green Validate, and npm publish refuses to publish over a version that already exists on npm. So the PR-time copy was redundant as an enforcement mechanism — its only effect was to block PRs that don't release anything.

Changes:

  • validate.yml: remove the Verify version changed step (and the fetch-depth: 2 that existed only for it).
  • npm-publish.yml: add an explicit Check if version already published step (npm view name@version) and skip npm publish when the version is already on npm. Without this, an unbumped merge would still be safe (npm 403s) but would show as a failed Publish run; now it is a clean no-op with a notice. Same pattern as datto-rmm-api-client.

Net effect: Dependabot PRs (#23, #28, #30, #31, #32) can be validated and merged individually; the next PR that bumps package.json releases them all. Option 1 (if: github.actor != 'dependabot[bot]') was not used — it would keep a duplicate gate that still blocks any human CI/docs-only PR for no release benefit.

Closes #33
Refs pncit/.github#3

🤖 Generated with Claude Code

Also pins npm@12.0.2 in publish (was floating on @latest).

robgilbreath and others added 3 commits September 1, 2026 11:39
The org runner group rejects jobs from public repos, so `runs-on:
self-hosted` has left every validate run since 2026-06-20 unschedulable.
Switch to GitHub-hosted (npm-publish.yml already is) and install the
.nvmrc Node ahead of verify-node-toolchain so it checks our toolchain,
not the image's system Node.

Refs pncit/.github#3

Co-Authored-By: Claude Code <noreply@anthropic.com>
The PR-time "Verify version changed" gate failed every Dependabot PR
since 2026-06-24 because Dependabot never bumps the package's own
version. The check exists to stop an unversioned release, and
npm-publish.yml already only fires on push to main after a green
Validate and cannot republish an existing version — so publish is where
the rule belongs. Drop the PR gate and make the publish-side check
explicit: look the version up on npm first and skip (rather than fail)
when it is already there.

Closes #33
Refs pncit/.github#3

Co-Authored-By: Claude Code <noreply@anthropic.com>
Was floating on @latest. Org standard is npm 12 (matches shared-actions
validate-codebase, which pins 12.0.2); npm/cli#9722 was fixed in 12.0.1.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@robgilbreath
robgilbreath merged commit c134f30 into main Sep 1, 2026
1 check passed
@robgilbreath
robgilbreath deleted the chore/repo-standard/hosted-runners branch September 1, 2026 21:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix timezest version gate that fails every Dependabot PR

1 participant