Repository navigation
ci: move validate to ubuntu-latest; enforce version bump at publish - #37
Merged
Merged
Conversation
The org runner group rejects jobs from public repos, so `runs-on: self-hosted` has left every validate run since 2026-06-20 unschedulable. Switch to GitHub-hosted (npm-publish.yml already is) and install the .nvmrc Node ahead of verify-node-toolchain so it checks our toolchain, not the image's system Node. Refs pncit/.github#3 Co-Authored-By: Claude Code <noreply@anthropic.com>
The PR-time "Verify version changed" gate failed every Dependabot PR since 2026-06-24 because Dependabot never bumps the package's own version. The check exists to stop an unversioned release, and npm-publish.yml already only fires on push to main after a green Validate and cannot republish an existing version — so publish is where the rule belongs. Drop the PR gate and make the publish-side check explicit: look the version up on npm first and skip (rather than fail) when it is already there. Closes #33 Refs pncit/.github#3 Co-Authored-By: Claude Code <noreply@anthropic.com>
Was floating on @latest. Org standard is npm 12 (matches shared-actions validate-codebase, which pins 12.0.2); npm/cli#9722 was fixed in 12.0.1. Co-Authored-By: Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two commits, two fixes; together they are what has kept every Validate run red since June.
1.
runs-on: self-hosted->ubuntu-latest(pncit/.github#3)The org's self-hosted runner group has
allows_public_repositories: false(correctly — it keeps fork PRs off the fleet), so this public repo's validate job could never be scheduled.npm-publish.ymlwas already onubuntu-latest.validate.yml:runs-on: ubuntu-latest, plusactions/setup-node(node-version-file: .nvmrc) beforeverify-node-toolchain. That vendored action assertsnode/npmmajors against the org vars (NODE_MAJOR_VERSION=24/NPM_MAJOR_VERSION=11) and previously relied on the self-hosted box having Node 24 preinstalled; on the hosted image it would have checked Ubuntu's system Node. Node 24 bundles npm 11, so the check passes as-is.validate-codebaseruns setup-node again afterwards — cache hit.ifgate is now a policy choice rather than a runner-safety requirement; dropped the stale "node-quickbooks uses self-hosted" aside in the publish workflow (Move validate/publish to ubuntu-latest; release 2.0.53 node-quickbooks#13 moves it too).Nothing in the workflow depended on runner-local state:
npm cihits registry.npmjs.org, no cached paths or local registries.2. Version gate moves to publish (#33, Option 3)
The
Verify version changedstep invalidate.ymlran on every PR and failed 100% of Dependabot PRs, since Dependabot never bumps the package's own version.The gate's purpose is to prevent an unversioned release.
npm-publish.ymlalready enforces that on its own: it only fires viaworkflow_runon a push to main after a green Validate, andnpm publishrefuses to publish over a version that already exists on npm. So the PR-time copy was redundant as an enforcement mechanism — its only effect was to block PRs that don't release anything.Changes:
validate.yml: remove theVerify version changedstep (and thefetch-depth: 2that existed only for it).npm-publish.yml: add an explicitCheck if version already publishedstep (npm view name@version) and skipnpm publishwhen the version is already on npm. Without this, an unbumped merge would still be safe (npm 403s) but would show as a failed Publish run; now it is a clean no-op with a notice. Same pattern asdatto-rmm-api-client.Net effect: Dependabot PRs (#23, #28, #30, #31, #32) can be validated and merged individually; the next PR that bumps
package.jsonreleases them all. Option 1 (if: github.actor != 'dependabot[bot]') was not used — it would keep a duplicate gate that still blocks any human CI/docs-only PR for no release benefit.Closes #33
Refs pncit/.github#3
🤖 Generated with Claude Code
Also pins npm@12.0.2 in publish (was floating on @latest).