Skip to content

Add CI workflow to auto-rebuild dist - #276

Merged
spatten merged 7 commits into
mainfrom
ci/auto-rebuild-dist
Mar 30, 2026
Merged

spatten merged 7 commits into
mainfrom
ci/auto-rebuild-dist

Conversation

@spatten

@spatten spatten commented Mar 30, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Dependabot PRs update package.json and yarn.lock but don't rebuild dist/index.js, which is the bundled file the action actually runs. This means dependency updates from Dependabot don't actually take effect until someone manually runs yarn build and commits the result.

This adds a new workflow that automatically rebuilds and commits dist/ when source or dependency files change on PR branches.

Triggers on changes to: package.json, yarn.lock, src/**, tsconfig.json
Skips: pushes to main, dist-only changes (no infinite loop)

NOTE: The fossa scan failure is a real vuln issue that is fixed in #275

Checklist

  • If I changed code, I ran yarn build and committed resulting changes.
    • N/A — this is a CI-only change.
  • I added an example exercising this PRs functionality to .github/workflows/test.yml or explained why it doesn't make sense to do so.
    • This is a new workflow file, not a code change to the action itself.

Important

After merging, make sure to create a new GitHub release and associated tag for this release.
You can either create the tag locally and then create a corresponding GitHub release,
or just create both the tag and release using the GitHub Release UI.

Additionally, if this is not a breaking change, make sure to update the v1 tag:

# Check out the tag you want to set as `v1`.
git checkout $TAG

# Delete and re-create the `v1` tag.
git tag -d v1 && git push origin :refs/tags/v1 && git tag v1 && git push origin tag v1

Dependabot PRs update package.json and yarn.lock but don't rebuild
dist/index.js, which is the bundled file the action actually runs.
This workflow automatically rebuilds and commits dist when source
or dependency files change on PR branches.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Mar 30, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@spatten has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 47 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 8 minutes and 47 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 29ffc91c-5f8e-4260-84af-3c059a697e30

📥 Commits

Reviewing files that changed from the base of the PR and between 22b2bf8 and c40f5f1.

📒 Files selected for processing (1)
  • .github/workflows/rebuild-dist.yml

Walkthrough

Adds a new GitHub Actions workflow .github/workflows/rebuild-dist.yml named "Rebuild dist". It triggers on push to all branches except main and runs only if the last commit modifies package.json, yarn.lock, tsconfig.json, or files under src/. The job runs on ubuntu-latest, sets up Node.js 20.x, installs Yarn, runs yarn --frozen-lockfile and yarn build, stages dist/, and if dist/ differs commits it as "Rebuild dist" using the Actions bot identity and pushes to the current branch. After pushing, the workflow emits an error annotation and exits with status 1.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: adding a CI workflow to automatically rebuild the dist directory.
Description check ✅ Passed The description includes all required template sections with clear context about the problem and solution, comprehensive checklist items with appropriate explanations.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/rebuild-dist.yml:
- Around line 22-30: The workflow currently always reinstalls dependencies
("Install dependencies" running "yarn --frozen-lockfile") which slows CI; add a
cache step using actions/cache (e.g., actions/cache@v4) before the "Install
dependencies" step to cache node_modules keyed by the yarn.lock hash and restore
it when available; specifically, insert a step referencing actions/cache@v4 (or
use setup-node's cache option) keyed on yarn.lock and with path node_modules so
the "Install dependencies" step and the "Install yarn" step benefit from
restored dependencies on subsequent runs.
- Around line 16-43: The workflow job "rebuild-dist" can run concurrently on
multiple pushes causing race conditions when committing/pushing dist; add a
concurrency block at the workflow or job level (e.g., under the top-level or
under jobs.rebuild-dist) with group: rebuild-dist-${{ github.ref }} and
cancel-in-progress: false to serialize runs per branch so queued runs wait and
avoid conflicting pushes.
- Around line 26-27: The "Install yarn" workflow step uses npm install -g yarn
which installs the latest Yarn and can cause nondeterministic builds; update the
"Install yarn" step to either pin a specific Yarn version (e.g., npm install -g
yarn@<version>) or replace the step with Corepack enable/prepare commands and
add a packageManager field in package.json to lock the Yarn version; modify the
workflow step titled "Install yarn" (and package.json packageManager)
accordingly to ensure reproducible installs.
- Line 37: The current CI check uses the command "git diff --name-only dist/"
which only detects changes to tracked files and can miss newly created or
deleted files in dist/; replace this with a sequence that stages dist/ (e.g.,
run a git add -A or git add --intent-to-add for dist/) and then use "git diff
--staged --quiet" (or "git diff --staged --exit-code") to detect any staged
modifications, additions, or deletions so the workflow will correctly trigger
when yarn build produces new/removed files in dist/.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: cd584f80-54ce-4bab-86d6-b918e8436e2b

📥 Commits

Reviewing files that changed from the base of the PR and between c9be25a and 3c67631.

📒 Files selected for processing (1)
  • .github/workflows/rebuild-dist.yml

Comment thread .github/workflows/rebuild-dist.yml
Comment thread .github/workflows/rebuild-dist.yml Outdated
Comment on lines +22 to +30
- uses: actions/setup-node@v6
with:
node-version: 20.x

- name: Install yarn
run: npm install -g yarn

- name: Install dependencies
run: yarn --frozen-lockfile

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick | 🔵 Trivial

Consider caching node_modules to improve workflow performance.

Adding a cache step would speed up dependency installation on subsequent runs.

⚡ Add dependency caching
 - uses: actions/setup-node@v6
   with:
     node-version: 20.x
+    cache: 'yarn'

 - name: Install yarn
   run: npm install -g yarn

Alternatively, use a dedicated cache action for more control:

- uses: actions/cache@v4
  with:
    path: node_modules
    key: ${{ runner.os }}-yarn-${{ hashFiles('**/yarn.lock') }}
    restore-keys: |
      ${{ runner.os }}-yarn-
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/rebuild-dist.yml around lines 22 - 30, The workflow
currently always reinstalls dependencies ("Install dependencies" running "yarn
--frozen-lockfile") which slows CI; add a cache step using actions/cache (e.g.,
actions/cache@v4) before the "Install dependencies" step to cache node_modules
keyed by the yarn.lock hash and restore it when available; specifically, insert
a step referencing actions/cache@v4 (or use setup-node's cache option) keyed on
yarn.lock and with path node_modules so the "Install dependencies" step and the
"Install yarn" step benefit from restored dependencies on subsequent runs.

Comment thread .github/workflows/rebuild-dist.yml Outdated
Comment on lines +26 to +27
- name: Install yarn
run: npm install -g yarn

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick | 🔵 Trivial

Consider pinning the Yarn version for reproducibility.

Installing the latest Yarn version with npm install -g yarn could lead to inconsistent behavior if Yarn releases breaking changes.

♻️ Pin Yarn version or use Corepack

Option 1: Pin Yarn version

-      - name: Install yarn
-        run: npm install -g yarn
+      - name: Install yarn
+        run: npm install -g yarn@1.22.19

Option 2: Use Corepack (recommended for Node.js 16.10+)

-      - name: Install yarn
-        run: npm install -g yarn
+      - name: Enable Corepack
+        run: corepack enable

Then add a packageManager field to package.json to specify the exact Yarn version.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- name: Install yarn
run: npm install -g yarn
- name: Install yarn
run: npm install -g yarn@1.22.19
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/rebuild-dist.yml around lines 26 - 27, The "Install yarn"
workflow step uses npm install -g yarn which installs the latest Yarn and can
cause nondeterministic builds; update the "Install yarn" step to either pin a
specific Yarn version (e.g., npm install -g yarn@<version>) or replace the step
with Corepack enable/prepare commands and add a packageManager field in
package.json to lock the Yarn version; modify the workflow step titled "Install
yarn" (and package.json packageManager) accordingly to ensure reproducible
installs.

Comment thread .github/workflows/rebuild-dist.yml Outdated
- Add concurrency group to prevent race conditions from parallel pushes
- Use git diff --staged to detect new/modified/deleted files in dist/

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
.github/workflows/rebuild-dist.yml (1)

30-34: 🧹 Nitpick | 🔵 Trivial

Pin Yarn (or use Corepack) to avoid nondeterministic builds.

Line 31 installs the latest Yarn globally, which can silently change behavior across runs (including lockfile/install flags used on Line 34). Please lock the Yarn version for reproducibility.

♻️ Suggested change
-      - name: Install yarn
-        run: npm install -g yarn
+      - name: Enable Corepack and pin Yarn
+        run: |
+          corepack enable
+          corepack prepare yarn@1.22.22 --activate
Does Yarn 4 still support `--frozen-lockfile`, and what is the recommended equivalent? Also confirm best practices for pinning Yarn in GitHub Actions using Corepack.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/rebuild-dist.yml around lines 30 - 34, The workflow
currently installs the latest Yarn in the "Install yarn" step and then runs
"yarn --frozen-lockfile" in the "Install dependencies" step, which can lead to
nondeterministic builds; change the "Install yarn" step to pin a specific Yarn
release (or enable Corepack and prepare a specific yarn@<version>) so the runner
always uses the same major/minor, and update the "Install dependencies" step to
use the lockfile flag that matches that pinned Yarn (replace the legacy
--frozen-lockfile with the recommended equivalent for the pinned major, e.g.,
Yarn v2+/v3+ uses the immutable install flag). Also add a short comment or check
that documents the chosen Yarn major so future maintainers know why the specific
version/flag was selected.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Duplicate comments:
In @.github/workflows/rebuild-dist.yml:
- Around line 30-34: The workflow currently installs the latest Yarn in the
"Install yarn" step and then runs "yarn --frozen-lockfile" in the "Install
dependencies" step, which can lead to nondeterministic builds; change the
"Install yarn" step to pin a specific Yarn release (or enable Corepack and
prepare a specific yarn@<version>) so the runner always uses the same
major/minor, and update the "Install dependencies" step to use the lockfile flag
that matches that pinned Yarn (replace the legacy --frozen-lockfile with the
recommended equivalent for the pinned major, e.g., Yarn v2+/v3+ uses the
immutable install flag). Also add a short comment or check that documents the
chosen Yarn major so future maintainers know why the specific version/flag was
selected.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 1efb9405-b093-4aa1-8a70-7998f1d202b8

📥 Commits

Reviewing files that changed from the base of the PR and between 3c67631 and 5fb7e23.

📒 Files selected for processing (1)
  • .github/workflows/rebuild-dist.yml

@spatten
spatten marked this pull request as ready for review March 30, 2026 18:35
@spatten
spatten requested a review from a team as a code owner March 30, 2026 18:35
@spatten
spatten requested a review from nficca March 30, 2026 18:35

@csasarak csasarak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks pretty good, please address the one comment I left about failure. Additionally, is this something we should do on merge? Or is push the best choice?

Comment thread .github/workflows/rebuild-dist.yml
spatten and others added 4 commits March 30, 2026 11:47
The workflow still rebuilds and pushes the fix, but now fails
so it can block auto-merge as a required status check. The
subsequent push triggers a new run that passes.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The paths filter prevented the workflow from running on PRs that
don't touch source/dependency files, which blocks merging when
this is a required status check. Instead, always trigger but
skip the build early if no relevant files changed.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Combine install, build, and verify steps into a single script
step so only two steps need the if condition instead of five.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (2)
.github/workflows/rebuild-dist.yml (2)

32-35: 🧹 Nitpick | 🔵 Trivial

Consider adding cache: 'yarn' to speed up dependency installation.

The actions/setup-node action supports built-in caching. Adding cache: 'yarn' would improve workflow performance on subsequent runs.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/rebuild-dist.yml around lines 32 - 35, Add the built-in
yarn cache to the GitHub Actions node setup step: update the
actions/setup-node@v6 invocation (the step using node-version: 20.x) to include
with: cache: 'yarn' so the runner will cache Yarn dependencies between runs and
speed up installs.

37-39: 🧹 Nitpick | 🔵 Trivial

Consider pinning the Yarn version for reproducibility.

Installing yarn without a version specifier (npm install -g yarn) could lead to inconsistent behavior if Yarn releases breaking changes.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/rebuild-dist.yml around lines 37 - 39, The "Install yarn"
step currently runs "npm install -g yarn" which installs whatever Yarn version
is latest; change this to pin a specific Yarn version (e.g., yarn@1.22.19 or
yarn@3.x) to ensure reproducible builds by replacing the command with a
versioned install (or enable Corepack with a pinned Yarn version); update the
step's run command and note the chosen version in the step name to make the pin
obvious when scanning the workflow.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Duplicate comments:
In @.github/workflows/rebuild-dist.yml:
- Around line 32-35: Add the built-in yarn cache to the GitHub Actions node
setup step: update the actions/setup-node@v6 invocation (the step using
node-version: 20.x) to include with: cache: 'yarn' so the runner will cache Yarn
dependencies between runs and speed up installs.
- Around line 37-39: The "Install yarn" step currently runs "npm install -g
yarn" which installs whatever Yarn version is latest; change this to pin a
specific Yarn version (e.g., yarn@1.22.19 or yarn@3.x) to ensure reproducible
builds by replacing the command with a versioned install (or enable Corepack
with a pinned Yarn version); update the step's run command and note the chosen
version in the step name to make the pin obvious when scanning the workflow.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 4045bd82-c8d3-455c-ab95-40ab6988e3a0

📥 Commits

Reviewing files that changed from the base of the PR and between 5fb7e23 and 22b2bf8.

📒 Files selected for processing (1)
  • .github/workflows/rebuild-dist.yml

@spatten
spatten enabled auto-merge (squash) March 30, 2026 19:28
@spatten
spatten merged commit 0bdc47f into main Mar 30, 2026
3 checks passed
@spatten
spatten deleted the ci/auto-rebuild-dist branch March 30, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants