Add CI workflow to auto-rebuild dist - #276
Conversation
Dependabot PRs update package.json and yarn.lock but don't rebuild dist/index.js, which is the bundled file the action actually runs. This workflow automatically rebuilds and commits dist when source or dependency files change on PR branches. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 8 minutes and 47 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
WalkthroughAdds a new GitHub Actions workflow 🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/rebuild-dist.yml:
- Around line 22-30: The workflow currently always reinstalls dependencies
("Install dependencies" running "yarn --frozen-lockfile") which slows CI; add a
cache step using actions/cache (e.g., actions/cache@v4) before the "Install
dependencies" step to cache node_modules keyed by the yarn.lock hash and restore
it when available; specifically, insert a step referencing actions/cache@v4 (or
use setup-node's cache option) keyed on yarn.lock and with path node_modules so
the "Install dependencies" step and the "Install yarn" step benefit from
restored dependencies on subsequent runs.
- Around line 16-43: The workflow job "rebuild-dist" can run concurrently on
multiple pushes causing race conditions when committing/pushing dist; add a
concurrency block at the workflow or job level (e.g., under the top-level or
under jobs.rebuild-dist) with group: rebuild-dist-${{ github.ref }} and
cancel-in-progress: false to serialize runs per branch so queued runs wait and
avoid conflicting pushes.
- Around line 26-27: The "Install yarn" workflow step uses npm install -g yarn
which installs the latest Yarn and can cause nondeterministic builds; update the
"Install yarn" step to either pin a specific Yarn version (e.g., npm install -g
yarn@<version>) or replace the step with Corepack enable/prepare commands and
add a packageManager field in package.json to lock the Yarn version; modify the
workflow step titled "Install yarn" (and package.json packageManager)
accordingly to ensure reproducible installs.
- Line 37: The current CI check uses the command "git diff --name-only dist/"
which only detects changes to tracked files and can miss newly created or
deleted files in dist/; replace this with a sequence that stages dist/ (e.g.,
run a git add -A or git add --intent-to-add for dist/) and then use "git diff
--staged --quiet" (or "git diff --staged --exit-code") to detect any staged
modifications, additions, or deletions so the workflow will correctly trigger
when yarn build produces new/removed files in dist/.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: cd584f80-54ce-4bab-86d6-b918e8436e2b
📒 Files selected for processing (1)
.github/workflows/rebuild-dist.yml
| - uses: actions/setup-node@v6 | ||
| with: | ||
| node-version: 20.x | ||
|
|
||
| - name: Install yarn | ||
| run: npm install -g yarn | ||
|
|
||
| - name: Install dependencies | ||
| run: yarn --frozen-lockfile |
There was a problem hiding this comment.
🧹 Nitpick | 🔵 Trivial
Consider caching node_modules to improve workflow performance.
Adding a cache step would speed up dependency installation on subsequent runs.
⚡ Add dependency caching
- uses: actions/setup-node@v6
with:
node-version: 20.x
+ cache: 'yarn'
- name: Install yarn
run: npm install -g yarnAlternatively, use a dedicated cache action for more control:
- uses: actions/cache@v4
with:
path: node_modules
key: ${{ runner.os }}-yarn-${{ hashFiles('**/yarn.lock') }}
restore-keys: |
${{ runner.os }}-yarn-🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/rebuild-dist.yml around lines 22 - 30, The workflow
currently always reinstalls dependencies ("Install dependencies" running "yarn
--frozen-lockfile") which slows CI; add a cache step using actions/cache (e.g.,
actions/cache@v4) before the "Install dependencies" step to cache node_modules
keyed by the yarn.lock hash and restore it when available; specifically, insert
a step referencing actions/cache@v4 (or use setup-node's cache option) keyed on
yarn.lock and with path node_modules so the "Install dependencies" step and the
"Install yarn" step benefit from restored dependencies on subsequent runs.
| - name: Install yarn | ||
| run: npm install -g yarn |
There was a problem hiding this comment.
🧹 Nitpick | 🔵 Trivial
Consider pinning the Yarn version for reproducibility.
Installing the latest Yarn version with npm install -g yarn could lead to inconsistent behavior if Yarn releases breaking changes.
♻️ Pin Yarn version or use Corepack
Option 1: Pin Yarn version
- - name: Install yarn
- run: npm install -g yarn
+ - name: Install yarn
+ run: npm install -g yarn@1.22.19Option 2: Use Corepack (recommended for Node.js 16.10+)
- - name: Install yarn
- run: npm install -g yarn
+ - name: Enable Corepack
+ run: corepack enableThen add a packageManager field to package.json to specify the exact Yarn version.
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - name: Install yarn | |
| run: npm install -g yarn | |
| - name: Install yarn | |
| run: npm install -g yarn@1.22.19 |
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/rebuild-dist.yml around lines 26 - 27, The "Install yarn"
workflow step uses npm install -g yarn which installs the latest Yarn and can
cause nondeterministic builds; update the "Install yarn" step to either pin a
specific Yarn version (e.g., npm install -g yarn@<version>) or replace the step
with Corepack enable/prepare commands and add a packageManager field in
package.json to lock the Yarn version; modify the workflow step titled "Install
yarn" (and package.json packageManager) accordingly to ensure reproducible
installs.
- Add concurrency group to prevent race conditions from parallel pushes - Use git diff --staged to detect new/modified/deleted files in dist/ Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
♻️ Duplicate comments (1)
.github/workflows/rebuild-dist.yml (1)
30-34: 🧹 Nitpick | 🔵 TrivialPin Yarn (or use Corepack) to avoid nondeterministic builds.
Line 31 installs the latest Yarn globally, which can silently change behavior across runs (including lockfile/install flags used on Line 34). Please lock the Yarn version for reproducibility.
♻️ Suggested change
- - name: Install yarn - run: npm install -g yarn + - name: Enable Corepack and pin Yarn + run: | + corepack enable + corepack prepare yarn@1.22.22 --activateDoes Yarn 4 still support `--frozen-lockfile`, and what is the recommended equivalent? Also confirm best practices for pinning Yarn in GitHub Actions using Corepack.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/rebuild-dist.yml around lines 30 - 34, The workflow currently installs the latest Yarn in the "Install yarn" step and then runs "yarn --frozen-lockfile" in the "Install dependencies" step, which can lead to nondeterministic builds; change the "Install yarn" step to pin a specific Yarn release (or enable Corepack and prepare a specific yarn@<version>) so the runner always uses the same major/minor, and update the "Install dependencies" step to use the lockfile flag that matches that pinned Yarn (replace the legacy --frozen-lockfile with the recommended equivalent for the pinned major, e.g., Yarn v2+/v3+ uses the immutable install flag). Also add a short comment or check that documents the chosen Yarn major so future maintainers know why the specific version/flag was selected.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Duplicate comments:
In @.github/workflows/rebuild-dist.yml:
- Around line 30-34: The workflow currently installs the latest Yarn in the
"Install yarn" step and then runs "yarn --frozen-lockfile" in the "Install
dependencies" step, which can lead to nondeterministic builds; change the
"Install yarn" step to pin a specific Yarn release (or enable Corepack and
prepare a specific yarn@<version>) so the runner always uses the same
major/minor, and update the "Install dependencies" step to use the lockfile flag
that matches that pinned Yarn (replace the legacy --frozen-lockfile with the
recommended equivalent for the pinned major, e.g., Yarn v2+/v3+ uses the
immutable install flag). Also add a short comment or check that documents the
chosen Yarn major so future maintainers know why the specific version/flag was
selected.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 1efb9405-b093-4aa1-8a70-7998f1d202b8
📒 Files selected for processing (1)
.github/workflows/rebuild-dist.yml
csasarak
left a comment
There was a problem hiding this comment.
Looks pretty good, please address the one comment I left about failure. Additionally, is this something we should do on merge? Or is push the best choice?
The workflow still rebuilds and pushes the fix, but now fails so it can block auto-merge as a required status check. The subsequent push triggers a new run that passes. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The paths filter prevented the workflow from running on PRs that don't touch source/dependency files, which blocks merging when this is a required status check. Instead, always trigger but skip the build early if no relevant files changed. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Combine install, build, and verify steps into a single script step so only two steps need the if condition instead of five. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
♻️ Duplicate comments (2)
.github/workflows/rebuild-dist.yml (2)
32-35: 🧹 Nitpick | 🔵 TrivialConsider adding
cache: 'yarn'to speed up dependency installation.The
actions/setup-nodeaction supports built-in caching. Addingcache: 'yarn'would improve workflow performance on subsequent runs.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/rebuild-dist.yml around lines 32 - 35, Add the built-in yarn cache to the GitHub Actions node setup step: update the actions/setup-node@v6 invocation (the step using node-version: 20.x) to include with: cache: 'yarn' so the runner will cache Yarn dependencies between runs and speed up installs.
37-39: 🧹 Nitpick | 🔵 TrivialConsider pinning the Yarn version for reproducibility.
Installing yarn without a version specifier (
npm install -g yarn) could lead to inconsistent behavior if Yarn releases breaking changes.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/rebuild-dist.yml around lines 37 - 39, The "Install yarn" step currently runs "npm install -g yarn" which installs whatever Yarn version is latest; change this to pin a specific Yarn version (e.g., yarn@1.22.19 or yarn@3.x) to ensure reproducible builds by replacing the command with a versioned install (or enable Corepack with a pinned Yarn version); update the step's run command and note the chosen version in the step name to make the pin obvious when scanning the workflow.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Duplicate comments:
In @.github/workflows/rebuild-dist.yml:
- Around line 32-35: Add the built-in yarn cache to the GitHub Actions node
setup step: update the actions/setup-node@v6 invocation (the step using
node-version: 20.x) to include with: cache: 'yarn' so the runner will cache Yarn
dependencies between runs and speed up installs.
- Around line 37-39: The "Install yarn" step currently runs "npm install -g
yarn" which installs whatever Yarn version is latest; change this to pin a
specific Yarn version (e.g., yarn@1.22.19 or yarn@3.x) to ensure reproducible
builds by replacing the command with a versioned install (or enable Corepack
with a pinned Yarn version); update the step's run command and note the chosen
version in the step name to make the pin obvious when scanning the workflow.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 4045bd82-c8d3-455c-ab95-40ab6988e3a0
📒 Files selected for processing (1)
.github/workflows/rebuild-dist.yml
Overview
Dependabot PRs update
package.jsonandyarn.lockbut don't rebuilddist/index.js, which is the bundled file the action actually runs. This means dependency updates from Dependabot don't actually take effect until someone manually runsyarn buildand commits the result.This adds a new workflow that automatically rebuilds and commits
dist/when source or dependency files change on PR branches.Triggers on changes to:
package.json,yarn.lock,src/**,tsconfig.jsonSkips: pushes to
main, dist-only changes (no infinite loop)NOTE: The
fossa scanfailure is a real vuln issue that is fixed in #275Checklist
yarn buildand committed resulting changes..github/workflows/test.ymlor explained why it doesn't make sense to do so.Important
After merging, make sure to create a new GitHub release and associated tag for this release.
You can either create the tag locally and then create a corresponding GitHub release,
or just create both the tag and release using the GitHub Release UI.
Additionally, if this is not a breaking change, make sure to update the
v1tag: