Skip to content

fix(ci): make edgeone artifact guard read-only - #76

Merged
PIKACHUIM merged 1 commit into
OpenListTeam:mainfrom
wumingzhinu:fix/artifact-guard
Sep 27, 2026
Merged

PIKACHUIM merged 1 commit into
OpenListTeam:mainfrom
wumingzhinu:fix/artifact-guard

Conversation

@wumingzhinu

Copy link
Copy Markdown
Contributor

Summary / 摘要

  • 将 EdgeOne Artifact Guard 改为只读校验,不再由 CI 自动 commit 或 push 受保护分支。

  • 使用 pnpm install --frozen-lockfile,确保 CI 使用锁文件安装依赖。

  • 同时检测已跟踪和未跟踪的 cloud-functions 产物;产物过期时明确失败并上传刷新后的产物。

  • 增加工作流契约回归测试,防止恢复自动 push 或非冻结安装。

  • This PR has breaking changes.
    / 此 PR 包含破坏性变更。

  • This PR changes public API, config, storage format, or migration behavior.
    / 此 PR 修改了公开 API、配置、存储格式或迁移行为。

  • This PR requires corresponding changes in related repositories.
    / 此 PR 需要关联仓库同步修改。

Related repository PRs / 关联仓库 PR:

  • OpenList: none
  • OpenList-Docs: none

Testing / 测试

  • node node_modules/tsx/dist/cli.mjs --test tests/artifact-guard.test.ts — 2/2 passed
  • YAML parse check for .github/workflows/edgeone-artifact-guard.yml
  • prettier --check for the changed workflow and test files
  • test:189 equivalent — 20/20 passed
  • test:drivers equivalent — 111/111 passed
  • test:store equivalent — 12/12 passed
  • test:model equivalent — 39/39 passed
  • Full typecheck — blocked by 2 pre-existing db_cipher.test.ts type errors
  • Full server suite — 124/129 passed; 5 pre-existing failures in default_credentials, healthz, and seed
  • Local full frontend build — blocked in Termux because the fetched frontend's pnpm launcher uses an unavailable /usr/bin/env; CI uses its normal Linux runner

Checklist / 检查清单

  • I have read CONTRIBUTING.
    / 我已阅读 CONTRIBUTING。
  • I confirm this contribution follows the repository license, contribution policy, and code of conduct.
    / 我确认本次贡献符合仓库许可证、贡献规范和行为准则。
  • I have formatted the changed code with Prettier where applicable.
    / 我已按适用情况使用 Prettier 格式化变更代码。
  • I have requested review from relevant maintainers or code owners where applicable.
    / 我已在适用情况下请求相关维护者或代码所有者审查。

AI Disclosure / AI 使用声明

  • This PR includes AI-assisted content.
    / 此 PR 包含 AI 辅助内容。

Tools used / 使用工具:

  • ChatGPT
  • Codex
  • GitHub Copilot
  • Claude
  • Gemini
  • Other: OpenCode

Usage scope / 使用范围:

  • Code generation / 代码生成

  • Refactoring / 重构

  • Documentation / 文档

  • Tests / 测试

  • Translation / 翻译

  • Review assistance / 审查辅助

  • I have reviewed and validated all AI-assisted content included in this PR.
    / 我已审核并验证此 PR 中的所有 AI 辅助内容。

  • I have ensured that all AI-assisted commits include Co-Authored-By attribution.
    / 我已确保所有 AI 辅助提交都包含 Co-Authored-By 归属信息。

  • I can reproduce all AI-assisted content included in this PR without any AI tools.
    / 我可以在没有任何 AI 工具的情况下重现此 PR 中包含的所有 AI 辅助内容。

@pikachuren

Copy link
Copy Markdown
Collaborator

评审结论:可以合并(需维护者确认一处策略变更)

核对通过:

  • pnpm-lock.yaml 存在(packageManager: pnpm@9.15.4),所以 --frozen-lockfile 可行;
    建议确认新工作流能跑绿再合(frozen lockfile 对锁文件与 package.json 的一致性很敏感)。
  • 报错文案里的 pnpm run build 与 CI 步骤一致(package.json 的
    build = node scripts/fetch-frontend.mjs && node scripts/build-edge.mjs,正是 workflow 的那两步),文案准确。
  • git status --porcelain 能同时反映已跟踪修改与未跟踪产出,检测逻辑正确;
    exit 1 之前 changed=true 已写入 GITHUB_OUTPUT,后续 if: always() 的 Job summary 仍能取到。
  • contents: write → read,并删除了 bot 自动提交与 git push,方向正确。

需要维护者拍板的一点

这改变了团队流程:以前 push 到 main 时产物过期会被 bot 自动提交,现在会直接把 main 变红。
方向(不往受保护分支推 bot 提交)是好的,但请确认团队接受「每次后端改动合入后需手动重建产物」,
否则 main 会长期处于红状态。

补充(在 #89 中发现的关联问题):如果 fetch-frontend.mjs 引入「发布版前端缺初始化协议时静默回退到构建 main」,
本守卫的产物会变成不可复现(见 #89 评审)。两个 PR 都涉及产物可复现性,建议一起考虑。


本评论由 AI 辅助的自动化评审生成,基于对该 PR 当前 head 提交的源码核对。标注「实测复现」的结论已在本地用真实源码(打补丁后)跑脚本验证;其余为代码走查结论。请以人工复核为准。

@PIKACHUIM
PIKACHUIM merged commit 0a36d0d into OpenListTeam:main Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants