Skip to content

docs: sync README "Send feedback" description with in-app dialog #266

docs: sync README "Send feedback" description with in-app dialog

docs: sync README "Send feedback" description with in-app dialog #266

Workflow file for this run

name: Tests
on:
push:
branches: [main, master]
pull_request:
workflow_dispatch:
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Install dependencies
run: npm ci
- name: Lint
run: npm run lint
- name: Check formatting
run: npm run format:check
- name: Typecheck
run: npm run typecheck
# Module-graph layering — fails CI if anything in tools/_core/
# imports from tools/_shell/ or a tool folder, if tools/_shell/
# imports from a tool folder or tools/_app/, or if a tool folder
# imports from tools/_app/. The four-tier rule from
# docs/architecture.md §3 is enforced mechanically by
# dependency-cruiser (.dependency-cruiser.cjs) rather than by
# convention.
- name: Module layering
run: npm run lint:boundaries
# Vendored React / ReactDOM are SRI-pinned in every tools/*.html via
# scripts/vendor-sri.js (security audit 02-05-2026, Tier B #4). This
# step fails CI if a vendor/* update landed without re-running the
# script — the alternative would be a silent supply-chain regression
# where a backdoored React ships and the integrity attribute goes
# stale, which the browser would then refuse to execute.
- name: Verify vendor SRI hashes
run: npm run lint:sri
# Anti-clickjack snippet sync step retired in v1.3.0 alongside
# the iframe → SPA migration: there is only one HTML file
# (index.html) so there is nothing to sync and the inline
# frame-buster is the canonical source by construction.
- name: Run tests
run: npm test
# Fast-check property tests run inside `npm test` (each tool has its
# own `tests/<tool>.property.test.js`). The prior bespoke fuzz
# harnesses + the weekly fuzz-release.yml sweep were retired in
# 2026-05-07: per-PR coverage is now ~25 k generated cases across
# the eight tools, with shrinking on failure.
- name: Verify build
run: npm run build
# The compiled tools/*.js outputs are checked into git so GitHub Pages
# can serve them statically. This step catches the case where someone
# edited a tools/*.tsx source but forgot to run `npm run build`, which
# would otherwise ship stale compiled JS to production.
#
# tools/version.js is excluded because it is generated from `git describe`
# rather than from TSX source — CI's shallow checkout has no tags and so
# would always regenerate it as "dev", producing a spurious drift.
- name: Verify compiled tsx sources are in sync
run: git diff --exit-code -- tools/ ':(exclude)tools/version.js'
# Playwright e2e — golden-path flows in real Chromium. Catches the
# "renders the wrong chart" class of bug the vm + functional-React-
# mock unit tests can't see (the volcano colorNs glitch in v1.2.0
# was the motivating example). The Python http.server is started
# automatically by playwright.config.ts; --with-deps installs the
# system libs Chromium needs on ubuntu-latest.
- name: Install Playwright Chromium
run: npx playwright install --with-deps chromium
- name: Run Playwright e2e
run: npx playwright test --reporter=github
- name: Upload Playwright report on failure
if: failure()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: |
playwright-report/
test-results/
retention-days: 7