docs: sync README "Send feedback" description with in-app dialog #266
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Tests | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| workflow_dispatch: | |
| env: | |
| FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Lint | |
| run: npm run lint | |
| - name: Check formatting | |
| run: npm run format:check | |
| - name: Typecheck | |
| run: npm run typecheck | |
| # Module-graph layering — fails CI if anything in tools/_core/ | |
| # imports from tools/_shell/ or a tool folder, if tools/_shell/ | |
| # imports from a tool folder or tools/_app/, or if a tool folder | |
| # imports from tools/_app/. The four-tier rule from | |
| # docs/architecture.md §3 is enforced mechanically by | |
| # dependency-cruiser (.dependency-cruiser.cjs) rather than by | |
| # convention. | |
| - name: Module layering | |
| run: npm run lint:boundaries | |
| # Vendored React / ReactDOM are SRI-pinned in every tools/*.html via | |
| # scripts/vendor-sri.js (security audit 02-05-2026, Tier B #4). This | |
| # step fails CI if a vendor/* update landed without re-running the | |
| # script — the alternative would be a silent supply-chain regression | |
| # where a backdoored React ships and the integrity attribute goes | |
| # stale, which the browser would then refuse to execute. | |
| - name: Verify vendor SRI hashes | |
| run: npm run lint:sri | |
| # Anti-clickjack snippet sync step retired in v1.3.0 alongside | |
| # the iframe → SPA migration: there is only one HTML file | |
| # (index.html) so there is nothing to sync and the inline | |
| # frame-buster is the canonical source by construction. | |
| - name: Run tests | |
| run: npm test | |
| # Fast-check property tests run inside `npm test` (each tool has its | |
| # own `tests/<tool>.property.test.js`). The prior bespoke fuzz | |
| # harnesses + the weekly fuzz-release.yml sweep were retired in | |
| # 2026-05-07: per-PR coverage is now ~25 k generated cases across | |
| # the eight tools, with shrinking on failure. | |
| - name: Verify build | |
| run: npm run build | |
| # The compiled tools/*.js outputs are checked into git so GitHub Pages | |
| # can serve them statically. This step catches the case where someone | |
| # edited a tools/*.tsx source but forgot to run `npm run build`, which | |
| # would otherwise ship stale compiled JS to production. | |
| # | |
| # tools/version.js is excluded because it is generated from `git describe` | |
| # rather than from TSX source — CI's shallow checkout has no tags and so | |
| # would always regenerate it as "dev", producing a spurious drift. | |
| - name: Verify compiled tsx sources are in sync | |
| run: git diff --exit-code -- tools/ ':(exclude)tools/version.js' | |
| # Playwright e2e — golden-path flows in real Chromium. Catches the | |
| # "renders the wrong chart" class of bug the vm + functional-React- | |
| # mock unit tests can't see (the volcano colorNs glitch in v1.2.0 | |
| # was the motivating example). The Python http.server is started | |
| # automatically by playwright.config.ts; --with-deps installs the | |
| # system libs Chromium needs on ubuntu-latest. | |
| - name: Install Playwright Chromium | |
| run: npx playwright install --with-deps chromium | |
| - name: Run Playwright e2e | |
| run: npx playwright test --reporter=github | |
| - name: Upload Playwright report on failure | |
| if: failure() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: playwright-report | |
| path: | | |
| playwright-report/ | |
| test-results/ | |
| retention-days: 7 |