Repository navigation
Add CI drift check for vendored Tiny Wire tokens - #7
Merged
Merged
Conversation
Runs scripts/check-tinywire-drift.sh on every push and PR: checks out tiny-wire at the tag matching src/lib/.tinywire-version and verifies the pin and vendored files match the pinned release byte for byte.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
.github/workflows/tinywire-drift.yml, which runsscripts/check-tinywire-drift.shon every push and pull request so vendored-token drift is caught in CI instead of only by hand.How it works:
src/lib/.tinywire-version(where the script actually looks — this consumer vendors intosrc/lib/, and the pin sits next totokens.css).LinzLos/tiny-wireat the tag matching the pin (v<pin>; upstream tags releases asvX.Y— currentlyv1.6, matching the pin). A pin naming a version with no tag fails the checkout step, which is itself a drift signal. Tiny-wire is public, so no extra token is needed.TW_REPO_DIR="$GITHUB_WORKSPACE/tiny-wire", since Actions can't place the source as a true sibling of the workspace.Validated locally: cloning tiny-wire at
v1.6and running the script reportsOK — vendored Tiny Wire tokens are in sync (v1.6). No vendored files or the pin were modified.Note the tradeoff of pinning the checkout to the tag: CI verifies byte-for-byte integrity against the pinned release, but a new upstream release won't fail this check until the pin is bumped. Switching the
reftomainwould flip that: red on every upstream release until re-sync.🤖 Generated with Claude Code
https://claude.ai/code/session_011wancyyu9ynb6atCpn7qt9
Generated by Claude Code