From 7d8d1a9da24c74a7a59f9d857d219ba50d650414 Mon Sep 17 00:00:00 2001 From: YeonGyu-Kim Date: Fri, 9 Oct 2026 17:00:19 +0900 Subject: [PATCH 1/2] build: peer @earendil-works/pi-* >=0.87.1 (verified floor) instead of * --- CHANGELOG.md | 2 ++ bun.lock | 8 ++++---- package-lock.json | 8 ++++---- package.json | 8 ++++---- 4 files changed, 14 insertions(+), 12 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3f97f0c..0e287f7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ ### Changed +- Peer dependencies on `@earendil-works/pi-*` are `>=0.87.1` instead of `*`. 0.87.1 is the oldest pi the extension is verified against: typecheck and the full test suite pass with every `@earendil-works` package at 0.87.1. +- CI: the Dependabot `bun.lock` refresh approves the CI run its own push starts, so the required checks attach to the pull request, and falls back to dispatching `ci.yml` if that run cannot be approved. - CI: the publish workflow no longer has an npm publish step; the package is distributed via git. A release now fails when its tag does not match `package.json`. ## [0.1.4] - 2026-10-03 diff --git a/bun.lock b/bun.lock index b1a93ac..adc507f 100644 --- a/bun.lock +++ b/bun.lock @@ -20,10 +20,10 @@ "vitest": "5.0.3", }, "peerDependencies": { - "@earendil-works/pi-agent-core": "*", - "@earendil-works/pi-ai": "*", - "@earendil-works/pi-coding-agent": "*", - "@earendil-works/pi-tui": "*", + "@earendil-works/pi-agent-core": ">=0.87.1", + "@earendil-works/pi-ai": ">=0.87.1", + "@earendil-works/pi-coding-agent": ">=0.87.1", + "@earendil-works/pi-tui": ">=0.87.1", }, }, }, diff --git a/package-lock.json b/package-lock.json index ff372f3..7571e47 100644 --- a/package-lock.json +++ b/package-lock.json @@ -27,10 +27,10 @@ "node": ">=22.19.0" }, "peerDependencies": { - "@earendil-works/pi-agent-core": "*", - "@earendil-works/pi-ai": "*", - "@earendil-works/pi-coding-agent": "*", - "@earendil-works/pi-tui": "*" + "@earendil-works/pi-agent-core": ">=0.87.1", + "@earendil-works/pi-ai": ">=0.87.1", + "@earendil-works/pi-coding-agent": ">=0.87.1", + "@earendil-works/pi-tui": ">=0.87.1" } }, "node_modules/@anthropic-ai/sdk": { diff --git a/package.json b/package.json index 8762ceb..861d9d4 100644 --- a/package.json +++ b/package.json @@ -43,10 +43,10 @@ "check": "tsgo --noEmit && biome check ." }, "peerDependencies": { - "@earendil-works/pi-agent-core": "*", - "@earendil-works/pi-ai": "*", - "@earendil-works/pi-coding-agent": "*", - "@earendil-works/pi-tui": "*" + "@earendil-works/pi-agent-core": ">=0.87.1", + "@earendil-works/pi-ai": ">=0.87.1", + "@earendil-works/pi-coding-agent": ">=0.87.1", + "@earendil-works/pi-tui": ">=0.87.1" }, "devDependencies": { "@biomejs/biome": "2.5.15", From 9ba5a8804ab1c657afeafa4c19a7bc7b85ef2f90 Mon Sep 17 00:00:00 2001 From: YeonGyu-Kim Date: Fri, 9 Oct 2026 17:00:19 +0900 Subject: [PATCH 2/2] ci: approve the bot commit pull_request run so required checks attach to the PR --- .github/workflows/dependabot-bun-lock.yml | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/.github/workflows/dependabot-bun-lock.yml b/.github/workflows/dependabot-bun-lock.yml index bb13ea7..d85cb08 100644 --- a/.github/workflows/dependabot-bun-lock.yml +++ b/.github/workflows/dependabot-bun-lock.yml @@ -2,7 +2,8 @@ name: dependabot bun.lock # Dependabot's npm updater rewrites package.json and package-lock.json but never bun.lock, so `bun install # --frozen-lockfile` in ci.yml fails on every npm bump before a test runs. This refreshes bun.lock on Dependabot's -# branches and re-runs CI on the new commit (a commit pushed with GITHUB_TOKEN starts no workflow by itself). +# branches. The commit's own pull_request CI run is held for approval (github-actions[bot] counts as a first-time +# contributor), so the job approves it, or dispatches ci.yml if it cannot. on: push: @@ -35,7 +36,7 @@ jobs: with: bun-version: 1.4.2 - # Pinned by SHA and run without dependency lifecycle scripts: this job holds a write token. + # No dependency lifecycle scripts: this job holds a write token. - name: Refresh bun.lock run: bun install --ignore-scripts @@ -57,4 +58,19 @@ jobs: git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git commit -m "build(deps): refresh bun.lock" -- bun.lock git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "HEAD:refs/heads/${BRANCH}" - gh workflow run ci.yml --ref "$BRANCH" + # The push creates this commit's pull_request CI run, held for approval because github-actions[bot] counts as a + # first-time contributor. Approving it attaches the required checks to the PR; if it cannot be found or approved, + # a dispatched run still checks the commit, though its checks do not show on the PR. + sha=$(git rev-parse HEAD) + run_id="" + for attempt in $(seq 1 12); do + run_id=$(gh run list --workflow ci.yml --commit "$sha" --event pull_request --json databaseId --jq '.[0].databaseId // empty' || true) + [ -n "$run_id" ] && break + [ "$attempt" -lt 12 ] && sleep 5 + done + if [ -n "$run_id" ] && gh api --method POST "repos/${GITHUB_REPOSITORY}/actions/runs/${run_id}/approve"; then + echo "approved pull_request run ${run_id}" + else + echo "::warning::could not approve the pull_request run (id: ${run_id:-none}); dispatching ci.yml instead" + gh workflow run ci.yml --ref "$BRANCH" + fi