diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml index 07e3833..39d41f3 100644 --- a/.github/workflows/pr.yml +++ b/.github/workflows/pr.yml @@ -15,6 +15,11 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v5 + with: + # These jobs run code from the pull request (install scripts, + # tests, the packaged CLI) and never push, so the checkout must + # not leave the job token readable in .git/config. + persist-credentials: false - uses: actions/setup-node@v6 with: node-version-file: '.nvmrc' @@ -32,12 +37,19 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v5 + with: + # These jobs run code from the pull request (install scripts, + # tests, the packaged CLI) and never push, so the checkout must + # not leave the job token readable in .git/config. + persist-credentials: false - uses: actions/setup-node@v6 with: node-version-file: '.nvmrc' cache: 'npm' - name: Install dependencies run: npm ci + - name: Run tests + run: npm test - name: Build project run: npm run build - name: Create package diff --git a/vitest.config.ts b/vitest.config.ts index 3f824fb..7cc6609 100644 --- a/vitest.config.ts +++ b/vitest.config.ts @@ -4,5 +4,10 @@ export default defineConfig({ test: { globals: true, environment: "node", + // Only the sources. `tsc` copies the specs into `dist/`, and stale builds + // and git worktrees leave more copies around, so an unscoped run collects + // the same test several times over — and fails on copies whose source is + // long gone. + include: ["src/**/*.spec.{ts,tsx}"], }, });