Scope CI and deployment to affected files - #42
Merged
Merged
Conversation
Scope workflow events by the inputs they validate and separate AUR, web/docs and automation contracts. Refine shared lockfile changes using reachable pnpm dependency projections so website-only dependencies do not start native jobs. Keep the existing native commands, manual/release entrypoints and production serialization, while moving packaging README checks into docs validation. Selective workflow success is no longer sufficient release evidence: require the executed workspace job and check step, with an explicit full-CI override when a release ref was filtered. Preserve successful legacy CI evidence. Constraint: Shared pnpm lockfiles require dependency-aware decisions; unknown data runs validation conservatively Rejected: Ignore lockfile changes | would miss application and transitive dependency regressions Confidence: high Scope-risk: moderate Directive: Keep workflow path policies aligned with actual inputs and preserve release job/step evidence checks Directive: Do not globally require path-filtered status checks without an always-reporting aggregate Tested: 38 Git/lockfile scenarios, 80 workflow path/event cases and 10 release-audit job/step modes Tested: Actual PR40 replay skips native and AUR work; real legacy CI job metadata passes the new audit guard Tested: Actionlint 1.7.12, workflow/requirements/docs/script gates, GitHub setup fixtures, lint/typecheck, 295 tests and web builds Not-tested: Unchanged native/AUR builds were not rerun locally; hosted workflow execution awaits the PR Related: #41
Record workflow ownership, dependency-aware selection, actual PR40 replay, release-evidence protection and the intentional limits of path-based checks. Confidence: high Scope-risk: narrow Tested: Recorded outcomes checked against routing tests, actionlint and script validation results Related: #41
This was referenced Sep 5, 2026
The recorded native snapshot was rejected after the homepage added GSAP to the shared lockfile, even though application dependency inputs were unchanged. Reuse the existing application projection for lockfile freshness and retain the snapshot, ancestry and other critical input checks. The explicit proof mode rejects uncertain comparisons instead of using CI's run-more fallback. Constraint: Preserve the original four-target VM evidence and tested commit Rejected: Ignore lockfile changes | native and shared dependencies must still invalidate proof Confidence: high Scope-risk: narrow Directive: Strict lockfile verification must reject uncertainty and never write workflow outputs Tested: Original snapshot failure reproduced, then all four recorded targets verified Tested: 27 proof regressions, 38 impact cases, 84 workflow path/event cases Tested: Packaging smoke including native fixture builds, Node/Ruby syntax, actionlint, whitespace Not-tested: Full workspace and hosted validation still running at commit time
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The main CI workflow currently runs native workspace checks and both Arch source-package builds on every PR. This change scopes validation to affected inputs and gives web/docs and workflow contracts their own lightweight workflows.
run=false, AURrun=false, webrun=true.Closes #41.
Scope
CI/platform automation and developer documentation. Existing native/AUR execution steps and the full local
pnpm checkcommand are preserved. Three packaging README prose assertions move into docs validation. No new actions or project dependencies; the helper uses Ruby/YAML already required by workflow verification. Branch protection and rulesets are unchanged.Validation
pnpm verify:workflows: 38 Git/lockfile integration scenarios, 84 workflow path/event cases, 27 native-proof/strict-mode regressions, and job/deployment wiring checks passed.pnpm verify:scripts: all existing automation fixtures plus 10 release-audit evidence modes passed. Scope-only success was reproduced as a failure before the audit fix.pnpm verify:packagingnow passes, including native fixture builds and the original four-target snapshot. Strict comparison tests reject changed/unknown inputs and verify no workflow-output writes.Boundaries
This PR changes native/AUR workflow definitions, so those checks are expected for this PR. Native fixture packaging checks passed locally. The full local
pnpm checkpassed, including all 295 workspace tests, native/Rust gates, packaging, types and production builds. The fresh hosted CI run passed on76b224d, including theValidate workspacejob and itsRun workspace checksstep. No new four-VM proof execution or AUR build was performed locally. Manual, scheduled and release-tag entrypoints remain deliberate overrides. GitHub path-diff limits still apply; path-filtered checks should not be made universally required without an appropriate always-reporting aggregate. No deployment or release was performed.Detailed file inventory and evidence.