From 772f27d055654c3dca4ae89a5a2b104da9f1e924 Mon Sep 17 00:00:00 2001 From: Jarek Potiuk Date: Fri, 24 Apr 2026 16:10:42 +0200 Subject: [PATCH] ci: verify committed dist/ matches a clean rebuild Apache Infrastructure's verify-action-build tool (used to auto-review Dependabot bumps of this action) flagged a drift in v0.0.10: the committed dist/ matches only when rebuilt against the v0.0.9 lockfile, not the v0.0.10 lockfile shipped alongside it. In practice this means the release commit bumped package.json/package-lock.json version strings but the dist/ was built earlier with the previous toolchain. This is one of several ways to address that class of problem. The other path is to simply rebuild dist/ and recommit for the current release; that leaves the door open for it to happen again on the next release. Adding this CI job is the preventive fix: it runs 'npm ci && npm run build' on Node 24 (matching action.yml 'using: node24') and fails if the committed dist/ differs from the rebuilt output. A release with a stale dist/ will then be caught in CI rather than by downstream consumers. The existing build job keeps Node 18.x for format/lint/test; the new job pins 24.x so the rebuild matches what the action actually runs on. --- .github/workflows/CI.yml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/.github/workflows/CI.yml b/.github/workflows/CI.yml index aa53139..fb345a7 100644 --- a/.github/workflows/CI.yml +++ b/.github/workflows/CI.yml @@ -37,6 +37,30 @@ jobs: - name: Build & Test run: npm run test + verify-dist: + name: Verify dist/ is up to date + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v6 + - name: Setup Node.js + uses: actions/setup-node@v6 + with: + node-version: 24.x + cache: npm + + - name: npm ci + run: npm ci + - name: Rebuild dist/ + run: npm run build + - name: Check dist/ matches committed output + run: | + if ! git diff --exit-code -- dist/; then + echo "::error::Committed dist/ does not match a clean rebuild from source." + echo "::error::Run 'npm ci && npm run build' locally and commit the updated dist/ before releasing." + exit 1 + fi + test: name: Test version runs-on: ${{ matrix.os }}