Repository navigation
Document vendor --force as variant-probe bypass (#923) #1860
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: npm hosted/vendored compatibility | |
| # Real npm releases (at least one per major, 6 through 12) through the | |
| # hermetic hosted (`e2e_redirect_npm_build`) and vendored | |
| # (`e2e_vendor_npm_build`) capstones, each flow ending in the manifest-less | |
| # VEX checks. Builds the CLI and both test binaries once; every matrix leg | |
| # installs one pinned npm and runs them. See docs/testing/npm-compatibility.md. | |
| on: | |
| # PRs: any crate source, but only the test files these capstones | |
| # compile (a later `!` pattern excludes, a later plain one re-includes). | |
| # Main pushes use the wider push filter below, plus a nightly full run. | |
| pull_request: | |
| types: [opened, synchronize, reopened, ready_for_review] | |
| # Only this ecosystem's own files. A change to shared engine code | |
| # (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on | |
| # push to main (when it is in the push filter below) or nightly, or on | |
| # demand via workflow_dispatch on the PR branch; | |
| # ci.yml's per-ecosystem blocking slice still runs on every PR and in | |
| # the merge queue (#1198). | |
| paths: | |
| - '.github/actions/upload-artifact/**' | |
| - '.github/workflows/npm-compatibility.yml' | |
| - 'docs/testing/npm-compatibility.md' | |
| - 'crates/*/src/**/*npm*' | |
| - 'crates/*/src/**/*npm*/**' | |
| - 'crates/socket-patch-core/src/package_json/**' | |
| - '!crates/*/src/**/*pnpm*' | |
| - '!crates/*/src/**/*pnpm*/**' | |
| - '!crates/socket-patch-node/**' | |
| - 'crates/socket-patch-cli/tests/e2e_redirect_npm_build.rs' | |
| - 'crates/socket-patch-cli/tests/e2e_vendor_npm_build.rs' | |
| - 'crates/socket-patch-cli/tests/npm_e2e_common/**' | |
| push: | |
| branches: [main] | |
| # The ecosystem's pre-#1198 relevance set (the shared engine code its | |
| # cells run through), its PR paths and the toolchain files. A main | |
| # push outside this set waits for the nightly run below. | |
| paths: | |
| - '.github/actions/upload-artifact/**' | |
| - 'Cargo.lock' | |
| - 'Cargo.toml' | |
| - 'rust-toolchain.toml' | |
| - '.cargo/config.toml' | |
| - '.github/workflows/npm-compatibility.yml' | |
| - 'docs/testing/npm-compatibility.md' | |
| - 'crates/**' | |
| - '!crates/**/*.md' | |
| - '!crates/socket-patch-node/**' | |
| - '!crates/socket-patch-core/tests/**' | |
| - '!crates/socket-patch-cli/tests/**' | |
| - 'crates/socket-patch-cli/tests/vex_e2e_common/**' | |
| - 'crates/socket-patch-cli/tests/e2e_redirect_npm_build.rs' | |
| - 'crates/socket-patch-cli/tests/e2e_vendor_npm_build.rs' | |
| - 'crates/socket-patch-cli/tests/npm_e2e_common/**' | |
| - 'crates/socket-patch-cli/tests/common/cache_env.rs' | |
| - '.cargo/**' | |
| schedule: | |
| # Nightly full matrix, so a main change outside the push filter | |
| # still gets a run within a day. | |
| - cron: '17 4 * * *' | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| # A newer push to the same PR supersedes the older run. Every other event | |
| # gets its own group (run_id), so no main push is cancelled, even while | |
| # pending behind another. | |
| concurrency: | |
| group: npm-compat-${{ github.event.pull_request.number || github.run_id }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| build: | |
| if: github.event.pull_request.draft != true | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 25 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - name: Compile CLI and npm capstones once | |
| run: | | |
| cargo test --locked -p socket-patch-cli --test e2e_redirect_npm_build --test e2e_vendor_npm_build --no-run --message-format=json > target-build.json | |
| python3 - <<'PY' | |
| import json, pathlib, shutil | |
| dest = pathlib.Path('target/npm-e2e'); dest.mkdir(parents=True, exist_ok=True) | |
| shutil.copy2('target/debug/socket-patch', dest / 'socket-patch') | |
| for line in pathlib.Path('target-build.json').read_text().splitlines(): | |
| item = json.loads(line) | |
| name = item.get('target', {}).get('name') | |
| if name in ('e2e_redirect_npm_build', 'e2e_vendor_npm_build') and item.get('executable'): | |
| shutil.copy2(item['executable'], dest / name) | |
| assert all((dest / n).is_file() for n in ('e2e_redirect_npm_build', 'e2e_vendor_npm_build')) | |
| PY | |
| - uses: ./.github/actions/upload-artifact | |
| with: | |
| name: npm-e2e | |
| path: target/npm-e2e/ | |
| if-no-files-found: error | |
| retention-days: 7 | |
| install-proof: | |
| needs: build | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 25 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| # node 16's bundled npm 8 writes the v2 lock for the npm 6 x v2 test. | |
| - {npm: '6.14.18', node: '16.20.2'} | |
| - {npm: '7.0.0', node: '16.20.2'} | |
| - {npm: '7.24.2', node: '16.20.2'} | |
| - {npm: '8.19.4', node: '16.20.2'} | |
| - {npm: '9.0.0', node: '18.20.8'} | |
| - {npm: '9.9.4', node: '18.20.8'} | |
| - {npm: '10.9.9', node: '22.22.2'} | |
| - {npm: '11.20.0', node: '24.11.1'} | |
| - {npm: '12.0.0', node: '24.15.0'} | |
| - {npm: '12.1.0', node: '24.15.0'} | |
| steps: | |
| # Same workspace path as the build job, so the socket-patch path | |
| # compiled into the tests (CARGO_BIN_EXE_socket-patch) resolves. | |
| - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| pattern: npm-e2e* | |
| merge-multiple: true | |
| path: target/debug | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: '24.11.1' | |
| - name: Install the pinned npm | |
| env: | |
| NPM_TEST_VERSION: ${{ matrix.npm }} | |
| run: | | |
| npm install --prefix "$RUNNER_TEMP/npm-tool" --no-audit --no-fund "npm@$NPM_TEST_VERSION" | |
| echo "SOCKET_PATCH_NPM_E2E_BIN=$RUNNER_TEMP/npm-tool/node_modules/.bin/npm" >> "$GITHUB_ENV" | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: ${{ matrix.node }} | |
| - name: Hosted + vendored installs, manifest-less VEX | |
| env: | |
| SOCKET_PATCH_NPM_E2E_VERSION: ${{ matrix.npm }} | |
| SOCKET_PATCH_NPM_E2E_REQUIRED: '1' | |
| SOCKET_NO_CONFIG: '1' | |
| SOCKET_NO_UPDATE_CHECK: '1' | |
| SOCKET_TELEMETRY_DISABLED: '1' | |
| run: | | |
| chmod +x target/debug/socket-patch target/debug/e2e_redirect_npm_build target/debug/e2e_vendor_npm_build | |
| target/debug/e2e_redirect_npm_build --include-ignored --test-threads 4 | |
| target/debug/e2e_vendor_npm_build --include-ignored --test-threads 4 |