ci: sync bun baseline refresh - #8
adelphi-liong wants to merge 1 commit into
Conversation
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughTwo separate reusable CI workflows for unit and integration tests are replaced by a single parameterized ChangesCI and Coverage Consolidation
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Welcome to Codecov 🎉Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests. ℹ️ You can also turn on project coverage checks and project coverage reporting on Pull Request comment Thanks for integrating Codecov - We've got you covered ☂️ |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/⚡reusable-test.yaml:
- Around line 22-23: The reusable test workflow step interpolates inputs.mode
directly into the shell command, so validate and constrain mode before it
reaches the run invocation in the reusable workflow. Update the workflow around
the Run ${{ inputs.mode }} tests step to allow only the expected values (for
example, unit or int) and fail fast on anything else, instead of relying on
scripts/ci/test-${{ inputs.mode }}.sh to catch it later. Use the existing
inputs.mode reference in the workflow to add the guard before the nix develop
command is executed.
In @.github/workflows/ci.yaml:
- Around line 11-20: The reusable workflow calls in ci.yaml are using secrets:
inherit, which grants broader access than needed; update the workflow dispatch
for the unit and int jobs to pass only CODECOV_TOKEN into ⚡reusable-test.yaml.
Keep the existing uses and with mode settings, but replace inherited secrets
with an explicit secrets mapping so the reusable workflow only receives the
secret it declares and uses.
In `@package.json`:
- Line 18: The Knip hook setup is assuming a Node runtime that is not guaranteed
by the repo’s current shells, so pin a compatible runtime for Knip v6 or switch
the hook entrypoint. Update the hook configuration that invokes
./node_modules/.bin/knip to either run through knip-bun/bunx --bun or ensure the
CI/dev shells declare Node 20.19+ alongside Bun, and keep package.json aligned
with the chosen runtime.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 0176e866-5ab0-4078-95a2-e0171d6e25ef
⛔ Files ignored due to path filters (1)
bun.lockis excluded by!**/*.lock
📒 Files selected for processing (15)
.github/workflows/ci.yaml.github/workflows/⚡reusable-test-int.yaml.github/workflows/⚡reusable-test-unit.yaml.github/workflows/⚡reusable-test.yamlREADME.mdbiome.jsonbunfig.int.tomlcodecov.ymldocs/developer/bun-baseline.mdknip.jsonknip.llm.jsonknip.production.jsonknip.production.llm.jsonpackage.jsontasks/Taskfile.docker.yaml
💤 Files with no reviewable changes (2)
- .github/workflows/⚡reusable-test-unit.yaml
- .github/workflows/⚡reusable-test-int.yaml
| - name: Run ${{ inputs.mode }} tests | ||
| run: nix develop .#ci -c ./scripts/ci/test-${{ inputs.mode }}.sh |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Inspect every caller of the reusable workflow and the exact mode values passed.
rg -n -C2 'uses:\s*\./\.github/workflows/⚡reusable-test\.yaml|mode:' .github/workflowsRepository: AtomiCloud/diene.bun-cli
Length of output: 1181
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== reusable workflow ==\n'
cat -n .github/workflows/⚡reusable-test.yaml
printf '\n== test wrapper ==\n'
cat -n scripts/ci/test.shRepository: AtomiCloud/diene.bun-cli
Length of output: 2753
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== workflow callers ==\n'
rg -n -C3 'uses:\s*\./\.github/workflows/⚡reusable-test\.yaml|mode:' .github/workflowsRepository: AtomiCloud/diene.bun-cli
Length of output: 1439
🏁 Script executed:
#!/bin/bash
set -euo pipefail
python3 - <<'PY'
import subprocess, shlex
for mode in ["unit", "unit; echo INJECTED", 'unit $(echo INJECTED)']:
cmd = f"echo nix develop .#ci -c ./scripts/ci/test-{mode}.sh"
print(f"\nMODE={mode!r}")
print("COMMAND:", cmd)
out = subprocess.check_output(["bash", "-lc", cmd], text=True)
print("OUTPUT:", out.rstrip())
PYRepository: AtomiCloud/diene.bun-cli
Length of output: 922
Validate mode before interpolating it into the shell command. workflow_call accepts an unconstrained string here, and run: nix develop .#ci -c ./scripts/ci/test-${{ inputs.mode }}.sh turns a bad value into shell injection or an unintended script path. The wrapper script checks unit|int, but that happens too late.
🧰 Tools
🪛 zizmor (1.26.1)
[error] 23-23: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/⚡reusable-test.yaml around lines 22 - 23, The reusable
test workflow step interpolates inputs.mode directly into the shell command, so
validate and constrain mode before it reaches the run invocation in the reusable
workflow. Update the workflow around the Run ${{ inputs.mode }} tests step to
allow only the expected values (for example, unit or int) and fail fast on
anything else, instead of relying on scripts/ci/test-${{ inputs.mode }}.sh to
catch it later. Use the existing inputs.mode reference in the workflow to add
the guard before the nix develop command is executed.
Source: Linters/SAST tools
| uses: ./.github/workflows/⚡reusable-test.yaml | ||
| secrets: inherit | ||
| with: | ||
| mode: unit | ||
| int: | ||
| name: Integration Tests | ||
| uses: ./.github/workflows/⚡reusable-test-int.yaml | ||
| uses: ./.github/workflows/⚡reusable-test.yaml | ||
| secrets: inherit | ||
| with: | ||
| mode: int |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Confirm which secrets the callee declares and actually references.
sed -n '1,80p' .github/workflows/⚡reusable-test.yaml
printf '\n--- secret references ---\n'
rg -n 'CODECOV_TOKEN|secrets\.' .github/workflows/⚡reusable-test.yaml .github/workflows/ci.yamlRepository: AtomiCloud/diene.bun-cli
Length of output: 1638
Pass only CODECOV_TOKEN into the reusable workflow.
⚡reusable-test.yaml only declares and uses that secret, so secrets: inherit gives the reusable workflow broader access than it needs.
🔐 Suggested fix
unit:
name: Unit Tests
uses: ./.github/workflows/⚡reusable-test.yaml
- secrets: inherit
+ secrets:
+ CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
with:
mode: unit
int:
name: Integration Tests
uses: ./.github/workflows/⚡reusable-test.yaml
- secrets: inherit
+ secrets:
+ CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
with:
mode: int📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| uses: ./.github/workflows/⚡reusable-test.yaml | |
| secrets: inherit | |
| with: | |
| mode: unit | |
| int: | |
| name: Integration Tests | |
| uses: ./.github/workflows/⚡reusable-test-int.yaml | |
| uses: ./.github/workflows/⚡reusable-test.yaml | |
| secrets: inherit | |
| with: | |
| mode: int | |
| uses: ./.github/workflows/⚡reusable-test.yaml | |
| secrets: | |
| CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
| with: | |
| mode: unit | |
| int: | |
| name: Integration Tests | |
| uses: ./.github/workflows/⚡reusable-test.yaml | |
| secrets: | |
| CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
| with: | |
| mode: int |
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 15-20: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[warning] 11-11: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow
(secrets-inherit)
[warning] 17-17: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow
(secrets-inherit)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yaml around lines 11 - 20, The reusable workflow calls
in ci.yaml are using secrets: inherit, which grants broader access than needed;
update the workflow dispatch for the unit and int jobs to pass only
CODECOV_TOKEN into ⚡reusable-test.yaml. Keep the existing uses and with mode
settings, but replace inherited secrets with an explicit secrets mapping so the
reusable workflow only receives the secret it declares and uses.
Source: Linters/SAST tools
| "@biomejs/biome": "^2.5.1", | ||
| "@types/bun": "^1.3.14", | ||
| "@types/node": "^26.0.1", | ||
| "knip": "^6.23.0", |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== package.json engines =="
jq '.engines // {}' package.json
echo
echo "== Knip call sites =="
for f in knip.json knip.production.json knip.llm.json knip.production.llm.json nix/pre-commit.nix scripts/local/deadcode.sh; do
if [ -f "$f" ]; then
echo "--- $f ---"
sed -n '1,160p' "$f"
echo
fi
done
echo "== Common toolchain files mentioning Node/Bun =="
fd -HI '(\.nvmrc|\.node-version|\.tool-versions|package\.json|.*\.ya?ml|.*\.nix|Dockerfile)$' . \
-E node_modules -E dist -E build \
-x sh -c 'echo "--- $1 ---"; rg -n "node|Node|NODE|bun|Bun|BUN" "$1" || true; echo' sh {}Repository: AtomiCloud/diene.bun-cli
Length of output: 8978
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== package.json =="
cat -n package.json | sed -n '1,220p'
echo
echo "== bun / node version declarations =="
rg -n --hidden --glob '!node_modules' --glob '!dist' --glob '!build' \
'node\s*v?|NODE_VERSION|bun\s*v?|BUN_VERSION|engines|packageManager|volta|asdf|nvm|corepack|oven/bun|actions.setup-node|setup-node|setup-bun' \
.github nix scripts . 2>/dev/null || true
echo
echo "== files likely relevant to runtime/toolchain =="
for f in bun.lock bunfig.toml bunfig.unit.toml bunfig.int.toml package.json nix/env.nix nix/packages.nix .github/workflows/⚡reusable-precommit.yaml .github/workflows/⚡reusable-test.yaml .github/workflows/⚡reusable-build.yaml .github/workflows/ci.yaml; do
if [ -f "$f" ]; then
echo "--- $f ---"
sed -n '1,220p' "$f"
echo
fi
doneRepository: AtomiCloud/diene.bun-cli
Length of output: 50380
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== flake and shell definitions mentioning ci/dev shells =="
for f in flake.nix nix/shells.nix nix/env.nix nix/packages.nix scripts/ci/pre-commit.sh scripts/ci/test.sh scripts/ci/test-unit.sh scripts/ci/test-int.sh scripts/ci/build.sh; do
if [ -f "$f" ]; then
echo "--- $f ---"
sed -n '1,240p' "$f"
echo
fi
done
echo "== node-related package references in nix =="
rg -n --hidden --glob '!node_modules' --glob '!dist' --glob '!build' 'nodejs|node\s*=|nodePackages|setup-node|actions.setup-node|node-version|Node\.js|Nodejs' flake.nix nix .github scripts docs 2>/dev/null || trueRepository: AtomiCloud/diene.bun-cli
Length of output: 5143
🌐 Web query:
Knip v6 Node.js v20.19.0 requirement knip-bun binary bun support package bin
💡 Result:
Knip v6 requires Node.js v20.19.0 or newer to run [1][2]. Alternatively, you can run Knip using Bun, which is officially supported [3]. Regarding your query about knip-bun and Bun support: - Bun Support: Knip has dedicated support for Bun through its Bun plugin [4]. This plugin is automatically enabled if "bun" is listed in your dependencies or devDependencies in package.json [4]. It includes support for Bun-specific configurations (like bunfig.toml) and testing utilities [4][5]. - knip-bun binary: The knip-bun binary was introduced to provide an explicit entry point for running Knip with the Bun runtime [6]. It is defined in the package.json bin field as: "knip-bun": "./bin/knip-bun.js" [6] The content of bin/knip-bun.js uses the shebang #!/usr/bin/env bun to execute using the Bun runtime rather than Node.js [6].
Citations:
- 1: https://knip.dev/blog/knip-v6
- 2: https://github.com/webpro-nl/knip/releases/tag/knip@6.0.0
- 3: https://knip.dev/overview/getting-started
- 4: https://knip.dev/reference/plugins/bun
- 5: feat(plugins): add support for bun test preloaded files webpro-nl/knip#1525
- 6: webpro-nl/knip@b685723
🌐 Web query:
Bun package manager node_modules/.bin wrapper shebang node or bun knip binary bun runtime
💡 Result:
When you execute a CLI from node_modules/.bin using Bun (via bun run or bunx), Bun's behavior depends on the environment and the specified flags [1][2]. Shebang Handling By default, Bun respects the shebang present in the executable script (e.g., #!/usr/bin/env node) [1][3]. If the shebang points to node, Bun will spawn a node process to execute the file [1][2]. Forcing Bun Runtime To override the default behavior and force execution using the Bun runtime, you can use the --bun flag [1][3]. When this flag is used, Bun internally creates a symlink to the locally installed Bun executable, names it "node," adds it to your PATH for the duration of the script's execution, and ensures that the script runs with Bun instead of Node.js [2][4]. Windows Implementation On Windows, where shebangs are not natively supported, Bun uses a lightweight wrapper executable called bun_shim [5][6]. This shim is responsible for reading the intended interpreter from the script and launching the appropriate process [7][5]. It includes logic to fall back to Bun if a node shebang is specified but the node executable is unavailable on the system [8]. General CLI Execution When running commands like bun run or bunx , Bun prioritizes package.json scripts before checking for binaries in node_modules/.bin [9]. This process is designed to be transparent, allowing you to use Bun as a drop-in replacement for npm/npx while maintaining compatibility with existing Node-based packages [2][10]. Packages like Knip, when executed via bun run or bunx, follow these same rules; they will run on Node by default unless the --bun flag is explicitly provided [1][3].
Citations:
- 1: https://bun.com/docs/pm/bunx
- 2: https://bun.com/docs/guides/install/from-npm-install-to-bun-install
- 3: https://bun.com/docs/runtime
- 4: https://github.com/oven-sh/bun/blob/b0a6feca57bf5c2a9ec2ef9773499cab7d904b30/src/cli/run_command.zig
- 5: https://github.com/oven-sh/bun/blob/801e475c72b3573a91e0fb4c3afdd53b437770e1/src/install/windows-shim/bun_shim_impl.zig
- 6: windows(install): add bun_shim (support bin linking, bin shebangs, etc) oven-sh/bun#8265
- 7: https://github.com/oven-sh/bun/blob/7e57e529/src/install/windows-shim/BinLinkingShim.zig
- 8: Feature Request: Support
--bunflag inbun installto persist Bun-execution for CLIs (Node-free environment) oven-sh/bun#29578 - 9: Fix bun run folder oven-sh/bun#15117
- 10: feature request: bun run <cli> oven-sh/bun#17971
Pin a compatible runtime for Knip v6. The current hooks call ./node_modules/.bin/knip, but the repo shells only add Bun and package.json doesn’t declare a Node floor. Either add Node 20.19+ to the CI/dev shells or switch these hooks to knip-bun/bunx --bun.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@package.json` at line 18, The Knip hook setup is assuming a Node runtime that
is not guaranteed by the repo’s current shells, so pin a compatible runtime for
Knip v6 or switch the hook entrypoint. Update the hook configuration that
invokes ./node_modules/.bin/knip to either run through knip-bun/bunx --bun or
ensure the CI/dev shells declare Node 20.19+ alongside Bun, and keep
package.json aligned with the chosen runtime.
|
Closing per request; changes will be kept locally instead of via PR. |
Summary
Validation
Summary by CodeRabbit
New Features
Bug Fixes
Documentation
Chores