Skip to content

ci: sync bun baseline refresh - #8

Closed
adelphi-liong wants to merge 1 commit into
mainfrom
adelphi-liong/sync-bun-base-refresh
Closed

adelphi-liong wants to merge 1 commit into
mainfrom
adelphi-liong/sync-bun-base-refresh

Conversation

@adelphi-liong

@adelphi-liong adelphi-liong commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • sync Bun baseline CI/docs/tooling from diene.bun-base
  • replace split unit/int reusable test workflows with the shared mode-based workflow
  • update package/lock/tooling versions and repo-specific Docker image names

Validation

  • bun install --frozen-lockfile
  • nix develop .#ci -c actionlint
  • nix develop .#ci -c ./scripts/ci/pre-commit.sh
  • nix develop .#ci -c ./scripts/ci/test-unit.sh
  • DOCKER_HOST=unix:///Users/erng/.orbstack/run/docker.sock nix develop .#ci -c ./scripts/ci/test-int.sh
  • nix develop .#ci -c ./scripts/ci/build.sh
  • docker build -f infra/Dockerfile -t diene-bun-cli:sync-bun-base-refresh .

Summary by CodeRabbit

  • New Features

    • Consolidated test automation into one reusable workflow for both unit and integration checks, with clearer status reporting and coverage uploads.
    • Added clearer project status badges to the README.
  • Bug Fixes

    • Improved coverage handling so test reporting is less likely to fail on external service issues.
    • Adjusted integration coverage exclusions for more accurate reporting.
  • Documentation

    • Updated developer notes to reflect the latest testing and coverage behavior.
  • Chores

    • Refreshed tool and schema versions across project configuration.

@coderabbitai

coderabbitai Bot commented Jun 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

No new commits to review since the last review.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0a28d12e-8dc5-4fbf-82ff-41b7bf6a90c9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Two separate reusable CI workflows for unit and integration tests are replaced by a single parameterized ⚡reusable-test.yaml workflow using a mode input. The Docker image reference is renamed from diene-bun-cli in CI and Taskfile. Coverage exclusions, Codecov config, Knip schemas (v5→v6), Biome schema, and several dependencies are also updated.

Changes

CI and Coverage Consolidation

Layer / File(s) Summary
Unified reusable test workflow
.github/workflows/⚡reusable-test.yaml, .github/workflows/ci.yaml
New ⚡reusable-test.yaml accepts a required mode input and runs the corresponding test script, uploads coverage artifact, and posts to Codecov. ci.yaml updated to call this workflow with mode: unit and mode: int, replacing the two deleted separate reusable workflows.
Docker rename and coverage config
.github/workflows/ci.yaml, tasks/Taskfile.docker.yaml, bunfig.int.toml, codecov.yml, docs/developer/bun-baseline.md, README.md
Docker image reference renamed from diene-bun-base to diene-bun-cli. Integration coverage now excludes src/index.ts and src/lib/** via coveragePathIgnorePatterns. Codecov project/patch statuses set to informational: true with threshold: 1%. Docs and README badges updated accordingly.
Tooling schema and dependency bumps
knip.json, knip.llm.json, knip.production.json, knip.production.llm.json, biome.json, package.json
All Knip configs updated from v5 to v6 schema; classMembers rule removed, enumMembers set to off. Biome schema bumped to 2.5.1. ioredis, @biomejs/biome, knip, testcontainers, typescript, and Bun/Node type packages bumped to newer versions.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Poem

🐇 Two workflows were two, now just one with a mode,
A single YAML to lighten the load.
The docker image got a fresh new name,
And Knip jumped to six — never the same!
Badges now gleam at the top of the README,
Hopping along, this bunny is free~ 🌿

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title matches the PR’s main theme: syncing the Bun baseline CI and related tooling/documentation updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch adelphi-liong/sync-bun-base-refresh

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Jun 30, 2026

Copy link
Copy Markdown

Welcome to Codecov 🎉

Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests.

ℹ️ You can also turn on project coverage checks and project coverage reporting on Pull Request comment

Thanks for integrating Codecov - We've got you covered ☂️

@adelphi-liong

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/⚡reusable-test.yaml:
- Around line 22-23: The reusable test workflow step interpolates inputs.mode
directly into the shell command, so validate and constrain mode before it
reaches the run invocation in the reusable workflow. Update the workflow around
the Run ${{ inputs.mode }} tests step to allow only the expected values (for
example, unit or int) and fail fast on anything else, instead of relying on
scripts/ci/test-${{ inputs.mode }}.sh to catch it later. Use the existing
inputs.mode reference in the workflow to add the guard before the nix develop
command is executed.

In @.github/workflows/ci.yaml:
- Around line 11-20: The reusable workflow calls in ci.yaml are using secrets:
inherit, which grants broader access than needed; update the workflow dispatch
for the unit and int jobs to pass only CODECOV_TOKEN into ⚡reusable-test.yaml.
Keep the existing uses and with mode settings, but replace inherited secrets
with an explicit secrets mapping so the reusable workflow only receives the
secret it declares and uses.

In `@package.json`:
- Line 18: The Knip hook setup is assuming a Node runtime that is not guaranteed
by the repo’s current shells, so pin a compatible runtime for Knip v6 or switch
the hook entrypoint. Update the hook configuration that invokes
./node_modules/.bin/knip to either run through knip-bun/bunx --bun or ensure the
CI/dev shells declare Node 20.19+ alongside Bun, and keep package.json aligned
with the chosen runtime.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0176e866-5ab0-4078-95a2-e0171d6e25ef

📥 Commits

Reviewing files that changed from the base of the PR and between 986de7b and 2bcd71a.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (15)
  • .github/workflows/ci.yaml
  • .github/workflows/⚡reusable-test-int.yaml
  • .github/workflows/⚡reusable-test-unit.yaml
  • .github/workflows/⚡reusable-test.yaml
  • README.md
  • biome.json
  • bunfig.int.toml
  • codecov.yml
  • docs/developer/bun-baseline.md
  • knip.json
  • knip.llm.json
  • knip.production.json
  • knip.production.llm.json
  • package.json
  • tasks/Taskfile.docker.yaml
💤 Files with no reviewable changes (2)
  • .github/workflows/⚡reusable-test-unit.yaml
  • .github/workflows/⚡reusable-test-int.yaml

Comment on lines +22 to +23
- name: Run ${{ inputs.mode }} tests
run: nix develop .#ci -c ./scripts/ci/test-${{ inputs.mode }}.sh

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Inspect every caller of the reusable workflow and the exact mode values passed.
rg -n -C2 'uses:\s*\./\.github/workflows/⚡reusable-test\.yaml|mode:' .github/workflows

Repository: AtomiCloud/diene.bun-cli

Length of output: 1181


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== reusable workflow ==\n'
cat -n .github/workflows/⚡reusable-test.yaml

printf '\n== test wrapper ==\n'
cat -n scripts/ci/test.sh

Repository: AtomiCloud/diene.bun-cli

Length of output: 2753


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== workflow callers ==\n'
rg -n -C3 'uses:\s*\./\.github/workflows/⚡reusable-test\.yaml|mode:' .github/workflows

Repository: AtomiCloud/diene.bun-cli

Length of output: 1439


🏁 Script executed:

#!/bin/bash
set -euo pipefail

python3 - <<'PY'
import subprocess, shlex

for mode in ["unit", "unit; echo INJECTED", 'unit $(echo INJECTED)']:
    cmd = f"echo nix develop .#ci -c ./scripts/ci/test-{mode}.sh"
    print(f"\nMODE={mode!r}")
    print("COMMAND:", cmd)
    out = subprocess.check_output(["bash", "-lc", cmd], text=True)
    print("OUTPUT:", out.rstrip())
PY

Repository: AtomiCloud/diene.bun-cli

Length of output: 922


Validate mode before interpolating it into the shell command. workflow_call accepts an unconstrained string here, and run: nix develop .#ci -c ./scripts/ci/test-${{ inputs.mode }}.sh turns a bad value into shell injection or an unintended script path. The wrapper script checks unit|int, but that happens too late.

🧰 Tools
🪛 zizmor (1.26.1)

[error] 23-23: code injection via template expansion (template-injection): may expand into attacker-controllable code

(template-injection)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/⚡reusable-test.yaml around lines 22 - 23, The reusable
test workflow step interpolates inputs.mode directly into the shell command, so
validate and constrain mode before it reaches the run invocation in the reusable
workflow. Update the workflow around the Run ${{ inputs.mode }} tests step to
allow only the expected values (for example, unit or int) and fail fast on
anything else, instead of relying on scripts/ci/test-${{ inputs.mode }}.sh to
catch it later. Use the existing inputs.mode reference in the workflow to add
the guard before the nix develop command is executed.

Source: Linters/SAST tools

Comment thread .github/workflows/ci.yaml
Comment on lines +11 to +20
uses: ./.github/workflows/⚡reusable-test.yaml
secrets: inherit
with:
mode: unit
int:
name: Integration Tests
uses: ./.github/workflows/⚡reusable-test-int.yaml
uses: ./.github/workflows/⚡reusable-test.yaml
secrets: inherit
with:
mode: int

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Confirm which secrets the callee declares and actually references.
sed -n '1,80p' .github/workflows/⚡reusable-test.yaml
printf '\n--- secret references ---\n'
rg -n 'CODECOV_TOKEN|secrets\.' .github/workflows/⚡reusable-test.yaml .github/workflows/ci.yaml

Repository: AtomiCloud/diene.bun-cli

Length of output: 1638


Pass only CODECOV_TOKEN into the reusable workflow.
⚡reusable-test.yaml only declares and uses that secret, so secrets: inherit gives the reusable workflow broader access than it needs.

🔐 Suggested fix
   unit:
     name: Unit Tests
     uses: ./.github/workflows/⚡reusable-test.yaml
-    secrets: inherit
+    secrets:
+      CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
     with:
       mode: unit
   int:
     name: Integration Tests
     uses: ./.github/workflows/⚡reusable-test.yaml
-    secrets: inherit
+    secrets:
+      CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
     with:
       mode: int
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
uses: ./.github/workflows/⚡reusable-test.yaml
secrets: inherit
with:
mode: unit
int:
name: Integration Tests
uses: ./.github/workflows/⚡reusable-test-int.yaml
uses: ./.github/workflows/⚡reusable-test.yaml
secrets: inherit
with:
mode: int
uses: ./.github/workflows/⚡reusable-test.yaml
secrets:
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
with:
mode: unit
int:
name: Integration Tests
uses: ./.github/workflows/⚡reusable-test.yaml
secrets:
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
with:
mode: int
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 15-20: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block

(excessive-permissions)


[warning] 11-11: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow

(secrets-inherit)


[warning] 17-17: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow

(secrets-inherit)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yaml around lines 11 - 20, The reusable workflow calls
in ci.yaml are using secrets: inherit, which grants broader access than needed;
update the workflow dispatch for the unit and int jobs to pass only
CODECOV_TOKEN into ⚡reusable-test.yaml. Keep the existing uses and with mode
settings, but replace inherited secrets with an explicit secrets mapping so the
reusable workflow only receives the secret it declares and uses.

Source: Linters/SAST tools

Comment thread package.json
"@biomejs/biome": "^2.5.1",
"@types/bun": "^1.3.14",
"@types/node": "^26.0.1",
"knip": "^6.23.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== package.json engines =="
jq '.engines // {}' package.json

echo
echo "== Knip call sites =="
for f in knip.json knip.production.json knip.llm.json knip.production.llm.json nix/pre-commit.nix scripts/local/deadcode.sh; do
  if [ -f "$f" ]; then
    echo "--- $f ---"
    sed -n '1,160p' "$f"
    echo
  fi
done

echo "== Common toolchain files mentioning Node/Bun =="
fd -HI '(\.nvmrc|\.node-version|\.tool-versions|package\.json|.*\.ya?ml|.*\.nix|Dockerfile)$' . \
  -E node_modules -E dist -E build \
  -x sh -c 'echo "--- $1 ---"; rg -n "node|Node|NODE|bun|Bun|BUN" "$1" || true; echo' sh {}

Repository: AtomiCloud/diene.bun-cli

Length of output: 8978


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== package.json =="
cat -n package.json | sed -n '1,220p'

echo
echo "== bun / node version declarations =="
rg -n --hidden --glob '!node_modules' --glob '!dist' --glob '!build' \
  'node\s*v?|NODE_VERSION|bun\s*v?|BUN_VERSION|engines|packageManager|volta|asdf|nvm|corepack|oven/bun|actions.setup-node|setup-node|setup-bun' \
  .github nix scripts . 2>/dev/null || true

echo
echo "== files likely relevant to runtime/toolchain =="
for f in bun.lock bunfig.toml bunfig.unit.toml bunfig.int.toml package.json nix/env.nix nix/packages.nix .github/workflows/⚡reusable-precommit.yaml .github/workflows/⚡reusable-test.yaml .github/workflows/⚡reusable-build.yaml .github/workflows/ci.yaml; do
  if [ -f "$f" ]; then
    echo "--- $f ---"
    sed -n '1,220p' "$f"
    echo
  fi
done

Repository: AtomiCloud/diene.bun-cli

Length of output: 50380


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== flake and shell definitions mentioning ci/dev shells =="
for f in flake.nix nix/shells.nix nix/env.nix nix/packages.nix scripts/ci/pre-commit.sh scripts/ci/test.sh scripts/ci/test-unit.sh scripts/ci/test-int.sh scripts/ci/build.sh; do
  if [ -f "$f" ]; then
    echo "--- $f ---"
    sed -n '1,240p' "$f"
    echo
  fi
done

echo "== node-related package references in nix =="
rg -n --hidden --glob '!node_modules' --glob '!dist' --glob '!build' 'nodejs|node\s*=|nodePackages|setup-node|actions.setup-node|node-version|Node\.js|Nodejs' flake.nix nix .github scripts docs 2>/dev/null || true

Repository: AtomiCloud/diene.bun-cli

Length of output: 5143


🌐 Web query:

Knip v6 Node.js v20.19.0 requirement knip-bun binary bun support package bin

💡 Result:

Knip v6 requires Node.js v20.19.0 or newer to run [1][2]. Alternatively, you can run Knip using Bun, which is officially supported [3]. Regarding your query about knip-bun and Bun support: - Bun Support: Knip has dedicated support for Bun through its Bun plugin [4]. This plugin is automatically enabled if "bun" is listed in your dependencies or devDependencies in package.json [4]. It includes support for Bun-specific configurations (like bunfig.toml) and testing utilities [4][5]. - knip-bun binary: The knip-bun binary was introduced to provide an explicit entry point for running Knip with the Bun runtime [6]. It is defined in the package.json bin field as: "knip-bun": "./bin/knip-bun.js" [6] The content of bin/knip-bun.js uses the shebang #!/usr/bin/env bun to execute using the Bun runtime rather than Node.js [6].

Citations:


🌐 Web query:

Bun package manager node_modules/.bin wrapper shebang node or bun knip binary bun runtime

💡 Result:

When you execute a CLI from node_modules/.bin using Bun (via bun run or bunx), Bun's behavior depends on the environment and the specified flags [1][2]. Shebang Handling By default, Bun respects the shebang present in the executable script (e.g., #!/usr/bin/env node) [1][3]. If the shebang points to node, Bun will spawn a node process to execute the file [1][2]. Forcing Bun Runtime To override the default behavior and force execution using the Bun runtime, you can use the --bun flag [1][3]. When this flag is used, Bun internally creates a symlink to the locally installed Bun executable, names it "node," adds it to your PATH for the duration of the script's execution, and ensures that the script runs with Bun instead of Node.js [2][4]. Windows Implementation On Windows, where shebangs are not natively supported, Bun uses a lightweight wrapper executable called bun_shim [5][6]. This shim is responsible for reading the intended interpreter from the script and launching the appropriate process [7][5]. It includes logic to fall back to Bun if a node shebang is specified but the node executable is unavailable on the system [8]. General CLI Execution When running commands like bun run or bunx , Bun prioritizes package.json scripts before checking for binaries in node_modules/.bin [9]. This process is designed to be transparent, allowing you to use Bun as a drop-in replacement for npm/npx while maintaining compatibility with existing Node-based packages [2][10]. Packages like Knip, when executed via bun run or bunx, follow these same rules; they will run on Node by default unless the --bun flag is explicitly provided [1][3].

Citations:


Pin a compatible runtime for Knip v6. The current hooks call ./node_modules/.bin/knip, but the repo shells only add Bun and package.json doesn’t declare a Node floor. Either add Node 20.19+ to the CI/dev shells or switch these hooks to knip-bun/bunx --bun.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 18, The Knip hook setup is assuming a Node runtime that
is not guaranteed by the repo’s current shells, so pin a compatible runtime for
Knip v6 or switch the hook entrypoint. Update the hook configuration that
invokes ./node_modules/.bin/knip to either run through knip-bun/bunx --bun or
ensure the CI/dev shells declare Node 20.19+ alongside Bun, and keep
package.json aligned with the chosen runtime.

@adelphi-liong

Copy link
Copy Markdown
Contributor Author

Closing per request; changes will be kept locally instead of via PR.

@adelphi-liong
adelphi-liong deleted the adelphi-liong/sync-bun-base-refresh branch June 30, 2026 06:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant