chore(ci): bump Bun pin 1.3.14 → 1.4.2 - #8337
Merged
Merged
Conversation
deruelle
force-pushed
the
chore-bump-bun-1.4.2
branch
4 times, most recently
from
September 19, 2026 20:11
7c5e1e2 to
313ceed
Compare
deruelle
enabled auto-merge (squash)
September 19, 2026 20:20
Bun 1.3.14's test runner null-derefs (SIGSEGV at 0x5, surfaced as SIGILL via its own panic trap) when a second test file imports a cached module carrying two or more build errors — so a syntax error in a shared lib crashes `bun test` instead of failing it. Hit locally on 2026-09-18 while editing plugins/soleur/lib/harness-parity.ts; the panic banner was swallowed by a `| grep` in the agent's pipeline. Upstream: oven-sh/bun#36963 (same version, same shape) and #40780 (root cause: print_errorlike_object reads AggregateError.errors via getDirect(), forEachInIterable then walks the empty JSValue). Fixed by oven-sh/bun#39633, shipped in 1.4.1. Verified the reproduction fails cleanly on 1.4.2 (`AggregateError: 3 errors building lib.ts`, exit 1). scripts/test-all.sh reads this file at runtime, so no other change is needed; CI picks it up via `bun-version-file`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… (P3) The one workflow whose setup-bun step floated `bun-version: latest` while every other workflow reads `bun-version-file: ".bun-version"`. Pre-existing; surfaced by the git-history seat while confirming every Bun consumer follows the pin this PR bumps. Pinning it preserves the intent the pin was introduced for (2026-03: no surprise breakage from a floating version). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…roll-up)
Four seats surfaced five declaration sites of the Bun version that did not
follow the pin this PR bumps — one gap, not five findings:
- web-platform-release.yml: setup-bun with no `with:` (floated latest)
- skill-security-scan-{corpus,pr-trailer}.yml: setup-bun pinned to the
2025-04 `v2` SHA while ci.yml:870 asks for lockstep on v2.1.2
- plugin-root-propagation-verify-in-image.sh: `npm i -g bun@1.3.11`, two
minors behind the pin it never read
- sandbox-canary-verify-in-image.sh: `curl bun.sh/install | bash` with no
version, so the canary ran on whatever bun.sh served that day
The two in-image scripts now read the pin host-side (they run from the repo
root; /src is apps/web-platform) and pass it in with `-e BUN_VERSION` —
EXPORTED, because `docker run -e NAME` reads the client environment, not
shell variables (shellcheck SC2034 caught the unexported first draft; proven
with a positive and a negative control).
validate-vector-config.yml gains `.bun-version` in both `paths:` lists so a
pin bump exercises the one workflow the three green CI runs never reached.
preflight-check10: the "VERIFIED ALSO ON 1.3.14" comment this PR made false
now records the 1.4.2 measurement — same suite on both binaries under
FORCE_COLOR=1, `cat -v` byte-identical apart from the elapsed-time suffix,
so the load-bearing terminator is unchanged.
Verified: shellcheck clean; lint-workflow-install-sites OK (41 sites) and
its 29-assertion test; preflight-check10 29/29; scripts-shard-runtime-
coverage ALL PASSED. actionlint's SC2221/SC2222 on pr-trailer.yml:155 are
pre-existing on main (4 there, 4 here) in a run: block this does not touch.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Records that soleur:review ran on this branch (see issue 6724). Empty by design: a review that finds nothing still needs to prove it ran. This is a boolean, not an attestation that the merged tree is the reviewed tree — see ADR-127. Reviewed-Coverage records HOW MUCH review ran (a separate axis from ADR-127's tree-binding decision); 'unknown' means the caller did not measure, never that coverage was full. Reviewed-By-Soleur: soleur:review Reviewed-Commit: b52a02e Reviewed-Coverage: full 4/4 agents
`lint-bot-statuses` reddened on the previous commit: both scripts bind a live ANTHROPIC_API_KEY (`docker run -e ANTHROPIC_API_KEY`) and carried no xtrace refusal, so an `sh -x` of either would print the credential into whatever captures stderr. Pre-existing — the lint is `--changed --base origin/main` scoped, so the gap only became visible when the previous commit brought these two files into the diff. Fixed rather than deferred: the guard is right, and the block it prescribes is what the compliant siblings already carry (seed-live-verify-user.sh, seed-dev-users.sh). Verified in both directions, not just the refusal arm: ANTHROPIC_API_KEY=… bash -x <script> → prints the refusal, exits 78 env -u ANTHROPIC_API_KEY bash -x … → no refusal (0 matches) lint now OK (3 scanned, 0 violations); shellcheck clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
deruelle
force-pushed
the
chore-bump-bun-1.4.2
branch
from
September 19, 2026 21:30
efc7681 to
9bb3084
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Bun 1.3.14's test runner crashes instead of failing when a second test file imports a cached module with two or more build errors — a syntax error in a shared lib takes down
bun testwithpanic(main thread): Segmentation fault at address 0x5, surfaced as SIGILL via Bun's own panic trap.Hit locally on 2026-09-18 while editing
plugins/soleur/lib/harness-parity.ts(a JSDoc block containing a literal*/closed the comment early). The panic banner was swallowed by a| grepin the agent's pipeline, so it looked like a run that matched nothing.Upstream
lib.tswith a syntax error imported by two spec files)print_errorlike_objectreadsAggregateError.errorsviagetDirect(), gets the empty JSValue when it isn't an own data property, andforEachInIterablewalks it as a cell near 0Verified
The reproduction fails cleanly on 1.4.2:
AggregateError: 3 errors building lib.ts,2 fail, exit 1. No panic, no core.test-bunpassed on 1.4.2 in three separate CI runs of this PR.Scope
.bun-versionplus what the 4-agent review found: every other place the Bun version was declared, brought into line so the pin is the single source of truth.web-platform-release.yml: setup-bun had nowith:(floated latest) → reads.bun-versionskill-security-scan-{corpus,pr-trailer}.yml: setup-bun SHA brought into lockstep with ci.yml (v2.1.2)validate-vector-config.yml:bun-version: latest→.bun-version, and.bun-versionadded to itspaths:so a pin bump exercises itplugin-root-propagation-verify-in-image.sh:npm i -g bun@1.3.11→ the pin, passed in via exportedBUN_VERSIONsandbox-canary-verify-in-image.sh:curl bun.sh/install | bash(unversioned) →bash -s "bun-v$BUN_VERSION"preflight-check10-suite-integrity.test.sh: the "verified on 1.3.14" comment replaced with the 1.4.2 measurement (byte-identical summary output underFORCE_COLOR=1, so the load-bearing terminator is unchanged)scripts/test-all.shreads the file at runtime and needed no change.Review
/soleur:review, non-code class, 4/4 agents (git-history, pattern-recognition, security-sentinel, code-quality). 8 findings triaged: 6 fixed inline (above), 2 wontfix — setup-bun does not verify download checksums (upstream action behaviour), and actionlint SC2221/SC2222 inskill-security-scan-pr-trailer.yml:155(pre-existing on main, untouchedrun:block). 0 filed.🤖 Generated with Claude Code