Skip to content

chore(ci): bump Bun pin 1.3.14 → 1.4.2 - #8337

Merged
deruelle merged 5 commits into
mainfrom
chore-bump-bun-1.4.2
Sep 19, 2026
Merged

deruelle merged 5 commits into
mainfrom
chore-bump-bun-1.4.2

Conversation

@deruelle

@deruelle deruelle commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Why

Bun 1.3.14's test runner crashes instead of failing when a second test file imports a cached module with two or more build errors — a syntax error in a shared lib takes down bun test with panic(main thread): Segmentation fault at address 0x5, surfaced as SIGILL via Bun's own panic trap.

Hit locally on 2026-09-18 while editing plugins/soleur/lib/harness-parity.ts (a JSDoc block containing a literal */ closed the comment early). The panic banner was swallowed by a | grep in the agent's pipeline, so it looked like a run that matched nothing.

Upstream

Verified

The reproduction fails cleanly on 1.4.2: AggregateError: 3 errors building lib.ts, 2 fail, exit 1. No panic, no core. test-bun passed on 1.4.2 in three separate CI runs of this PR.

Scope

.bun-version plus what the 4-agent review found: every other place the Bun version was declared, brought into line so the pin is the single source of truth.

  • web-platform-release.yml: setup-bun had no with: (floated latest) → reads .bun-version
  • skill-security-scan-{corpus,pr-trailer}.yml: setup-bun SHA brought into lockstep with ci.yml (v2.1.2)
  • validate-vector-config.yml: bun-version: latest → .bun-version, and .bun-version added to its paths: so a pin bump exercises it
  • plugin-root-propagation-verify-in-image.sh: npm i -g bun@1.3.11 → the pin, passed in via exported BUN_VERSION
  • sandbox-canary-verify-in-image.sh: curl bun.sh/install | bash (unversioned) → bash -s "bun-v$BUN_VERSION"
  • preflight-check10-suite-integrity.test.sh: the "verified on 1.3.14" comment replaced with the 1.4.2 measurement (byte-identical summary output under FORCE_COLOR=1, so the load-bearing terminator is unchanged)

scripts/test-all.sh reads the file at runtime and needed no change.

Review

/soleur:review, non-code class, 4/4 agents (git-history, pattern-recognition, security-sentinel, code-quality). 8 findings triaged: 6 fixed inline (above), 2 wontfix — setup-bun does not verify download checksums (upstream action behaviour), and actionlint SC2221/SC2222 in skill-security-scan-pr-trailer.yml:155 (pre-existing on main, untouched run: block). 0 filed.

🤖 Generated with Claude Code

@deruelle
deruelle force-pushed the chore-bump-bun-1.4.2 branch 4 times, most recently from 7c5e1e2 to 313ceed Compare September 19, 2026 20:11
@deruelle
deruelle enabled auto-merge (squash) September 19, 2026 20:20
deruelle and others added 5 commits September 19, 2026 23:30
Bun 1.3.14's test runner null-derefs (SIGSEGV at 0x5, surfaced as SIGILL
via its own panic trap) when a second test file imports a cached module
carrying two or more build errors — so a syntax error in a shared lib
crashes `bun test` instead of failing it. Hit locally on 2026-09-18 while
editing plugins/soleur/lib/harness-parity.ts; the panic banner was
swallowed by a `| grep` in the agent's pipeline.

Upstream: oven-sh/bun#36963 (same version, same shape) and #40780
(root cause: print_errorlike_object reads AggregateError.errors via
getDirect(), forEachInIterable then walks the empty JSValue). Fixed by
oven-sh/bun#39633, shipped in 1.4.1. Verified the reproduction fails
cleanly on 1.4.2 (`AggregateError: 3 errors building lib.ts`, exit 1).

scripts/test-all.sh reads this file at runtime, so no other change is
needed; CI picks it up via `bun-version-file`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… (P3)

The one workflow whose setup-bun step floated `bun-version: latest` while
every other workflow reads `bun-version-file: ".bun-version"`. Pre-existing;
surfaced by the git-history seat while confirming every Bun consumer
follows the pin this PR bumps. Pinning it preserves the intent the pin
was introduced for (2026-03: no surprise breakage from a floating version).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…roll-up)

Four seats surfaced five declaration sites of the Bun version that did not
follow the pin this PR bumps — one gap, not five findings:

- web-platform-release.yml: setup-bun with no `with:` (floated latest)
- skill-security-scan-{corpus,pr-trailer}.yml: setup-bun pinned to the
  2025-04 `v2` SHA while ci.yml:870 asks for lockstep on v2.1.2
- plugin-root-propagation-verify-in-image.sh: `npm i -g bun@1.3.11`, two
  minors behind the pin it never read
- sandbox-canary-verify-in-image.sh: `curl bun.sh/install | bash` with no
  version, so the canary ran on whatever bun.sh served that day

The two in-image scripts now read the pin host-side (they run from the repo
root; /src is apps/web-platform) and pass it in with `-e BUN_VERSION` —
EXPORTED, because `docker run -e NAME` reads the client environment, not
shell variables (shellcheck SC2034 caught the unexported first draft; proven
with a positive and a negative control).

validate-vector-config.yml gains `.bun-version` in both `paths:` lists so a
pin bump exercises the one workflow the three green CI runs never reached.

preflight-check10: the "VERIFIED ALSO ON 1.3.14" comment this PR made false
now records the 1.4.2 measurement — same suite on both binaries under
FORCE_COLOR=1, `cat -v` byte-identical apart from the elapsed-time suffix,
so the load-bearing terminator is unchanged.

Verified: shellcheck clean; lint-workflow-install-sites OK (41 sites) and
its 29-assertion test; preflight-check10 29/29; scripts-shard-runtime-
coverage ALL PASSED. actionlint's SC2221/SC2222 on pr-trailer.yml:155 are
pre-existing on main (4 there, 4 here) in a run: block this does not touch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Records that soleur:review ran on this branch (see issue 6724). Empty by design: a review that finds nothing still needs to prove it ran. This is a boolean, not an attestation that the merged tree is the reviewed tree — see ADR-127. Reviewed-Coverage records HOW MUCH review ran (a separate axis from ADR-127's tree-binding decision); 'unknown' means the caller did not measure, never that coverage was full.

Reviewed-By-Soleur: soleur:review
Reviewed-Commit: b52a02e
Reviewed-Coverage: full 4/4 agents
`lint-bot-statuses` reddened on the previous commit: both scripts bind a
live ANTHROPIC_API_KEY (`docker run -e ANTHROPIC_API_KEY`) and carried no
xtrace refusal, so an `sh -x` of either would print the credential into
whatever captures stderr.

Pre-existing — the lint is `--changed --base origin/main` scoped, so the
gap only became visible when the previous commit brought these two files
into the diff. Fixed rather than deferred: the guard is right, and the
block it prescribes is what the compliant siblings already carry
(seed-live-verify-user.sh, seed-dev-users.sh).

Verified in both directions, not just the refusal arm:
  ANTHROPIC_API_KEY=… bash -x <script>  → prints the refusal, exits 78
  env -u ANTHROPIC_API_KEY bash -x …    → no refusal (0 matches)
lint now OK (3 scanned, 0 violations); shellcheck clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@deruelle
deruelle force-pushed the chore-bump-bun-1.4.2 branch from efc7681 to 9bb3084 Compare September 19, 2026 21:30
@deruelle
deruelle merged commit f9cd8dc into main Sep 19, 2026
76 checks passed
@deruelle
deruelle deleted the chore-bump-bun-1.4.2 branch September 19, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant