Skip to content

ci: pin Bun across web validation jobs - #13596

Merged
teamleaderleo merged 1 commit into
mainfrom
ci/pin-web-bun-version
Sep 22, 2026
Merged

teamleaderleo merged 1 commit into
mainfrom
ci/pin-web-bun-version

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Pin every setup-bun invocation in the reusable web CI workflow to Bun 1.3.14.

Four jobs already carried the explicit version. Four others relied on the action's default/latest resolution:

  • React/webview generated-asset checks;
  • diff sidecar checks;
  • web database migrations;
  • Agent Session web resources.

Why

Unversioned setup-bun resolves release metadata through the GitHub API. Under a busy CI installation, two independent jobs in #13360 failed before running any project code because that tag lookup hit the installation rate limit.

The workflow already standardizes its other Bun jobs on 1.3.14, so using the same explicit version everywhere removes that metadata lookup and makes the web lanes use one known toolchain.

Testing

Adds a workflow contract test requiring every setup-bun block in ci-web.yml to carry bun-version: "1.3.14".

Demo Video

N/A — CI toolchain reliability only.

Checklist

  • All web CI Bun jobs use the same version
  • No project test/build command changes
  • Regression coverage prevents unpinned setup from returning

Summary by cubic

Pins every setup-bun invocation in the web CI workflow to Bun 1.3.14, preventing the jobs that relied on the action's default version from failing under GitHub API rate limits during heavy CI load. Adds a workflow contract test requiring every setup-bun block in ci-web.yml to specify bun-version: "1.3.14".

Written for commit 22562ea. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Maintenance

    • Standardized Bun setup across web-based CI jobs by pinning version 1.3.14.
  • Tests

    • Added automated coverage to verify that every web workflow Bun setup uses the pinned version.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 256448bf-d950-4c6b-95d7-22e20acf6461

📥 Commits

Reviewing files that changed from the base of the PR and between 9c59b59 and 22562ea.

📒 Files selected for processing (2)
  • .github/workflows/ci-web.yml
  • tests/test_ci_change_areas.py

Included review availability: Your plan provides up to 10 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The web CI workflow now pins Bun 1.3.14 in four jobs. A test verifies that every pinned Bun setup uses this version.

Changes

Bun version pinning

Layer / File(s) Summary
Pin Bun in web CI
.github/workflows/ci-web.yml
The React apps, diff-sidecar, web database migrations, and agent-session web resources jobs now configure Bun 1.3.14.
Validate every Bun setup
tests/test_ci_change_areas.py
A test verifies that each pinned setup-bun action includes bun-version: "1.3.14".

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 22562

Web CI now consistently uses Bun 1.3.14 across its web jobs, reducing setup-time failures and remaining mergeable with normal checks.

🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Cloud Persistent Session And Early Input ✅ Passed The check is not applicable. The authoritative PR diff changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The code changes add Bun 1.3.14 inputs and a workflow contract…
Cmux Swift Actor Isolation ✅ Passed PASS — The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The diff contains no Swift files or production Swift code, so it cannot introduce or worsen the…
Cmux Swift Blocking Runtime ✅ Passed The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The diff contains no production Swift changes and introduces no semaphores, blocking waits, sleeps, de…
Cmux Browser Automation Off-Main ✅ Passed PASS: The pull request changes only Bun version inputs in .github/workflows/ci-web.yml and adds a CI contract test. It introduces no browser.* command, socket-worker routing, WebKit/AppKit access,…
Cmux Expensive Synchronous Load ✅ Passed The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The diff contains no Swift changes and no agent-history load, synchronous parsing, or interactive-path…
Cmux Cache Substitution Correctness ✅ Passed PASS: The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. It does not change production Swift, TypeScript, or JavaScript code, and it does not substitute …
Cmux No Hacky Sleeps ✅ Passed The pull request adds only Bun version fields to GitHub Actions YAML and a Python test-only contract. The rule explicitly excludes GitHub Actions workflow YAML, and the added lines contain no sleeps, …
Cmux Algorithmic Complexity ✅ Passed PASS. The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The workflow changes pin Bun versions and introduce no production Swift, TypeScript, JavaScript,…
Cmux Swift Concurrency ✅ Passed PASS. The authoritative diff changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. It contains no Swift paths and introduces no DispatchQueue, Combine, completion-handler,…
Cmux Swift @Concurrent ✅ Passed The authoritative PR diff changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. It contains no Swift files, Swift functions, or actor-isolation changes. The `swift-concurren…
Cmux Swift Package Boundaries ✅ Passed PASS. The authoritative diff changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. It contains no Swift production changes, so the Swift package-boundary rule is not applica…
Cmux Swiftpm Lockfiles ✅ Passed The PR changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The workflow additions pin Bun to 1.3.14; they do not change SwiftPM dependencies or Xcode package references.…
Cmux Swift Logging ✅ Passed The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The authoritative diff contains no Swift files or Swift logging changes, so this check is not applicab…
Cmux User-Facing Error Privacy ✅ Passed PASS. The PR changes only the internal .github/workflows/ci-web.yml CI workflow and a developer test. The workflow additions pin oven-sh/setup-bun to bun-version: "1.3.14"; the test checks that …
Cmux Full Internationalization ✅ Passed PASS: The pull request changes only the operational .github/workflows/ci-web.yml workflow and a test. It adds the literal Bun version configuration to CI setup steps and adds a developer-facing work…
Cmux Swiftui State Layout ✅ Passed PASS. The reviewed diff changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. It adds Bun version pins and a CI contract test. No Swift or SwiftUI code changes are present, …
Cmux Architecture Rethink ✅ Passed PASS. The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. It adds Bun version pins and a Python workflow contract test. It contains no Swift changes, life…
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. The diff contains no Swift code or standalone cmux-owned window changes, so the auxiliary-window close…
Cmux Source Artifacts ✅ Passed The diff changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. Both are regular, intentional workflow/test source files. The workflow adds Bun version configuration, and the…
Cmux No Test Or Debug Seam In Production Source ✅ Passed The pull request changes only .github/workflows/ci-web.yml and tests/test_ci_change_areas.py. It changes no Swift file under a production Sources/ path, so the custom check does not apply.
Title check ✅ Passed The title clearly and concisely describes the main change: pinning Bun across the web validation jobs.
Description check ✅ Passed The description explains what changed, why it changed, and how it was tested. It also addresses the non-UI change with “N/A” for the demo video. The required Review Trigger section and several standar…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo enabled auto-merge (squash) September 22, 2026 04:26

Copy link
Copy Markdown
Collaborator Author

This appears to be the repo-wide fix for the current burst of fake Web CI failures.

I checked recent unrelated PR runs (#13591, #13598, #13587): web / agent-session-web-resources is failing before project code with setup-bun attempting a GitHub tag lookup and receiving HTTP 403. This PR's own run has the corresponding Web jobs green with the version pinned.

Once the separate guard-ownership regression from #13585/#13535 is repaired on main, I'd prioritize getting this landed before interpreting Web failures on the other branches.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@teamleaderleo
teamleaderleo merged commit 2c042a4 into main Sep 22, 2026
61 of 62 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant