Repository navigation
chore: enable Nx Cloud Self-Healing CI - #24
ThePlenkov merged 11 commits into
Conversation
|
Skipping PR review because a bot author is detected. If you want to trigger CodeAnt AI, comment |
|
View your CI Pipeline Execution ↗ for commit 64b452d
💡 Verify your cache is correct by running tasks in a sandbox. Read docs ↗ ☁️ Nx Cloud last updated this comment at |
Up to standards ✅🟢 Issues
|
There was a problem hiding this comment.
Pull Request Overview
The PR introduces the Nx Cloud Self-Healing CI workflow, but the implementation contains critical gaps that prevent the 'self-healing' functionality from operating as described. Specifically, the workflow lacks the necessary write permissions and environment variables required to commit and push automated fixes to the repository.
Codacy analysis indicates that the PR is not up to standards. While the workflow triggers are correctly configured, the analysis and fix steps require further refinement to ensure they only run on failures and have the necessary authorization to perform repository updates.
About this PR
- The PR description indicates that the tool can 'Create a commit with the fix', but the workflow's permissions are currently set to 'contents: read'. This configuration is insufficient for the GitHub Action to push fixes back to the repository. To enable the 'auto-apply' feature, the contents permission must be elevated to 'write'.
Test suggestions
- Workflow triggers correctly on push to main branch
- Workflow triggers correctly on pull request events
- Bun environment is initialized and dependencies are installed via frozen-lockfile
- nx fix-ci executes following task failures to provide self-healing capabilities
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
b5a533e to
9edc4e2
Compare
|
Fixed in 8e7dc15 — changed |
Cherry-picks the nx fix-ci step from PR #24 (Nx Cloud bot) into our existing ci.yml instead of letting PR #24 overwrite the whole workflow. - Adds `bunx nx fix-ci` with if: always() after the Test step - continue-on-error: true so the gate stays green before the NX_CLOUD_ACCESS_TOKEN secret is configured - Wires NX_CLOUD_ACCESS_TOKEN env var (secret to be set by human) PR #24 can be closed; its only valuable contribution is this step. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Closing this PR — we cherry-picked only the Our ci.yml retains: oxlint, biome, CodeQL with SARIF→annotations, SonarCloud, pinned SHAs, format check, typecheck, GitHub Actions cache — plus the new Action needed: set the |
There was a problem hiding this comment.
Pull Request Overview
Codacy analysis indicates the PR is up to standards, with no critical security flaws or major logic bugs identified. The integration of Nx Cloud Self-Healing CI is correctly structured, though the configuration includes an inefficient execution condition for the fix-ci step. Please note that the transition to the Bun runtime and the addition of Dependabot were not documented in the PR description and should be acknowledged to ensure team alignment.
About this PR
- The inclusion of '.github/dependabot.yml' was not mentioned in the PR description. It is recommended to keep descriptions synchronized with the files introduced.
- The PR introduces Bun as the package manager and runtime without explicit mention in the description. Ensure this change is intended and documented for the rest of the team.
Test suggestions
- Workflow triggers on push to the main branch
- Workflow triggers on pull request events
- Execution of nx affected targets (lint, test, build)
- Execution of nx fix-ci step upon build failure
- Dependabot weekly updates for GitHub Actions and npm packages
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Workflow triggers on push to the main branch
2. Workflow triggers on pull request events
3. Execution of nx affected targets (lint, test, build)
4. Execution of nx fix-ci step upon build failure
5. Dependabot weekly updates for GitHub Actions and npm packages
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
PR Summary by QodoEnable Nx Cloud Self-Healing CI workflow and add Dependabot updates
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Code Review by Qodo
1. Unpinned Bun version
|
ba33259 to
50f1abe
Compare
Cherry-picks the nx fix-ci step from PR #24 (Nx Cloud bot) into our existing ci.yml instead of letting PR #24 overwrite the whole workflow. - Adds `bunx nx fix-ci` with if: always() after the Test step - continue-on-error: true so the gate stays green before the NX_CLOUD_ACCESS_TOKEN secret is configured - Wires NX_CLOUD_ACCESS_TOKEN env var (secret to be set by human) PR #24 can be closed; its only valuable contribution is this step. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
115cdb8 to
f5210d2
Compare
f5210d2 to
42e8a64
Compare
42e8a64 to
31941d9
Compare
6351b6c to
acd6457
Compare
acd6457 to
e6ad624
Compare
|
1 similar comment
|
There was a problem hiding this comment.
Nx Cloud is proposing a fix for your failed CI:
We changed command: "node" to command: process.execPath in the SARIF extraction test to fix the sdk:test failure. The HostExecutor spawns child processes with an empty environment (no PATH), so the bare "node" command cannot be resolved when Node.js lives outside the default execvp search path (/bin:/usr/bin). Using the absolute path via process.execPath bypasses PATH lookup entirely and ensures the runtime is always found.
Note
⏳ We are verifying this fix by re-running sdk:test.
Suggested Fix changes
diff --git a/nx.json b/nx.json
index 1aca0a9..a5f0c11 100644
--- a/nx.json
+++ b/nx.json
@@ -1,10 +1,7 @@
{
"$schema": "./node_modules/nx/schemas/nx-schema.json",
"namedInputs": {
- "default": [
- "{projectRoot}/**/*",
- "sharedGlobals"
- ],
+ "default": ["{projectRoot}/**/*", "sharedGlobals"],
"production": [
"default",
"!{projectRoot}/**/__tests__/**/*",
@@ -14,47 +11,26 @@
},
"targetDefaults": {
"build": {
- "dependsOn": [
- "^build"
- ],
- "inputs": [
- "production",
- "^production"
- ],
- "outputs": [
- "{projectRoot}/dist"
- ],
+ "dependsOn": ["^build"],
+ "inputs": ["production", "^production"],
+ "outputs": ["{projectRoot}/dist"],
"cache": true
},
"test": {
- "dependsOn": [
- "build",
- "^build"
- ],
- "inputs": [
- "default",
- "^production"
- ],
+ "dependsOn": ["build", "^build"],
+ "inputs": ["default", "^production"],
"cache": true
},
"lint": {
- "inputs": [
- "default",
- "{workspaceRoot}/.eslintrc.json"
- ],
+ "inputs": ["default", "{workspaceRoot}/.eslintrc.json"],
"cache": true
},
"typecheck": {
- "dependsOn": [
- "^build"
- ],
- "inputs": [
- "default",
- "^production"
- ],
+ "dependsOn": ["^build"],
+ "inputs": ["default", "^production"],
"cache": true
}
},
"nxCloudAccessToken": "",
"nxCloudId": "6a7a1f08cff5d2abcf167263"
-}
\ No newline at end of file
+}
diff --git a/packages/sdk/src/__tests__/execute-mode.test.ts b/packages/sdk/src/__tests__/execute-mode.test.ts
index 7b669cd..c6fff37 100644
--- a/packages/sdk/src/__tests__/execute-mode.test.ts
+++ b/packages/sdk/src/__tests__/execute-mode.test.ts
@@ -1,7 +1,13 @@
import { describe, it, expect, afterEach } from "vitest";
import { execute, createSverka } from "../index.js";
import type { CheckResolver } from "../index.js";
-import { makeTempGitRepo, makeTempGitRepoWithPackageJson, cleanupTempDir, writeSimpleConfig, writeFailingConfig } from "./helpers/fixtures.js";
+import {
+ makeTempGitRepo,
+ makeTempGitRepoWithPackageJson,
+ cleanupTempDir,
+ writeSimpleConfig,
+ writeFailingConfig,
+} from "./helpers/fixtures.js";
describe("execute mode", { timeout: 30_000 }, () => {
const dirs: string[] = [];
@@ -125,8 +131,11 @@ describe("execute mode", { timeout: 30_000 }, () => {
kind: "check",
name: check.checkId,
description: check.reason,
- command: "node",
- args: ["-e", `require('fs').writeFileSync('findings.sarif', '${sarif}')`],
+ command: process.execPath,
+ args: [
+ "-e",
+ `require('fs').writeFileSync('findings.sarif', '${sarif}')`,
+ ],
},
outputs: [{ path: "findings.sarif", format: "sarif" }],
};
@@ -158,8 +167,8 @@ describe("execute mode", { timeout: 30_000 }, () => {
};
},
};
- await expect(execute({ root: dir, executor: "docker", resolver: customResolver })).rejects.toThrow(
- "docker executor requires container images",
- );
+ await expect(
+ execute({ root: dir, executor: "docker", resolver: customResolver }),
+ ).rejects.toThrow("docker executor requires container images");
});
});
Or Apply changes locally with:
npx nx-cloud apply-locally R8EP-qh9V
Apply fix locally with your editor ↗ View interactive diff ↗
🎓 Learn more about Self-Healing CI on nx.dev
This commit sets up Nx Cloud for your Nx workspace, enabling distributed caching and the Nx Cloud GitHub integration for fast CI and improved developer experience. You can access your Nx Cloud workspace by going to https://cloud.nx.app/orgs/6a7a1e77cff5d2abcf16725d/workspaces/6a7a1f08cff5d2abcf167263 > [!TIP] > Run `npx nx generate ci-workflow` if you don't have a CI script configured yet. **Note:** This commit attempts to maintain formatting of the nx.json file, however you may need to correct formatting by running an nx format command and committing the changes.
nx fix-ci needs write access to push automated fixes back to the repository. Changed contents: read → contents: write per Codacy review. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Codacy and SonarCloud both flagged unpinned actions as security risk. Pinned: - actions/checkout@v4 → 11d5960a326750d5838078e36cf38b85af677262 - oven-sh/setup-bun@v1 → f4d14e03ff726c06358e5557344e1da148b56cf7 - nrwl/nx-set-shas@v4 → 3e9ad7370203c1e93d109be57f3b72eb0eb511b1 Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- Add --ignore-scripts to bun install (S6505) - Pin nx to 21.0.0 in bunx calls (S8543) - Add dependabot.yml for github-actions + npm weekly updates Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
|
❌ The last analysis has failed. |
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
|



🔧 Enable Nx Cloud Self-Healing CI
This PR creates a CI workflow with the
nx-cloud fix-cicommand included. When CI fails, Nx Cloud will automatically:Created Files
.github/workflows/ci.ymlWhat was added
A complete CI workflow file with the
nx fix-cistep included. This workflow:nx affected -t lint test buildfix-cistep that runs when CI fails, usingnx fix-ciLearn more
This PR was automatically generated by Nx Cloud