Skip to content

test(bundle): assert dist/index.js requires only node built-ins and inlines every package src/ imports - #266

Merged
github-actions[bot] merged 1 commit into
mainfrom
quality/test-dist-self-contained
Oct 2, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
quality/test-dist-self-contained

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Test Improvement

Adds __tests__/bundle/selfContained.test.ts (new file; does not touch bundle.test.ts, which the held bundle PRs #236–#262 edit):

  • requires only node built-in modules — every require(<literal>) specifier in dist/index.js satisfies node:module's isBuiltin. Catches a package left external by ncc, which webpackMissingModule does not (that marker only fires for modules ncc could not resolve at build time), and which the bundle e2e suite cannot see because runBundle.ts spawns from the repository root where node_modules resolves the import.
  • inlines every package src/ imports — every bare package imported by src/**/*.ts (@actions/core, @actions/github, @octokit/rest, js-yaml) appears in the bundle as an inlined node_modules/<pkg>/ module.

Verified on main @ c48bd6d, Node v26.10.0: both tests pass; npx eslint clean. Mutation check: appending require("js-yaml") to dist/index.js fails the first test with expected [ 'js-yaml' ] to deeply equal [].

Related Issue

Closes #265


Filed by quality agent (hold-gated mode). Human review required.

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

…nlines every package src/ imports

action.yml runs dist/index.js on a runner without node_modules, so every
package has to be inlined by ncc. bundle.test.ts only checks node --check
and the webpackMissingModule marker; a module left external emits a literal
require() that passes both, and runBundle.ts spawns from the repository
root where node_modules resolves it anyway.

Signed-off-by: quality <quality@hive.kubestellar.io>
@hivecommons-hive
hivecommons-hive Bot requested a review from jpmcb as a code owner October 2, 2026 08:27
@hivecommons-hive hivecommons-hive Bot added the hold Indicates that a PR should not merge because someone has issued a /hold command. label Oct 2, 2026
@hivecommons-hive

Copy link
Copy Markdown
Contributor Author

Important

Held for human review by the hive's ACMM level gate.

This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the outreach agent is always held because it publishes project-facing communication.

Hive will keep the hold label until a human removes it. Operators can make a deliberate one-off release during an ACMM level change with release_level_holds=true, but level changes never release this hold automatically.

@jeefy

jeefy commented Oct 2, 2026

Copy link
Copy Markdown
Member

/kind cleanup
/lgtm
/approve
/hold cancel

@github-actions github-actions Bot added kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. lgtm "Looks good to me", indicates that a PR is ready to be merged. and removed hold Indicates that a PR should not merge because someone has issued a /hold command. labels Oct 2, 2026
@github-actions
github-actions Bot merged commit 60b0608 into main Oct 2, 2026
10 checks passed
@mrbobbytables
mrbobbytables deleted the quality/test-dist-self-contained branch October 9, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. lgtm "Looks good to me", indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[quality] dist/index.js self-containment is unguarded — a leaked external require() passes the bundle suite

1 participant