Skip to content

Evaluate a reproducible bundled Action while preserving package-spec #20

Description

@cucuwang

Follow-up to #19. The current composite Action pins the top-level npm version but resolves transitive dependencies at runtime. A fixed JS bundle could remove install-time resolution, but the public package-spec input supports alternate/test tarballs and must retain deliberate semantics.

Compare an isolated lockfile/npm ci implementation with a bundled runtime: reproducibility, measured checkout/download size, cold execution time, maintenance/update cost, security surface and Marketplace compatibility.

Acceptance:

  • Prototype bundling of ESM, dynamic imports and puppeteer-core paths; measure size rather than estimating.
  • Build twice from locked npm ci and compare bytes; add stale-bundle detection.
  • Preserve root and compatibility Action paths, package-spec, advisory/blocking modes, score/report outputs and failure behavior.
  • Review dependencies/licenses and document rebuild/release ownership.
  • Keep scoring/CLI/API contracts unchanged.

No runtime rewrite or production publication is authorized by this follow-up. Technical comparison is in docs/action-reproducibility.md in #19.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions