feat(check): add the opt-in Vapi checks PR workflow and user docs - #64
Open
scott-lowe-vapi wants to merge 1 commit into
Open
scott-lowe-vapi wants to merge 1 commit into
scott-lowe-vapi wants to merge 1 commit into
Conversation
.github/workflows/vapi-checks.yml runs `npm run check` on pull requests (opened, synchronize, reopened, ready_for_review) and on manual dispatch, only when the repository variable VAPI_CHECKS_ENABLED is 'true' and a vapi-checks.yml exists — so on the upstream template it is dormant. - Live runs only for same-repository, non-Dependabot PRs and dispatch; forks and Dependabot get a keyless dry run, and secrets are passed only to live runs. Never pull_request_target. - Checks out the head SHA with full history (for --changed-since against origin/<base>) and persist-credentials: false. - --all posts the aggregate `Vapi Evals` status; dispatching one named check doesn't. The run step execs node so GitHub's cancel reaches it, inside a 22-minute budget under a 30-minute job timeout; concurrency cancels a superseded push's runs. - permissions: contents: read, statuses: write. Docs: a README "PR Checks" section (setup from test files to required status, the build-failure table, fork/Dependabot handling, CI orgs, cost and what stays real), the AGENTS.md simulations step, a "Inline PR Checks" section in docs/learnings/simulations.md, and improvements.md #34. Refs TEST-141 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 1, 2026
Contributor
Author
|
Warning This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
This stack of pull requests is managed by Graphite. Learn more about stacking. |
scott-lowe-vapi
marked this pull request as ready for review
October 1, 2026 23:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Value
V.A.L.U.E. tier: project — PR 8 of 10 for inline simulation PR checks (TEST-141). This PR turns
npm run checkinto a PR check and documents setup end to end.npm run check(PR 7) gives a verdict locally, but a reviewer needs it on the PR: aVapi Evalsstatus whose Details link opens the exact run (PAL-608's contract), run on every affected push, safe for forks and Dependabot..github/workflows/vapi-checks.yml(opt-in):pull_request(opened, synchronize, reopened, ready_for_review), plusworkflow_dispatchwith an optionalcheckinput. Neverpull_request_target.vars.VAPI_CHECKS_ENABLED == 'true', and does nothing without avapi-checks.yml, so on the upstream template it stays dormant.fetch-depth: 0so--changed-since origin/<base>diffs from the merge base, andpersist-credentials: false.--allposts the aggregateVapi Evals; dispatching one named check never changes it.cancel-in-progress, and the run stepexecs node, so GitHub's cancel reaches it and it cancels the superseded runs.--budget-minutes 22undertimeout-minutes: 30.contents: readandstatuses: write.README "PR Checks": the end-user guide, covering:
Vapi Evalsrequired, and fork/Dependabot unblocking;The project tree gains
vapi-checks.example.ymlandcheck-cmd.ts.AGENTS.md: the "Testing with Simulations" step 5 now points at
npm run simvsnpm run check.docs/learnings/simulations.md"Inline PR Checks":Indexes: the learnings index row, and
improvements.mdrefactor(push): extract reconcileStateKeyForResource — fold two ensure-fns into one generic helper #34 (RESOLVED). Nodocs/changelog.mdedit.Evidence of value
VapiAI/gitopshas noVAPI_CHECKS_ENABLEDvariable, so thevapi-checksjob is skipped in this PR's own checks (run 36941407785:completed / skipped). That also shows GitHub parsed the workflow and evaluated itsif:. Customers who haven't opted in see no change and no spend.--all,--changed-since, live and dry run, statuses, job summary, JSON) is covered end to end by PR 7's tests against a stub of the simulations and GitHub APIs. It was also run live in the owner's test org: innocuous exit 0, degraded exit 1, no resources created, every tool result a mock.npm test: 474 passing (docs and workflow only; no code change).Testing plan
actionlintisn't available in this environment, so it isn't linted. To check by hand:if:expressions, thesecretsternaries in stepenv, and theexecline.resources/<test-org>/holding the parity squad fromtests/fixtures/check-parity/resources/parity/, renamed, and that fixture'svapi-checks.yml.VAPI_PRIVATE_API_KEYsecret andVAPI_CHECKS_ENABLED=true.Vapi Evalsstatuses whose Details links land on the runs, plus the job summaries (screenshots to add here).package.jsonchange as Dependabot would. ExpectVapi Evals=error.itemCounts.canceled > 0).Stacked on #63.
Refs TEST-141
🤖 Generated with Claude Code