Repository navigation
test(workflows): name a step that runs an unknown script or subcommand - #525
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The validation is consistent with the dispatcher contract and covers the relevant failure modes.
Review effort: Balanced
Findings: None
What changed in this PR
Adds workflow wiring checks that identify unknown scripts and subcommands before post-green hooks run.
Changes:
- Exports the post-green command registry.
- Validates workflow script invocations against registered commands.
- Corrects the release topology documentation path.
| File | Description |
|---|---|
.github/scripts/post-green-steps.ts |
Exports and reuses the command table. |
test/workflows/post-green-workflow.test.ts |
Adds script parsing, validation, and negative controls. |
CONTRIBUTING.md |
Updates the topology source path. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The wiring relation in test/workflows/post-green-workflow.test.ts judged a `bun .github/scripts/<script>.ts <subcommand>` step only by the outputs it declares, so a step naming a script that does not exist, or a known script with a mistyped subcommand, raised no problem: the typo passed until the hook ran on main. A SCRIPTS registry now pairs each steps script's exported COMMANDS table (what it dispatches) with its STEP_OUTPUTS (what those write), and the relation names a step whose script is not registered or whose subcommand the script does not dispatch. A broad detector (any run text with bun ahead of a steps script path) and a strict reader (the hooks' shapes: bash-identifier assignments ahead of bun, arguments after the subcommand, spaces or tabs between tokens) sit side by side, with a control that a detected step the reader cannot parse fails loudly; the control's own control pins a newline between tokens, a bun flag, `bun run`, a line continuation, and a digit-leading prefix as detected and unread. The registry is a Map and the outputs lookup is an own-key read, so `constructor` as a script or subcommand is named as unknown instead of throwing. post-green-steps.ts exports its COMMANDS table as release-pipeline.ts does. CONTRIBUTING.md names .github/scripts/release-pipeline/tags.ts as where the git topology lives, where the split moved it.
Vivswan
force-pushed
the
test/workflows-unknown-script-step
branch
from
October 6, 2026 23:17
6fb43c3 to
311bc62
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Before
After
How
COMMANDStable (what it dispatches) beside itsSTEP_OUTPUTS(what those write).buna steps script is detected; a detected step the reader cannot parse fails the control.release-pipeline/tags.tsas where the git topology lives, where the split moved it.Proof
""and the six-line list above), then passed; the doubled-space row went red again under a single-space regex.Technical details
STEP_OUTPUTSalone lists only the subcommands that write outputs (release-pipeline declares 1 of 11), so it cannot judge a subcommand.GITHUB_SHA="$SOURCE_SHA" bun ... package-commit|package|retag-major|npm-publish next|npm-publish stablesteps; their declared outputs are unchanged (none), soisProbeand the gate chain read as before.constructor.tsand aconstructorsubcommand are named as unknown instead of throwing inoutputsWritten; a row pins each.bun run, a line continuation, a prefix bash reads as a command (1PAT_SET="true"), single-quoted assignments, multi-command blocks; each is detected and fails the control rather than passing unjudged, and the control pins the first five. Any run text withbunahead of.github/scripts/is detected.test/workflows/post-green-workflow.test.ts,.github/scripts/post-green-steps.ts(the export),CONTRIBUTING.md(line 60).