Files
store-scraper-bot/plans/260510-0001-backlog-cleanup/phase-02-ci-workflow-on-pr-push.md
T
tiennm99 49726f14c1 chore: backlog cleanup — deps, CI, bot description, ops docs
- pin form-data/qs/tough-cookie via package.json overrides; clears 3 of 4
  Dependabot alerts (request SSRF risk-accepted, no upstream fix)
- add GitHub Actions CI (lint + syntax check) on push/PR
- add /settings and /setdayswarning to setMyCommands
- new npm run describe sets bot profile description via Bot API
- README: drop stale preview warning, add Operations section
2026-05-10 00:13:09 +07:00

2.1 KiB

phase, title, status, priority, effort, dependencies
phase title status priority effort dependencies
2 CI workflow on PR/push completed P2 30m

Phase 2: CI workflow on PR/push

Overview

Add a single GitHub Actions workflow running on PR + push: npm ci, secret-leak lint, and node --check on every .js file. No tests exist yet so no test job. Cheap signal that someone's commit at least parses + doesn't add secrets.

Architecture

One workflow file, single job, two minutes max runtime. Use Node 20 (matches engines.node in package.json). Cache npm via actions/setup-node@v4's built-in cache.

Create

  • .github/workflows/ci.yml

Implementation Steps

  1. Create .github/workflows/ci.yml:
    name: CI
    on:
      push:
        branches: [main]
      pull_request:
    jobs:
      verify:
        runs-on: ubuntu-latest
        steps:
          - uses: actions/checkout@v4
          - uses: actions/setup-node@v4
            with:
              node-version: 20
              cache: npm
          - run: npm ci
          - run: npm run lint
          - name: Syntax check all JS
            run: find api scripts src -name '*.js' -print0 | xargs -0 -n1 node --check
    
  2. Commit + push → confirm green run in Actions tab.
  3. Add a status badge to README (optional, low value — skip unless trivial).

Success Criteria

  • Workflow file present at .github/workflows/ci.yml
  • First run on push to main is green
  • PRs show CI status check
  • Job completes < 2 minutes

Risk Assessment

  • Bundle-size gate dropped: original todo asked for "lint + bundle-size as PR check". Bundle size mattered when target was Cloudflare Workers (1MB script limit). On Vercel serverless, 250MB unzipped limit makes bundle size irrelevant. Skipped — YAGNI.
  • find path coverage: if a future top-level dir is added, the syntax check misses it. Mitigation: documented in workflow comment to update the find roots when adding new dirs. Acceptable — no current dynamism in repo layout.
  • npm ci slowness: mitigated by built-in npm cache. Cold runs ~30s, warm <10s.